import { expect, test } from "vitest"; import { loadConfig } from "../src/config.js"; test("loads a safe Git workspace registry configuration", () => { const cfg = loadConfig({ THT_WORKSPACE_REGISTRY_ROOT: "/data/workspace-registry", THT_WORKSPACE_GIT_REMOTE: "ssh://git@gitea.example/thoth/workspaces.git", THT_WORKSPACE_GIT_BRANCH: "main", THT_WORKSPACE_INSTALLATION_ID: "server-psd-1", THT_WORKSPACE_SECRET_ROOTS: "/run/secrets,/data/secrets", }); expect(cfg.workspaceRegistry).toMatchObject({ root: "/data/workspace-registry", remoteUrl: "ssh://git@gitea.example/thoth/workspaces.git", branch: "main", installationId: "server-psd-1", secretRoots: ["/run/secrets", "/data/secrets"], }); }); test("uses safe workspace registry defaults", () => { expect(loadConfig({}).workspaceRegistry).toMatchObject({ root: "/data/workspace-registry", branch: "main", maxImportBytes: 10 * 1024 * 1024, maxImportEntries: 32, }); }); test("rejects a relative registry root and invalid import limits", () => { expect(() => loadConfig({ THT_WORKSPACE_REGISTRY_ROOT: "registry" })).toThrow(/registry/i); expect(() => loadConfig({ THT_WORKSPACE_REGISTRY_ROOT: "/data/registry", THT_WORKSPACE_MAX_IMPORT_BYTES: "0", })).toThrow(/import/i); expect(() => loadConfig({ THT_WORKSPACE_REGISTRY_ROOT: "/data/registry", THT_WORKSPACE_MAX_IMPORT_ENTRIES: "1.5", })).toThrow(/import/i); }); test("rejects unsafe registry branch, installation ID, and secret roots", () => { expect(() => loadConfig({ THT_WORKSPACE_GIT_BRANCH: "" })).toThrow(/branch/i); expect(() => loadConfig({ THT_WORKSPACE_INSTALLATION_ID: "" })).toThrow(/installation/i); expect(() => loadConfig({ THT_WORKSPACE_SECRET_ROOTS: "/run/secrets,relative" })) .toThrow(/secret/i); });