import { expect, test } from "vitest"; import { loadConfig } from "../src/config.js"; test("loads a safe Git workspace registry configuration", () => { const cfg = loadConfig({ THT_WORKSPACE_REGISTRY_ROOT: "/data/workspace-registry", THT_WORKSPACE_GIT_REMOTE: "ssh://git@gitea.example/thoth/workspaces.git", THT_WORKSPACE_GIT_BRANCH: "main", THT_WORKSPACE_INSTALLATION_ID: "server-psd-1", THT_WORKSPACE_SECRET_ROOTS: "/run/secrets,/data/secrets", }); expect(cfg.workspaceRegistry).toMatchObject({ root: "/data/workspace-registry", remoteUrl: "ssh://git@gitea.example/thoth/workspaces.git", branch: "main", installationId: "server-psd-1", secretRoots: ["/run/secrets", "/data/secrets"], }); }); test("uses safe workspace registry defaults", () => { const registry = loadConfig({}).workspaceRegistry; expect(registry).toMatchObject({ root: "/data/workspace-registry", branch: "main", }); expect(registry).not.toHaveProperty("gitAuthorName"); expect(registry).not.toHaveProperty("gitAuthorEmail"); expect(registry).not.toHaveProperty("maxImportBytes"); expect(registry).not.toHaveProperty("maxImportEntries"); }); test("rejects a relative registry root", () => { expect(() => loadConfig({ THT_WORKSPACE_REGISTRY_ROOT: "registry" })).toThrow(/registry/i); }); test("rejects unsafe registry branch, installation ID, and secret roots", () => { expect(() => loadConfig({ THT_WORKSPACE_GIT_BRANCH: "" })).toThrow(/branch/i); expect(() => loadConfig({ THT_WORKSPACE_INSTALLATION_ID: "" })).toThrow(/installation/i); expect(() => loadConfig({ THT_WORKSPACE_SECRET_ROOTS: "/run/secrets,relative" })) .toThrow(/secret/i); }); test("rejects ref-unsafe Git branches", () => { for (const branch of ["topic..bad", "--upload-pack=/tmp/x", "release/.hidden", "release.lock"]) { expect(() => loadConfig({ THT_WORKSPACE_GIT_BRANCH: branch })).toThrow(/branch/i); } }); test("rejects the reserved HEAD branch without rejecting lowercase head", () => { expect(() => loadConfig({ THT_WORKSPACE_GIT_BRANCH: "HEAD" })).toThrow(/branch/i); expect(loadConfig({ THT_WORKSPACE_GIT_BRANCH: "head" }).workspaceRegistry.branch).toBe("head"); }); test("rejects control characters in installation IDs", () => { for (const codePoint of [...Array(0x20).keys(), ...Array(0x21).keys()].map((code, index) => ( index < 0x20 ? code : code + 0x7f ))) { expect(() => loadConfig({ THT_WORKSPACE_INSTALLATION_ID: `server-psd-1${String.fromCodePoint(codePoint)}`, })).toThrow(/installation/i); } });