Token scope is now bound to package maturity, gated on netkingdom's own maturity: - maturity-build -> gitea-wide, maturity-test -> org-wide, maturity-prod -> repo-scoped (scope narrows as stakes rise; broad tokens only for low-stakes build artifacts) - the graduated table is DORMANT until netkingdom reaches production grade; until then every lane clamps to repo-scope, injected as NPM_AUTH_TOKEN (fail-safe) - token env-var name signals blast radius: NPM_AUTH_TOKEN (repo default), NPM_AUTH_COULOMB_TOKEN (org), NPM_AUTH_GITEA_TOKEN (gitea), NPM_AUTH_WHYNOT_TOKEN (npm scope, defined but unused), NPM_AUTH_WHYNOTDESIGN (explicit repo) netkingdom is at maturity-build today, so whynot-design resolves to repo-scope / NPM_AUTH_TOKEN. Flip netkingdom_maturity to maturity-prod to activate graduation. - policies/netkingdom-publication-scope.yaml: the policy data + gate - publication_policy.py: load + resolve (clamp/active, env naming, override) - exec delivery injects under the resolved env-var name (was fixed SE_NPM_TOKEN) - catalog lane carries delivery_config.npm.maturity - new CLI: `secrets-engine policy publication <lane>` - docs/publication-scope-policy.md; tests for clamp, graduation, naming, override Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
24 lines
1 KiB
Python
24 lines
1 KiB
Python
from secrets_engine.exec_delivery import _npm_userconfig, _registry_authkey
|
|
|
|
|
|
def test_registry_authkey_strips_scheme_and_trails_slash():
|
|
assert (
|
|
_registry_authkey("https://gitea.coulomb.social/api/packages/coulomb/npm/")
|
|
== "//gitea.coulomb.social/api/packages/coulomb/npm/"
|
|
)
|
|
# missing trailing slash is added
|
|
assert _registry_authkey("https://host/api/npm") == "//host/api/npm/"
|
|
|
|
|
|
def test_npm_userconfig_writes_registry_and_token_ref_not_value():
|
|
registry = "https://gitea.coulomb.social/api/packages/coulomb/npm/"
|
|
with _npm_userconfig(registry, "@whynot", "NPM_AUTH_TOKEN") as path:
|
|
body = path.read_text()
|
|
assert f"@whynot:registry={registry}" in body
|
|
# token is referenced via env expansion, never written literally
|
|
assert "${NPM_AUTH_TOKEN}" in body
|
|
assert "//gitea.coulomb.social/api/packages/coulomb/npm/:_authToken" in body
|
|
# file is mode 0600
|
|
assert (path.stat().st_mode & 0o077) == 0
|
|
# cleaned up on context exit
|
|
assert not path.exists()
|