()
| 784 | |
| 785 | #[test] |
| 786 | fn creds_fail_when_keypair_cannot_load() { |
| 787 | // Identity resolved but its signing key can't be loaded — no token can |
| 788 | // be minted. This stands in for an "expired"/unusable credential, which |
| 789 | // in this self-signed-JWT model means "cannot sign right now". |
| 790 | let issue = evaluate_push_credentials(false, Some("alice"), Some("alice"), |_| false); |
| 791 | assert_eq!( |
| 792 | issue, |
| 793 | Some(CredentialIssue::KeypairUnavailable { |
| 794 | name: "alice".to_string() |
| 795 | }) |
| 796 | ); |
| 797 | } |
| 798 | |
| 799 | #[test] |
| 800 | fn credential_issue_messages_are_actionable() { |
nothing calls this directly
no test coverage detected