29 lines
1.8 KiB
JavaScript
29 lines
1.8 KiB
JavaScript
import { test } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import { dockerHub } from "./release-registry.mjs";
|
|
import { sha256 } from "./release-bundle.mjs";
|
|
|
|
test("registry verifies pinned config/platform and does not forward auth to blob storage", async () => {
|
|
const original = globalThis.fetch;
|
|
const config = JSON.stringify({ os: "linux", architecture: "amd64", config: { Labels: { "org.opencontainers.image.revision": "b".repeat(40) } } });
|
|
const configDigest = "sha256:" + sha256(config);
|
|
const manifest = JSON.stringify({ schemaVersion: 2, config: { digest: configDigest } });
|
|
const imageDigest = "sha256:" + sha256(manifest);
|
|
const auth = [];
|
|
globalThis.fetch = async (target, options) => {
|
|
const url = new URL(target);
|
|
if (url.hostname === "auth.docker.io") return new Response(JSON.stringify({ token: "registry-token" }));
|
|
if (url.hostname === "blob.example.test") { auth.push(options.headers?.Authorization); return new Response(config); }
|
|
if (url.pathname.includes("/blobs/")) return new Response(null, { status: 307, headers: { location: "https://blob.example.test/config" } });
|
|
return new Response(manifest, { headers: { "docker-content-digest": imageDigest } });
|
|
};
|
|
try {
|
|
const registry = dockerHub({ Username: "publisher", Secret: "PRIVATE_TOKEN" });
|
|
const image = await registry.inspect("example/core", imageDigest, "linux/amd64", { anonymous: true });
|
|
assert.equal(image.reference, `docker.io/example/core@${imageDigest}`);
|
|
assert.deepEqual(auth, [undefined]);
|
|
await assert.rejects(registry.inspect("example/core", imageDigest, "linux/arm64"), /platform mismatch/);
|
|
await assert.rejects(registry.inspect("example/core", "sha256:" + "0".repeat(64), "linux/amd64"), /Requested image digest/);
|
|
} finally { globalThis.fetch = original; }
|
|
});
|