88 lines
4.7 KiB
Go
88 lines
4.7 KiB
Go
package cmd
|
|
|
|
import (
|
|
"bytes"
|
|
"errors"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/Pingu-Studio/MaidnCLI/internal/config"
|
|
"github.com/spf13/cobra"
|
|
)
|
|
|
|
func TestAppSecretSetReadsValueFromStdinWithoutOutput(t *testing.T) {
|
|
originalLoad, originalStore := loadAppSecretConfig, storeAppSecret
|
|
originalConfig, originalFile, originalToken, originalShared := appSecretConfigPath, appSecretFile, appSecretTokenFile, appSecretShared
|
|
t.Cleanup(func() {
|
|
loadAppSecretConfig, storeAppSecret = originalLoad, originalStore
|
|
appSecretConfigPath, appSecretFile, appSecretTokenFile, appSecretShared = originalConfig, originalFile, originalToken, originalShared
|
|
})
|
|
appSecretConfigPath, appSecretFile, appSecretTokenFile, appSecretShared = "private.yaml", "", "restricted-token", false
|
|
loadAppSecretConfig = func(string) (config.Config, error) {
|
|
return config.Config{Git: config.GitConfig{CloneParent: "checkouts"}, Talos: config.TalosConfig{RepoDirName: "talos", GeneratedDir: "generated"}, SOPS: config.SOPSConfig{RecoveryIdentityPath: "must-not-pass", RecoveryBundlePath: "must-not-pass"}}, nil
|
|
}
|
|
const value = "do-not-print"
|
|
storeAppSecret = func(kubeconfig, tokenPath, path string, got []byte) error {
|
|
if kubeconfig != filepath.Join("checkouts", "talos", "generated", "kubeconfig") || tokenPath != "restricted-token" || path != "apps/orders-api/publish" || string(got) != value {
|
|
t.Fatal("set did not pass only kubeconfig, token path, target, and stdin value")
|
|
}
|
|
return nil
|
|
}
|
|
output := new(bytes.Buffer)
|
|
command := &cobra.Command{}
|
|
command.SetIn(strings.NewReader(value))
|
|
command.SetOut(output)
|
|
if err := runAppSecretSet(command, []string{"orders-api", "publish"}); err != nil || strings.Contains(output.String(), value) {
|
|
t.Fatal("set leaked its value or failed")
|
|
}
|
|
}
|
|
|
|
func TestAppSecretDeleteRequiresExplicitConfirmation(t *testing.T) {
|
|
originalYes := appSecretDeleteYes
|
|
t.Cleanup(func() { appSecretDeleteYes = originalYes })
|
|
appSecretDeleteYes = false
|
|
if err := runAppSecretDelete(&cobra.Command{}, []string{"orders-api", "publish"}); err == nil || !strings.Contains(err.Error(), "--yes") {
|
|
t.Fatalf("delete confirmation error = %v", err)
|
|
}
|
|
}
|
|
|
|
func TestAppSecretGenerateDoesNotReadOrPrintValue(t *testing.T) {
|
|
originalGenerate, originalFile := appSecretGenerate, appSecretFile
|
|
t.Cleanup(func() { appSecretGenerate, appSecretFile = originalGenerate, originalFile })
|
|
appSecretGenerate, appSecretFile = true, ""
|
|
value, err := readAppSecretValue(&cobra.Command{})
|
|
if err != nil || len(value) < 40 || strings.Contains(string(value), "\n") {
|
|
t.Fatal("generated app secret is not a bounded opaque value")
|
|
}
|
|
}
|
|
|
|
func TestAppSecretGrantOnlySavesNewDeclarativeDefinition(t *testing.T) {
|
|
originalLoad, originalSave := loadAppSecretConfig, saveAppSecretConfig
|
|
originalConfig, originalEnvironment, originalSecrets, originalShared := appSecretConfigPath, appSecretGrantEnvironment, appSecretGrantSecrets, appSecretGrantShared
|
|
t.Cleanup(func() {
|
|
loadAppSecretConfig, saveAppSecretConfig = originalLoad, originalSave
|
|
appSecretConfigPath, appSecretGrantEnvironment, appSecretGrantSecrets, appSecretGrantShared = originalConfig, originalEnvironment, originalSecrets, originalShared
|
|
})
|
|
appSecretConfigPath, appSecretGrantEnvironment, appSecretGrantSecrets, appSecretGrantShared = "private.yaml", "production", []string{"database"}, []string{"rabbitmq"}
|
|
loadAppSecretConfig = func(string) (config.Config, error) { return config.Config{}, nil }
|
|
saved := false
|
|
saveAppSecretConfig = func(path string, cfg config.Config) error {
|
|
saved = path == "private.yaml" && len(cfg.SecretGrants) == 1 && cfg.SecretGrants[0].Application == "orders-api" && cfg.SecretGrants[0].Consumer == "runtime" && cfg.SecretGrants[0].Environment == "production" && len(cfg.SecretGrants[0].Secrets) == 1 && cfg.SecretGrants[0].Secrets[0] == "database" && len(cfg.SecretGrants[0].Shared) == 1 && cfg.SecretGrants[0].Shared[0] == "rabbitmq"
|
|
return nil
|
|
}
|
|
command := &cobra.Command{}
|
|
command.SetOut(new(bytes.Buffer))
|
|
if err := runAppSecretGrant(command, []string{"orders-api", "runtime"}); err != nil || !saved {
|
|
t.Fatalf("runAppSecretGrant() = %v, saved = %t", err, saved)
|
|
}
|
|
|
|
loadAppSecretConfig = func(string) (config.Config, error) {
|
|
return config.Config{SecretGrants: []config.SecretGrant{{Application: "orders-api", Consumer: "runtime", Environment: "production", Secrets: []string{"database"}, Shared: []string{"other"}}}}, nil
|
|
}
|
|
saveAppSecretConfig = func(string, config.Config) error { return errors.New("must not save ambiguous grant") }
|
|
if err := runAppSecretGrant(command, []string{"orders-api", "runtime"}); err == nil || !strings.Contains(err.Error(), "different definition") {
|
|
t.Fatalf("ambiguous grant error = %v", err)
|
|
}
|
|
}
|