diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Add a test suite for the shipped extensions
Diffstat (limited to '')
-rwxr-xr-xtests/t0505-auth.sh68
1 file changed, 68 insertions, 0 deletions
diff --git a/tests/t0505-auth.sh b/tests/t0505-auth.sh
new file mode 100755
index 0000000..d4dcd52
--- /dev/null
+++ b/tests/t0505-auth.sh
@@ -0,0 +1,68 @@
+#!/bin/sh
+
+# Checks auth-file.lua and auth-inline.lua, the shipped auth filters, which
+# share their cookie signing, redirect vetting and action flows and differ
+# only in where accounts live. The unit checks under a standalone Lua meet
+# luaossl and luaposix with deterministic stand-ins from the harness, so
+# they prove this script's own logic on any machine, tampered and expired
+# cookies turned away, header injection stripped, unsafe redirects refused
+# and the login flows answering as documented. The run through cgit itself
+# needs the real modules inside the binary's own Lua, so it is probed for,
+# and an unedited copy protects nothing, which is itself the behaviour worth
+# proving end to end.
+
+test_description='Check the shipped auth extensions'
+CGIT_TEST_NO_CREATE_REPOS=YesPlease
+. ./setup.sh
+. "$TEST_OUTPUT_DIRECTORY/extensions/lib.sh"
+
+interpreters=$(ext_lua_interpreters 4)
+test -z "$interpreters" &&
+ say 'no standalone lua on the path, unit checks skipped'
+
+for lua in $interpreters
+do
+ for variant in inline file
+ do
+ test_expect_success "auth-$variant checks under $lua" "
+ '$lua' '$EXT_TEST_DIRECTORY/test-auth.lua' \
+ '$EXTENSIONS_DIRECTORY/auth-$variant.lua' $variant
+ "
+ done
+done
+
+test_expect_success 'create a repository with one commit' '
+ test_create_repo repos/authy &&
+ (
+ cd repos/authy &&
+ echo content >file &&
+ git add file &&
+ git commit -m "guarded commit"
+ )
+'
+
+if test "$CGIT_HAS_LUA" -eq 1 &&
+ cgit_lua_probe "$PWD/repos/authy/.git" \
+ openssl.rand openssl.hmac posix.sys.stat posix.unistd
+then
+ test_set_prereq CGIT_LUA_AUTH
+else
+ say 'cgit lua lacks luaossl or luaposix, checks through cgit skipped'
+fi
+
+test_expect_success CGIT_LUA_AUTH 'point cgit at the unedited auth filter' '
+ cat >cgitrc <<-EOF
+ virtual-root=/
+ cache-size=0
+ auth-filter=lua:$EXTENSIONS_DIRECTORY/auth-inline.lua
+ repo.url=authy
+ repo.path=$PWD/repos/authy/.git
+ EOF
+'
+
+test_expect_success CGIT_LUA_AUTH 'an unedited copy protects nothing' '
+ cgit_url "authy/log/" >tmp &&
+ grep ">guarded commit</a>" tmp
+'
+
+test_done