secrets-engine/tests/test_exec_delivery.py
tegwick f87f4e5e4d refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry
Gitea's "project/package/release" terms are overloaded, so the catalog now uses
the most explicit words:
- org  = coulomb (the Gitea organisation)
- repo = whynot-design (the Gitea repository/product) — not an org, not a scope
- npm scope @whynot and package @whynot/design are distinct from both

Changes:
- catalog schema: replace conflated `owner` with required `org` + `repo`; `owner`
  is now a derived `org/repo` slug property
- npm-config delivery is data-driven: registry + scope live in
  delivery_config.npm and are validated; engine no longer hardcodes a registry
- exec delivery writes `<scope>:registry=<url>` + scoped `:_authToken` for the
  configured Gitea registry (token still env-expanded, never written to disk)
- pilot lane points at https://gitea.coulomb.social/api/packages/coulomb/npm/,
  scope @whynot, KV path coulomb/whynot-design/npm/publish
- npm-publish-demo uses @whynot scope so dry-run resolves the Gitea registry
- docs: terminology table; routing owner shown as coulomb/whynot-design
- tests: org/repo required, npm-config validation, registry authkey mapping

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 12:44:55 +02:00

24 lines
1 KiB
Python

from secrets_engine.exec_delivery import _npm_userconfig, _registry_authkey
def test_registry_authkey_strips_scheme_and_trails_slash():
assert (
_registry_authkey("https://gitea.coulomb.social/api/packages/coulomb/npm/")
== "//gitea.coulomb.social/api/packages/coulomb/npm/"
)
# missing trailing slash is added
assert _registry_authkey("https://host/api/npm") == "//host/api/npm/"
def test_npm_userconfig_writes_registry_and_token_ref_not_value():
registry = "https://gitea.coulomb.social/api/packages/coulomb/npm/"
with _npm_userconfig(registry, "@whynot") as path:
body = path.read_text()
assert f"@whynot:registry={registry}" in body
# token is referenced via env expansion, never written literally
assert "${SE_NPM_TOKEN}" in body
assert "//gitea.coulomb.social/api/packages/coulomb/npm/:_authToken" in body
# file is mode 0600
assert (path.stat().st_mode & 0o077) == 0
# cleaned up on context exit
assert not path.exists()