e2e/tagprotect_test.go

69d8aa4ff9115d6ca1116e09a232e7a6416e4645
gitbay/e2e/tagprotect_test.go history · blame · raw

77 lines · 3433 bytes

 1package e2e
 2
 3import (
 4	"os"
 5	"path/filepath"
 6	"strings"
 7	"testing"
 8)
 9
10// Protected-tag globs refuse moving and deleting matching tags; a tag a
11// release is anchored to refuses both on its own (#201).
12func TestTagProtection(t *testing.T) {
13	inst := startInstance(t)
14	aliceKey := inst.newKey(t, "alice")
15	inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
16	if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/app"); code != 0 {
17		t.Fatalf("repo create: %s", errOut)
18	}
19	work := t.TempDir()
20	env := inst.gitEnv(aliceKey)
21	mustGit(t, work, env, "clone", "-q", inst.sshURL("alice/app"), "w")
22	dir := filepath.Join(work, "w")
23	if err := os.WriteFile(filepath.Join(dir, "a.txt"), []byte("a\n"), 0o644); err != nil {
24		t.Fatal(err)
25	}
26	mustGit(t, dir, env, "checkout", "-q", "-b", "main")
27	mustGit(t, dir, env, "add", ".")
28	mustGit(t, dir, env, "commit", "-q", "-m", "base")
29	mustGit(t, dir, env, "tag", "v1.0")
30	mustGit(t, dir, env, "tag", "nightly")
31	mustGit(t, dir, env, "push", "-q", "origin", "main", "v1.0", "nightly")
32
33	if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "settings", "protect-tag", "alice/app", "'['"); code != 2 {
34		t.Fatalf("bad glob accepted: %d %s", code, errOut)
35	}
36	if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "settings", "protect-tag", "alice/app", "'v*'"); code != 0 {
37		t.Fatalf("protect-tag: %s", errOut)
38	}
39	out, _, _ := inst.ssh(t, aliceKey, "", "repo", "settings", "show", "alice/app", "--json")
40	if !strings.Contains(out, `"protected_tags":["v*"]`) {
41		t.Fatalf("settings show: %s", out)
42	}
43
44	// Delete and move are refused for a matching tag; an unmatched tag is
45	// free, and a new matching tag can still be created.
46	if out, code := gitRun(t, dir, env, "push", "origin", ":v1.0"); code == 0 || !strings.Contains(out, "protected") {
47		t.Fatalf("protected tag deleted: %d\n%s", code, out)
48	}
49	mustGit(t, dir, env, "commit", "-q", "--allow-empty", "-m", "second")
50	mustGit(t, dir, env, "tag", "-f", "v1.0")
51	if out, code := gitRun(t, dir, env, "push", "--force", "origin", "v1.0"); code == 0 || !strings.Contains(out, "protected") {
52		t.Fatalf("protected tag moved: %d\n%s", code, out)
53	}
54	mustGit(t, dir, env, "push", "-q", "origin", ":nightly")
55	mustGit(t, dir, env, "tag", "v1.1")
56	mustGit(t, dir, env, "push", "-q", "origin", "v1.1")
57
58	// Unprotected again, the tag can go — unless a release anchors it.
59	if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "settings", "unprotect-tag", "alice/app", "'v*'"); code != 0 {
60		t.Fatalf("unprotect-tag: %s", errOut)
61	}
62	if _, errOut, code := inst.ssh(t, aliceKey, "", "release", "create", "alice/app", "v1.1", "--title", "'one one'"); code != 0 {
63		t.Fatalf("release create: %s", errOut)
64	}
65	if out, code := gitRun(t, dir, env, "push", "origin", ":v1.1"); code == 0 || !strings.Contains(out, "anchors a release") {
66		t.Fatalf("release tag deleted: %d\n%s", code, out)
67	}
68	mustGit(t, dir, env, "commit", "-q", "--allow-empty", "-m", "third")
69	mustGit(t, dir, env, "tag", "-f", "v1.1")
70	if out, code := gitRun(t, dir, env, "push", "--force", "origin", "v1.1"); code == 0 || !strings.Contains(out, "anchors a release") {
71		t.Fatalf("release tag moved: %d\n%s", code, out)
72	}
73	if _, errOut, code := inst.ssh(t, aliceKey, "", "release", "delete", "alice/app", "v1.1", "--yes"); code != 0 {
74		t.Fatalf("release delete: %s", errOut)
75	}
76	mustGit(t, dir, env, "push", "-q", "origin", ":v1.1")
77}