internal/control/token_test.go

1ed9fb9399b21da8e6cf45be8389792aac82d5bc
gitbay/internal/control/token_test.go history · blame · raw

80 lines · 2267 bytes

 1package control
 2
 3import (
 4	"bytes"
 5	"slices"
 6	"strings"
 7	"testing"
 8	"time"
 9
10	"gitbay.org/gitbay/internal/protocol"
11	"gitbay.org/gitbay/internal/store"
12)
13
14// The minting commands, pinned: adding one to the list, or dropping
15// one, is a decision this test makes someone take.
16func TestMintingCommandsMarked(t *testing.T) {
17	want := []string{
18		"admin email verify", "admin invite", "admin user create", "email verify",
19		"keys add", "repo deploy-key add", "repo runner add", "token create", "web login",
20	}
21	var got []string
22	for _, cmd := range Commands() {
23		if cmd.MintsCredential {
24			got = append(got, joinPath(cmd.Path))
25		}
26	}
27	slices.Sort(got)
28	if !slices.Equal(got, want) {
29		t.Fatalf("MintsCredential on %q, want %q", got, want)
30	}
31}
32
33// Dispatch refuses before the command runs, so no arguments are needed.
34func TestExpiringCredentialCannotMint(t *testing.T) {
35	exp := time.Now().Add(time.Hour)
36	for _, cmd := range Commands() {
37		if !cmd.MintsCredential {
38			continue
39		}
40		var out, errOut bytes.Buffer
41		c := &Ctx{User: store.User{ID: 1, Username: "root", IsAdmin: true}, Scope: "full", Expires: &exp, Stdout: &out, Stderr: &errOut}
42		if code := Dispatch(c, cmd.Path); code != protocol.ExitDenied || !strings.Contains(errOut.String(), "expires") {
43			t.Errorf("%s: exit %d %q, want %d and the reason", joinPath(cmd.Path), code, errOut.String(), protocol.ExitDenied)
44		}
45	}
46}
47
48func TestTokenCreateDefaultsToReadAndRecordsCreator(t *testing.T) {
49	st, _, uid := newQueueTestRepo(t)
50	if err := st.CreateAPIToken(uid, "parent", "h-parent", "full", nil, 0); err != nil {
51		t.Fatal(err)
52	}
53	_, parent, err := st.APITokenUser("h-parent")
54	if err != nil {
55		t.Fatal(err)
56	}
57	c, errOut := pruneCtx(st, t.TempDir(), store.User{ID: uid, Username: "alice"})
58	c.Cfg.Limits.WriteRate = -1
59	c.TokenID = parent.ID
60	if code := Dispatch(c, []string{"token", "create", "--name", "child"}); code != protocol.ExitOK {
61		t.Fatalf("exit %d: %s", code, errOut)
62	}
63	toks, err := st.ListAPITokens(uid)
64	if err != nil {
65		t.Fatal(err)
66	}
67	var found bool
68	for _, tk := range toks {
69		if tk.Name != "child" {
70			continue
71		}
72		found = true
73		if tk.Scope != "read" || tk.CreatedBy != "parent" {
74			t.Fatalf("child: %+v", tk)
75		}
76	}
77	if !found {
78		t.Fatal(`no token named "child"`)
79	}
80}