Gitea's "project/package/release" terms are overloaded, so the catalog now uses the most explicit words: - org = coulomb (the Gitea organisation) - repo = whynot-design (the Gitea repository/product) — not an org, not a scope - npm scope @whynot and package @whynot/design are distinct from both Changes: - catalog schema: replace conflated `owner` with required `org` + `repo`; `owner` is now a derived `org/repo` slug property - npm-config delivery is data-driven: registry + scope live in delivery_config.npm and are validated; engine no longer hardcodes a registry - exec delivery writes `<scope>:registry=<url>` + scoped `:_authToken` for the configured Gitea registry (token still env-expanded, never written to disk) - pilot lane points at https://gitea.coulomb.social/api/packages/coulomb/npm/, scope @whynot, KV path coulomb/whynot-design/npm/publish - npm-publish-demo uses @whynot scope so dry-run resolves the Gitea registry - docs: terminology table; routing owner shown as coulomb/whynot-design - tests: org/repo required, npm-config validation, registry authkey mapping Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
24 lines
1 KiB
Python
24 lines
1 KiB
Python
from secrets_engine.exec_delivery import _npm_userconfig, _registry_authkey
|
|
|
|
|
|
def test_registry_authkey_strips_scheme_and_trails_slash():
|
|
assert (
|
|
_registry_authkey("https://gitea.coulomb.social/api/packages/coulomb/npm/")
|
|
== "//gitea.coulomb.social/api/packages/coulomb/npm/"
|
|
)
|
|
# missing trailing slash is added
|
|
assert _registry_authkey("https://host/api/npm") == "//host/api/npm/"
|
|
|
|
|
|
def test_npm_userconfig_writes_registry_and_token_ref_not_value():
|
|
registry = "https://gitea.coulomb.social/api/packages/coulomb/npm/"
|
|
with _npm_userconfig(registry, "@whynot") as path:
|
|
body = path.read_text()
|
|
assert f"@whynot:registry={registry}" in body
|
|
# token is referenced via env expansion, never written literally
|
|
assert "${SE_NPM_TOKEN}" in body
|
|
assert "//gitea.coulomb.social/api/packages/coulomb/npm/:_authToken" in body
|
|
# file is mode 0600
|
|
assert (path.stat().st_mode & 0o077) == 0
|
|
# cleaned up on context exit
|
|
assert not path.exists()
|