from secrets_engine.exec_delivery import _npm_userconfig, _registry_authkey def test_registry_authkey_strips_scheme_and_trails_slash(): assert ( _registry_authkey("https://gitea.coulomb.social/api/packages/coulomb/npm/") == "//gitea.coulomb.social/api/packages/coulomb/npm/" ) # missing trailing slash is added assert _registry_authkey("https://host/api/npm") == "//host/api/npm/" def test_npm_userconfig_writes_registry_and_token_ref_not_value(): registry = "https://gitea.coulomb.social/api/packages/coulomb/npm/" with _npm_userconfig(registry, "@whynot") as path: body = path.read_text() assert f"@whynot:registry={registry}" in body # token is referenced via env expansion, never written literally assert "${SE_NPM_TOKEN}" in body assert "//gitea.coulomb.social/api/packages/coulomb/npm/:_authToken" in body # file is mode 0600 assert (path.stat().st_mode & 0o077) == 0 # cleaned up on context exit assert not path.exists()