fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -97,6 +97,48 @@ func TestWriteCanonicalNewFileRejectsExistingTargets(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestPreflightPrivateDirectoryAllowsOnlyAMissingFinalComponentWithoutMutation(t *testing.T) {
|
||||
temporaryRoot, err := filepath.EvalSymlinks(os.TempDir())
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
root, err := os.MkdirTemp(temporaryRoot, "tht-safeio-preflight-")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Cleanup(func() { _ = os.RemoveAll(root) })
|
||||
|
||||
missing := filepath.Join(root, "auth")
|
||||
exists, err := PreflightPrivateDirectory(missing)
|
||||
if err != nil || exists {
|
||||
t.Fatalf("missing final preflight exists=%v error=%v, want false/nil", exists, err)
|
||||
}
|
||||
if _, err := os.Lstat(missing); !errors.Is(err, os.ErrNotExist) {
|
||||
t.Fatalf("preflight created missing final: %v", err)
|
||||
}
|
||||
|
||||
nested := filepath.Join(root, "missing-parent", "auth")
|
||||
if _, err := PreflightPrivateDirectory(nested); !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("missing intermediate preflight error=%v, want ErrUnsafeFile", err)
|
||||
}
|
||||
if _, err := os.Lstat(filepath.Join(root, "missing-parent")); !errors.Is(err, os.ErrNotExist) {
|
||||
t.Fatalf("preflight created missing intermediate: %v", err)
|
||||
}
|
||||
|
||||
realParent := filepath.Join(root, "real-parent")
|
||||
if err := os.Mkdir(realParent, 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
linkedParent := filepath.Join(root, "linked-parent")
|
||||
testsupport.SymlinkOrSkip(t, realParent, linkedParent)
|
||||
if _, err := PreflightPrivateDirectory(filepath.Join(linkedParent, "auth")); !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("symlink ancestor preflight error=%v, want ErrUnsafeFile", err)
|
||||
}
|
||||
if _, err := os.Lstat(filepath.Join(realParent, "auth")); !errors.Is(err, os.ErrNotExist) {
|
||||
t.Fatalf("preflight mutated symlink target: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestListCanonicalPrivateDirectoryBoundsAndSortsValidatedEntries(t *testing.T) {
|
||||
temporaryRoot, err := filepath.EvalSymlinks(os.TempDir())
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user