e2e/deploykey_test.go
116 lines · 4684 bytes
1 symbol in this file
1package e2e
2
3import (
4 "encoding/json"
5 "os"
6 "path/filepath"
7 "strings"
8 "testing"
9)
10
11func TestDeployKeys(t *testing.T) {
12 t.Parallel()
13 inst := startInstance(t)
14 aliceKey := inst.newKey(t, "alice")
15 bobKey := inst.newKey(t, "bob")
16 inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
17 inst.admin(t, "admin", "user", "create", "bob", "--key", bobKey+".pub")
18
19 // Private repo with content.
20 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/app", "--private"); code != 0 {
21 t.Fatalf("repo create: %s", errOut)
22 }
23 work := t.TempDir()
24 env := inst.gitEnv(aliceKey)
25 mustGit(t, work, env, "clone", inst.sshURL("alice/app"), "w")
26 dir := filepath.Join(work, "w")
27 os.WriteFile(filepath.Join(dir, "app.txt"), []byte("v1\n"), 0o644)
28 mustGit(t, dir, env, "checkout", "-q", "-b", "main")
29 mustGit(t, dir, env, "add", ".")
30 mustGit(t, dir, env, "commit", "-q", "-m", "init")
31 mustGit(t, dir, env, "push", "-q", "origin", "main")
32
33 // Bind a read-only deploy key; non-admins cannot.
34 roKey := inst.newKey(t, "ci-ro")
35 roPub, _ := os.ReadFile(roKey + ".pub")
36 if _, _, code := inst.ssh(t, bobKey, string(roPub), "repo", "deploy-key", "add", "alice/app"); code != 3 {
37 t.Fatalf("non-admin deploy-key add on private repo: want not-found parity")
38 }
39 out, errOut, code := inst.ssh(t, aliceKey, string(roPub), "repo", "deploy-key", "add", "alice/app", "--json")
40 if code != 0 {
41 t.Fatalf("deploy-key add: %s", errOut)
42 }
43 var env2 struct {
44 Data struct {
45 Fingerprint string `json:"fingerprint"`
46 } `json:"data"`
47 }
48 json.Unmarshal([]byte(out), &env2)
49 roFP := env2.Data.Fingerprint
50
51 // The ro key clones the private repo but cannot push, cannot touch any
52 // other repo, and cannot run control commands.
53 roEnv := inst.gitEnv(roKey)
54 roWork := t.TempDir()
55 mustGit(t, roWork, roEnv, "clone", inst.sshURL("alice/app"), "w")
56 roDir := filepath.Join(roWork, "w")
57 mustGit(t, roDir, roEnv, "commit", "-q", "--allow-empty", "-m", "try")
58 if out, code := gitRun(t, roDir, roEnv, "push", "origin", "main"); code == 0 {
59 t.Fatalf("ro deploy key pushed:\n%s", out)
60 }
61 if _, _, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/other", "--private"); code != 0 {
62 t.Fatal("other repo failed")
63 }
64 if out, code := gitRun(t, t.TempDir(), roEnv, "clone", inst.sshURL("alice/other")); code == 0 || !strings.Contains(out, "repository not found") {
65 t.Fatalf("deploy key crossed repos: %d\n%s", code, out)
66 }
67 if _, _, code := inst.ssh(t, roKey, "", "whoami"); code != 4 {
68 t.Fatal("deploy key ran a control command")
69 }
70
71 // An rw key pushes.
72 rwKey := inst.newKey(t, "ci-rw")
73 rwPub, _ := os.ReadFile(rwKey + ".pub")
74 if _, errOut, code = inst.ssh(t, aliceKey, string(rwPub), "repo", "deploy-key", "add", "alice/app", "--rw"); code != 0 {
75 t.Fatalf("rw add: %s", errOut)
76 }
77 rwEnv := inst.gitEnv(rwKey)
78 rwWork := t.TempDir()
79 mustGit(t, rwWork, rwEnv, "clone", inst.sshURL("alice/app"), "w")
80 rwDir := filepath.Join(rwWork, "w")
81 // Its push closes the bound repository's issue whether the message
82 // names it bare or by full path (#213).
83 for _, title := range []string{"'bare'", "'full path'"} {
84 if _, errOut, code := inst.ssh(t, aliceKey, "", "issue", "create", "alice/app", "--title", title); code != 0 {
85 t.Fatalf("issue create: %s", errOut)
86 }
87 }
88 mustGit(t, rwDir, rwEnv, "commit", "-q", "--allow-empty", "-m", "ci push\n\nCloses #1, closes alice/app#2")
89 mustGit(t, rwDir, rwEnv, "push", "-q", "origin", "main")
90 for _, n := range []string{"1", "2"} {
91 if out, _, _ := inst.ssh(t, aliceKey, "", "issue", "show", "alice/app", n, "--json"); !strings.Contains(out, `"state":"closed"`) {
92 t.Fatalf("deploy key push did not close issue %s: %s", n, out)
93 }
94 }
95
96 // The binding survives an owner rename (keys bind to the repo ID).
97 if _, errOut, code = inst.ssh(t, aliceKey, "", "org", "create", "moved"); code != 0 {
98 t.Fatalf("org create: %s", errOut)
99 }
100 if _, errOut, code = inst.ssh(t, aliceKey, "", "repo", "transfer", "alice/app", "moved"); code != 0 {
101 t.Fatalf("transfer: %s", errOut)
102 }
103 mustGit(t, t.TempDir(), roEnv, "clone", inst.sshURL("moved/app"))
104
105 // List shows both with modes; removal severs access immediately.
106 out, _, _ = inst.ssh(t, aliceKey, "", "repo", "deploy-key", "list", "moved/app")
107 if !strings.Contains(out, "ro") || !strings.Contains(out, "rw") {
108 t.Fatalf("deploy-key list: %s", out)
109 }
110 if _, errOut, code = inst.ssh(t, aliceKey, "", "repo", "deploy-key", "remove", "moved/app", roFP); code != 0 {
111 t.Fatalf("remove: %s", errOut)
112 }
113 if out, code := gitRun(t, t.TempDir(), roEnv, "clone", inst.sshURL("moved/app")); code == 0 {
114 t.Fatalf("removed deploy key still works:\n%s", out)
115 }
116}