SurrealDB Rust driver and in-memory server: can integration tests connect without any credentials?
0 reputation · 21 Jan 2020, 04:17 UTC
0 reputation · 21 Jan 2020, 04:17 UTC
I am wiring the official SurrealDB Rust driver (surrealdb crate) against a local SurrealDB server started in memory-only mode (mem://) for an integration-test suite. The goal is a reproducible test environment that never touches production credentials or any persistent datastore.
The server is launched without the --auth flag, so my understanding is that no root password is required and the driver can connect using only the WebSocket endpoint. What is unclear is where the boundary sits between "no authentication configured" and "anonymous session": the driver exposes an explicit signin call, and it is not obvious whether omitting it yields a fully usable session for namespace/database selection and queries, or only a restricted one.
A second concern is portability of this setup. If a teammate or CI job starts the same binary with authentication enabled or a non-empty root password, the same test code presumably fails with an authentication error, so I want the test harness to detect that misconfiguration early rather than fail obscurely.
--auth, is calling signin with an empty root password required before use_ns/use_db and queries, or does the driver negotiate an equivalent session automatically?29275 reputation · 21 Jan 2020, 08:22 UTC
When a SurrealDB instance is started with the mem:// protocol and the --auth flag is omitted, the server accepts WebSocket connections without requiring any authentication. The Rust driver will automatically create an anonymous session if signin is not called. You can immediately call use_ns, use_db, and execute queries such as SELECT 1; and they will succeed.
signin with an empty password is a safe way to verify that the server is indeed running without authentication; the operation should return success.--auth or a non‑empty root password, the same signin call will fail with an authentication error, and any query will also fail.surreal start mem:// (no --auth).ws://localhost:8000/rpc.client.signin("root", "").await and assert that the result is Ok; this immediately tells you the server is in no‑auth mode.client.use_ns("test").await, client.use_db("demo").await, and any query you need.Include a tiny “sanity” query in the test’s setup phase, for example:
let res = client.query("SELECT 1;").await;
assert!(res.is_ok(), "Server should accept queries without authentication");
If the test fails here, it indicates that the server is running with authentication enabled or a root password is set.
In that case the same SELECT 1; query will return an error such as AuthenticationRequired. The test harness will fail at the sanity check, giving you an early, clear failure message instead of a later obscure error.
To be absolutely certain that the test environment is correctly configured, you may want to inspect the server’s startup logs or query the /status endpoint (if available) for the auth flag. If you have access to those logs, could you confirm that the server was launched without --auth?
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.