mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
Outbound sync answers NIP-42 challenges with the relay owner key on
every connection. When no owner key is available, the previous code
panicked at registration (`.expect`), and the retry machinery would
still have reserved a one-shot authentication retry that nothing could
ever fulfil.
Approach: `RelayConnection::new{,_with_database}` now take
`Option<Keys>` and only attach the SDK authenticator when present,
exposing `answers_auth_challenges()`. Without an authenticator an
auth-required CLOSED is terminal like any other CLOSED: the terminal
listener retires the subscription, the data lane releases its live
permit, and `handle_subscription_closed` skips the one-retry
reservation and goes straight to retirement plus the
AuthenticationRequired policy refusal (24h probe). `register_relay`
degrades gracefully to an unauthenticated connection with a warning
instead of panicking.
Correctness assumptions: rust-nostr only retains auth-refused
subscriptions for post-authentication resubscription when an
authenticator is configured, so every has_authenticator branch mirrors
an SDK behavior split; a reserved retry without an authenticator would
dangle until disconnect cleanup.
Test infrastructure: new AuthGatingRelay helper - a NIP-42 gate in
front of a backend relay that serves a plain NIP-11 document,
challenges every session, refuses queries pre-auth, marks negentropy
unsupported, and either bridges (Admit) or answers `restricted:`
(Restricted) after a valid AUTH, recording authenticated pubkeys and
REQ counts.
Validation: integration tests prove (1) a public instance
authenticates to a gated ordinary relay with its owner key and the
retained subscription is answered after AUTH (announcement reaches
purgatory through the gate, the instance's only event source), and
(2) a restricted refusal after successful authentication parks the
work - the gate's REQ count holds still for a full 2s observation
window. cargo test --lib (789 passed) and --test sync
sync::outbound_auth pass.
28 lines
850 B
Rust
28 lines
850 B
Rust
//! Common test utilities
|
|
#![allow(dead_code)] // Test helpers may not be used in all test configurations
|
|
#![allow(unused_imports)] // Re-exports may not be used in all test configurations
|
|
|
|
pub mod auth_gating_relay;
|
|
pub mod censoring_proxy;
|
|
pub mod flapping_relay;
|
|
pub mod git_server;
|
|
pub mod mock_relay;
|
|
pub mod neg_limiting_proxy;
|
|
pub mod nip09_helpers;
|
|
pub mod port;
|
|
pub mod purgatory_helpers;
|
|
pub mod relay;
|
|
pub mod req_limiting_proxy;
|
|
pub mod setup_drop_relay;
|
|
pub mod sync_helpers;
|
|
pub mod upload_pack_counting_proxy;
|
|
|
|
pub use auth_gating_relay::{AuthGatingRelay, GateMode};
|
|
pub use git_server::{SimpleGitServer, SmartGitServer};
|
|
pub use mock_relay::MockRelay;
|
|
pub use nip09_helpers::*;
|
|
pub use port::{reserve_port, PortReservation};
|
|
pub use purgatory_helpers::*;
|
|
pub use relay::{DeletionLifecycleOptions, TestRelay};
|
|
pub use sync_helpers::*;
|