import { afterEach, describe, expect, test } from "bun:test"; import { realpath, rm, stat } from "node:fs/promises"; import { getTrustPath, readTrust, requireLocalTrust, resolveTrustIdentity, updateTrust, } from "../../lib/trust"; const originalConfig = process.env.XDG_CONFIG_HOME; afterEach(async () => { const path = getTrustPath(); if (originalConfig === undefined) delete process.env.XDG_CONFIG_HOME; else process.env.XDG_CONFIG_HOME = originalConfig; await rm(path, { force: true }); await rm(path.slice(0, path.lastIndexOf("/")), { recursive: true, force: true, }); }); describe("local namespace trust", () => { test("grants and revokes a resolved CWD fingerprint in a mode-0600 store", async () => { process.env.XDG_CONFIG_HOME = `/tmp/kuber-trust-${crypto.randomUUID()}`; const cwd = await realpath("."); const identity = await resolveTrustIdentity("demo", cwd); await updateTrust((records) => [...records, identity]); expect(await requireLocalTrust(identity)).toEqual(identity); expect((await stat(getTrustPath())).mode & 0o777).toBe(0o600); await updateTrust((records) => records.filter( (record) => record.project !== identity.project || record.fingerprint !== identity.fingerprint, ), ); await expect(requireLocalTrust(identity)).rejects.toThrow("TRUST_REQUIRED"); }); test("rejects an unregistered directory in the same namespace", async () => { process.env.XDG_CONFIG_HOME = `/tmp/kuber-trust-${crypto.randomUUID()}`; const first = { project: "demo", fingerprint: "a".repeat(64) }; const second = { project: "demo", fingerprint: "b".repeat(64) }; await updateTrust(() => [first]); await expect(requireLocalTrust(second)).rejects.toThrow("TRUST_REQUIRED"); expect(await readTrust()).toEqual([first]); }); });