import { test } from "node:test"; import assert from "node:assert/strict"; import { dockerHub } from "./release-registry.mjs"; import { sha256 } from "./release-bundle.mjs"; test("registry verifies pinned config/platform and does not forward auth to blob storage", async () => { const original = globalThis.fetch; const config = JSON.stringify({ os: "linux", architecture: "amd64", config: { Labels: { "org.opencontainers.image.revision": "b".repeat(40) } } }); const configDigest = "sha256:" + sha256(config); const manifest = JSON.stringify({ schemaVersion: 2, config: { digest: configDigest } }); const imageDigest = "sha256:" + sha256(manifest); const auth = []; globalThis.fetch = async (target, options) => { const url = new URL(target); if (url.hostname === "auth.docker.io") return new Response(JSON.stringify({ token: "registry-token" })); if (url.hostname === "blob.example.test") { auth.push(options.headers?.Authorization); return new Response(config); } if (url.pathname.includes("/blobs/")) return new Response(null, { status: 307, headers: { location: "https://blob.example.test/config" } }); return new Response(manifest, { headers: { "docker-content-digest": imageDigest } }); }; try { const registry = dockerHub({ Username: "publisher", Secret: "PRIVATE_TOKEN" }); const image = await registry.inspect("example/core", imageDigest, "linux/amd64", { anonymous: true }); assert.equal(image.reference, `docker.io/example/core@${imageDigest}`); assert.deepEqual(auth, [undefined]); await assert.rejects(registry.inspect("example/core", imageDigest, "linux/arm64"), /platform mismatch/); await assert.rejects(registry.inspect("example/core", "sha256:" + "0".repeat(64), "linux/amd64"), /Requested image digest/); } finally { globalThis.fetch = original; } });