|
1 | 1 | //! Security foundation integration tests. |
2 | 2 |
|
3 | 3 | use spanda_core::{check, compile, run, RunOptions}; |
| 4 | +use spanda_runtime::security_runtime::SecurityRuntime; |
4 | 5 | use spanda_security::{ |
5 | | - CapabilitySet, PackagePermissions, RobotIdentity, SecurePolicy, SecurityContext, TrustLevel, |
| 6 | + CapabilitySet, PackagePermissions, RobotIdentity, SecurePolicy, SecurityBackedRuntime, |
| 7 | + SecurityContext, TrustLevel, |
6 | 8 | }; |
7 | 9 |
|
| 10 | +fn security_backed_runtime() -> Box<dyn SecurityRuntime> { |
| 11 | + Box::new(SecurityBackedRuntime::new()) |
| 12 | +} |
| 13 | + |
| 14 | +fn secured_run_options() -> RunOptions { |
| 15 | + RunOptions { |
| 16 | + security_runtime_factory: Some(security_backed_runtime), |
| 17 | + ..Default::default() |
| 18 | + } |
| 19 | +} |
| 20 | + |
8 | 21 | #[test] |
9 | 22 | fn security_example_type_checks() { |
10 | 23 | // Description: |
@@ -93,7 +106,7 @@ robot R { |
93 | 106 | } |
94 | 107 | } |
95 | 108 | "#; |
96 | | - let err = run(source, RunOptions::default()).expect_err("unsigned secure topic should fail"); |
| 109 | + let err = run(source, secured_run_options()).expect_err("unsigned secure topic should fail"); |
97 | 110 | assert!( |
98 | 111 | err.to_string().contains("Identity required") || err.to_string().contains("identity"), |
99 | 112 | "expected identity requirement, got: {err}" |
@@ -287,7 +300,7 @@ robot R { |
287 | 300 | behavior run() { audit.record("e", "p"); } |
288 | 301 | } |
289 | 302 | "#; |
290 | | - let err = run(source, RunOptions::default()) |
| 303 | + let err = run(source, secured_run_options()) |
291 | 304 | .expect_err("strict permissions should block audit.write"); |
292 | 305 | assert!( |
293 | 306 | err.to_string().contains("capability denied"), |
|
0 commit comments