fix: harden workspace registry config validation
This commit is contained in:
@@ -46,3 +46,19 @@ test("rejects unsafe registry branch, installation ID, and secret roots", () =>
|
||||
expect(() => loadConfig({ THT_WORKSPACE_SECRET_ROOTS: "/run/secrets,relative" }))
|
||||
.toThrow(/secret/i);
|
||||
});
|
||||
|
||||
test("rejects ref-unsafe Git branches", () => {
|
||||
for (const branch of ["topic..bad", "--upload-pack=/tmp/x", "release/.hidden", "release.lock"]) {
|
||||
expect(() => loadConfig({ THT_WORKSPACE_GIT_BRANCH: branch })).toThrow(/branch/i);
|
||||
}
|
||||
});
|
||||
|
||||
test("rejects control characters in installation IDs", () => {
|
||||
for (const codePoint of [...Array(0x20).keys(), ...Array(0x21).keys()].map((code, index) => (
|
||||
index < 0x20 ? code : code + 0x7f
|
||||
))) {
|
||||
expect(() => loadConfig({
|
||||
THT_WORKSPACE_INSTALLATION_ID: `server-psd-1${String.fromCodePoint(codePoint)}`,
|
||||
})).toThrow(/installation/i);
|
||||
}
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user