This PR contains the work done to do a little bit of housekeeping pass across all packages and the Website service. To provide further details about the work: * Refreshed the READMEs and source documentation to match the current code; * Tagged every test case consistently across the Infrastructure, Localization, Persistence, and Website test targets; * Removed Website middleware tests now covered by Infrastructure's own suite; * Conformed the `PrepareDB` method to Sendable; * Relaxes the production Compose DATABASE_TLS default from require to prefer; * Added Persistence test verifying the prefer posture falls back to plaintext connections. Reviewed-on: rock-n-code/loud-amsterdam#27 Co-authored-by: Javier Cicchelli <javier@rock-n-code.com> Co-committed-by: Javier Cicchelli <javier@rock-n-code.com>
59 lines
1.6 KiB
Swift
59 lines
1.6 KiB
Swift
import Logging
|
|
import MySQLNIO
|
|
import NIOCore
|
|
import NIOPosix
|
|
import NIOSSL
|
|
import Testing
|
|
|
|
@testable import Persistence
|
|
|
|
@Suite(
|
|
"TLS enumeration",
|
|
.tags(.enumeration)
|
|
)
|
|
struct TLSTests {
|
|
|
|
// MARK: Properties tests
|
|
|
|
@Test
|
|
func `off has no TLS configuration`() {
|
|
#expect(TLS.off.tlsConfiguration == nil)
|
|
}
|
|
|
|
@Test(arguments: [
|
|
TLS.prefer,
|
|
TLS.require
|
|
])
|
|
func `maps to the default client configuration`(
|
|
for tls: TLS
|
|
) throws {
|
|
let configuration = try #require(tls.tlsConfiguration)
|
|
|
|
#expect(configuration.bestEffortEquals(.makeClientConfiguration()))
|
|
}
|
|
|
|
@Test
|
|
func `prefer falls back to plaintext when the server offers no TLS`() async throws {
|
|
// The fake server never advertises `CLIENT_SSL`, so this connection can only succeed by downgrading to
|
|
// plaintext — pinning the driver behavior the `prefer` posture relies on.
|
|
let server = try await PlaintextMySQLServer.start()
|
|
let tlsConfiguration = try #require(TLS.prefer.tlsConfiguration)
|
|
let connection = try await MySQLConnection.connect(
|
|
to: .init(ipAddress: "127.0.0.1", port: server.port),
|
|
username: "loud",
|
|
database: "loud",
|
|
tlsConfiguration: tlsConfiguration,
|
|
logger: Logger(label: "test"),
|
|
on: MultiThreadedEventLoopGroup.singleton.any()
|
|
).get()
|
|
|
|
let isConnected = !connection.isClosed
|
|
|
|
try await connection.close().get()
|
|
try await server.stop()
|
|
|
|
#expect(isConnected)
|
|
}
|
|
|
|
}
|