Files
kuber/tests/lib/trust.test.ts
T

51 lines
1.8 KiB
TypeScript

import { afterEach, describe, expect, test } from "bun:test";
import { realpath, rm, stat } from "node:fs/promises";
import {
getTrustPath,
readTrust,
requireLocalTrust,
resolveTrustIdentity,
updateTrust,
} from "../../lib/trust";
const originalConfig = process.env.XDG_CONFIG_HOME;
afterEach(async () => {
const path = getTrustPath();
if (originalConfig === undefined) delete process.env.XDG_CONFIG_HOME;
else process.env.XDG_CONFIG_HOME = originalConfig;
await rm(path, { force: true });
await rm(path.slice(0, path.lastIndexOf("/")), {
recursive: true,
force: true,
});
});
describe("local namespace trust", () => {
test("grants and revokes a resolved CWD fingerprint in a mode-0600 store", async () => {
process.env.XDG_CONFIG_HOME = `/tmp/kuber-trust-${crypto.randomUUID()}`;
const cwd = await realpath(".");
const identity = await resolveTrustIdentity("demo", cwd);
await updateTrust((records) => [...records, identity]);
expect(await requireLocalTrust(identity)).toEqual(identity);
expect((await stat(getTrustPath())).mode & 0o777).toBe(0o600);
await updateTrust((records) =>
records.filter(
(record) =>
record.project !== identity.project ||
record.fingerprint !== identity.fingerprint,
),
);
await expect(requireLocalTrust(identity)).rejects.toThrow("TRUST_REQUIRED");
});
test("rejects an unregistered directory in the same namespace", async () => {
process.env.XDG_CONFIG_HOME = `/tmp/kuber-trust-${crypto.randomUUID()}`;
const first = { project: "demo", fingerprint: "a".repeat(64) };
const second = { project: "demo", fingerprint: "b".repeat(64) };
await updateTrust(() => [first]);
await expect(requireLocalTrust(second)).rejects.toThrow("TRUST_REQUIRED");
expect(await readTrust()).toEqual([first]);
});
});