feat: harden self-managed reconciliation
This commit is contained in:
@@ -0,0 +1,50 @@
|
||||
import { afterEach, describe, expect, test } from "bun:test";
|
||||
import { realpath, rm, stat } from "node:fs/promises";
|
||||
import {
|
||||
getTrustPath,
|
||||
readTrust,
|
||||
requireLocalTrust,
|
||||
resolveTrustIdentity,
|
||||
updateTrust,
|
||||
} from "../../lib/trust";
|
||||
|
||||
const originalConfig = process.env.XDG_CONFIG_HOME;
|
||||
|
||||
afterEach(async () => {
|
||||
const path = getTrustPath();
|
||||
if (originalConfig === undefined) delete process.env.XDG_CONFIG_HOME;
|
||||
else process.env.XDG_CONFIG_HOME = originalConfig;
|
||||
await rm(path, { force: true });
|
||||
await rm(path.slice(0, path.lastIndexOf("/")), {
|
||||
recursive: true,
|
||||
force: true,
|
||||
});
|
||||
});
|
||||
|
||||
describe("local namespace trust", () => {
|
||||
test("grants and revokes a resolved CWD fingerprint in a mode-0600 store", async () => {
|
||||
process.env.XDG_CONFIG_HOME = `/tmp/kuber-trust-${crypto.randomUUID()}`;
|
||||
const cwd = await realpath(".");
|
||||
const identity = await resolveTrustIdentity("demo", cwd);
|
||||
await updateTrust((records) => [...records, identity]);
|
||||
expect(await requireLocalTrust(identity)).toEqual(identity);
|
||||
expect((await stat(getTrustPath())).mode & 0o777).toBe(0o600);
|
||||
await updateTrust((records) =>
|
||||
records.filter(
|
||||
(record) =>
|
||||
record.project !== identity.project ||
|
||||
record.fingerprint !== identity.fingerprint,
|
||||
),
|
||||
);
|
||||
await expect(requireLocalTrust(identity)).rejects.toThrow("TRUST_REQUIRED");
|
||||
});
|
||||
|
||||
test("rejects an unregistered directory in the same namespace", async () => {
|
||||
process.env.XDG_CONFIG_HOME = `/tmp/kuber-trust-${crypto.randomUUID()}`;
|
||||
const first = { project: "demo", fingerprint: "a".repeat(64) };
|
||||
const second = { project: "demo", fingerprint: "b".repeat(64) };
|
||||
await updateTrust(() => [first]);
|
||||
await expect(requireLocalTrust(second)).rejects.toThrow("TRUST_REQUIRED");
|
||||
expect(await readTrust()).toEqual([first]);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user