55 lines
2.1 KiB
Python
55 lines
2.1 KiB
Python
|
|
from dataclasses import replace
|
||
|
|
|
||
|
|
import pytest
|
||
|
|
|
||
|
|
from secrets_engine.config import repo_root
|
||
|
|
from secrets_engine.errors import PolicyGuardError
|
||
|
|
from secrets_engine.publication_policy import PublicationPolicy, resolve
|
||
|
|
|
||
|
|
|
||
|
|
def _policy():
|
||
|
|
return PublicationPolicy.load(repo_root() / "policies")
|
||
|
|
|
||
|
|
|
||
|
|
def test_netkingdom_is_build_and_dormant():
|
||
|
|
p = _policy()
|
||
|
|
assert p.netkingdom_maturity == "maturity-build"
|
||
|
|
assert p.production_grade is False
|
||
|
|
|
||
|
|
|
||
|
|
def test_dormant_clamps_to_repo_and_default_token_env():
|
||
|
|
p = _policy()
|
||
|
|
r = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
|
||
|
|
package_maturity="maturity-build")
|
||
|
|
assert r.effective_scope == "repo"
|
||
|
|
assert r.token_env == "NPM_AUTH_TOKEN"
|
||
|
|
assert r.clamped is True # build->gitea would be broader; clamped down
|
||
|
|
assert r.active is False
|
||
|
|
|
||
|
|
|
||
|
|
def test_active_graduated_scoping_when_production_grade():
|
||
|
|
p = replace(_policy(), netkingdom_maturity="maturity-prod")
|
||
|
|
build = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
|
||
|
|
package_maturity="maturity-build")
|
||
|
|
test = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
|
||
|
|
package_maturity="maturity-test")
|
||
|
|
prod = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
|
||
|
|
package_maturity="maturity-prod")
|
||
|
|
assert (build.effective_scope, build.token_env) == ("gitea", "NPM_AUTH_GITEA_TOKEN")
|
||
|
|
assert (test.effective_scope, test.token_env) == ("org", "NPM_AUTH_COULOMB_TOKEN")
|
||
|
|
assert (prod.effective_scope, prod.token_env) == ("repo", "NPM_AUTH_TOKEN")
|
||
|
|
assert build.active is True and build.clamped is False
|
||
|
|
|
||
|
|
|
||
|
|
def test_token_env_override_wins():
|
||
|
|
p = _policy()
|
||
|
|
r = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot",
|
||
|
|
package_maturity="maturity-build", token_env_override="NPM_AUTH_WHYNOTDESIGN")
|
||
|
|
assert r.token_env == "NPM_AUTH_WHYNOTDESIGN"
|
||
|
|
|
||
|
|
|
||
|
|
def test_invalid_maturity_rejected():
|
||
|
|
p = _policy()
|
||
|
|
with pytest.raises(PolicyGuardError):
|
||
|
|
resolve(p, org="coulomb", repo="x", npm_scope="@y", package_maturity="maturity-ga")
|