blob: 2ebee10f4dfd06a94e35b04500dd2e84f3e54a2f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
#!/bin/sh

# Checks auth-file.lua and auth-inline.lua, the shipped auth filters, which
# differ only in where accounts live. The unit checks meet luaossl and
# luaposix with deterministic stand-ins from the harness, proving tampered
# and expired cookies turned away, header injection stripped, unsafe
# redirects refused and the login flows answering as documented. The run
# through cgit itself needs the real modules inside the binary's own Lua, so
# it is probed for, and proves an unedited copy protects nothing.

test_description='Check the shipped auth extensions'
CGIT_TEST_NO_CREATE_REPOS=YesPlease
. ./setup.sh
. "$TEST_OUTPUT_DIRECTORY/extensions/lib.sh"

interpreters=$(ext_lua_interpreters 4)
test -z "$interpreters" &&
	say 'no standalone lua on the path, unit checks skipped'

for lua in $interpreters
do
	for variant in inline file
	do
		test_expect_success "auth-$variant checks under $lua" "
			'$lua' '$EXT_TEST_DIRECTORY/test-auth.lua' '$EXTENSIONS_DIRECTORY/auth-$variant.lua' $variant
		"
	done
done

test_expect_success 'create a repository with one commit' '
	test_create_repo repos/authy &&
	(
		cd repos/authy &&
		echo content >file &&
		git add file &&
		git commit -m "guarded commit"
	)
'

if test "$CGIT_HAS_LUA" -eq 1 &&
	cgit_lua_probe "$PWD/repos/authy/.git" openssl.rand openssl.hmac posix.sys.stat posix.unistd
then
	test_set_prereq CGIT_LUA_AUTH
else
	say 'cgit lua lacks luaossl or luaposix, checks through cgit skipped'
fi

test_expect_success CGIT_LUA_AUTH 'point cgit at the unedited auth filter' '
	cat >cgitrc <<-EOF
	virtual-root=/
	cache-size=0
	auth-filter=lua:$EXTENSIONS_DIRECTORY/auth-inline.lua
	repo.url=authy
	repo.path=$PWD/repos/authy/.git
	EOF
'

test_expect_success CGIT_LUA_AUTH 'an unedited copy protects nothing' '
	cgit_url "authy/log/" >tmp &&
	grep ">guarded commit</a>" tmp
'

test_done