Files
orca/cloud/apps/relay-ops/src/gcloud-client.test.ts
T
Jinwoo Hong 3eec77c11a chore(cloud): add the relay fence broker, ops console, Terraform root, scripts, and 24 cloud-* workflows (#18413)
Phase 6 of the relay split: the relay's deploy/operate surface moves under cloud/ with 24 cloud-* workflows gated on ORCA_CLOUD_OPERATIONS_ENABLED, the Cloud SQL rollout lease action, the relay Terraform root (dual-accept identities for both repositories), scripts, docs, CODEOWNERS, and a terraform validate job in Cloud Verify.
2026-09-03 06:55:14 -04:00

44 lines
1.3 KiB
TypeScript

import { describe, expect, it } from 'vitest'
import { createGcloudClient } from './gcloud-client.js'
describe('createGcloudClient', () => {
it('shares and caches one credential refresh across concurrent readers', async () => {
let calls = 0
const token = 'a'.repeat(40)
const client = createGcloudClient(async () => {
calls += 1
await Promise.resolve()
return token
})
const values = await Promise.all([
client.accessToken(),
client.accessToken(),
client.accessToken()
])
expect(values).toEqual([token, token, token])
expect(await client.accessToken()).toBe(token)
expect(calls).toBe(1)
})
it('caches bounded identity tokens by audience', async () => {
const commands: string[][] = []
const token = 'aaa.bbb.ccc'
const client = createGcloudClient(async (args) => {
commands.push(args)
return token
})
await expect(client.identityToken?.('https://relay.example/admin')).resolves.toBe(token)
await expect(client.identityToken?.('https://relay.example/admin')).resolves.toBe(token)
expect(commands).toEqual([
[
'auth',
'print-identity-token',
'--audiences=https://relay.example/admin',
'--include-email'
]
])
})
})