#!/bin/sh # Checks auth-file.lua and auth-inline.lua, the shipped auth filters, which # share their cookie signing, redirect vetting and action flows and differ # only in where accounts live. The unit checks under a standalone Lua meet # luaossl and luaposix with deterministic stand-ins from the harness, so # they prove this script's own logic on any machine, tampered and expired # cookies turned away, header injection stripped, unsafe redirects refused # and the login flows answering as documented. The run through cgit itself # needs the real modules inside the binary's own Lua, so it is probed for, # and an unedited copy protects nothing, which is itself the behaviour worth # proving end to end. test_description='Check the shipped auth extensions' CGIT_TEST_NO_CREATE_REPOS=YesPlease . ./setup.sh . "$TEST_OUTPUT_DIRECTORY/extensions/lib.sh" interpreters=$(ext_lua_interpreters 4) test -z "$interpreters" && say 'no standalone lua on the path, unit checks skipped' for lua in $interpreters do for variant in inline file do test_expect_success "auth-$variant checks under $lua" " '$lua' '$EXT_TEST_DIRECTORY/test-auth.lua' \ '$EXTENSIONS_DIRECTORY/auth-$variant.lua' $variant " done done test_expect_success 'create a repository with one commit' ' test_create_repo repos/authy && ( cd repos/authy && echo content >file && git add file && git commit -m "guarded commit" ) ' if test "$CGIT_HAS_LUA" -eq 1 && cgit_lua_probe "$PWD/repos/authy/.git" \ openssl.rand openssl.hmac posix.sys.stat posix.unistd then test_set_prereq CGIT_LUA_AUTH else say 'cgit lua lacks luaossl or luaposix, checks through cgit skipped' fi test_expect_success CGIT_LUA_AUTH 'point cgit at the unedited auth filter' ' cat >cgitrc <<-EOF virtual-root=/ cache-size=0 auth-filter=lua:$EXTENSIONS_DIRECTORY/auth-inline.lua repo.url=authy repo.path=$PWD/repos/authy/.git EOF ' test_expect_success CGIT_LUA_AUTH 'an unedited copy protects nothing' ' cgit_url "authy/log/" >tmp && grep ">guarded commit" tmp ' test_done