Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled
71 lines
3.2 KiB
TypeScript
71 lines
3.2 KiB
TypeScript
import assert from 'node:assert/strict';
|
|
import test from 'node:test';
|
|
|
|
import {
|
|
isPluginCredentialCatalogEntryAvailable,
|
|
isSafePluginAuthenticationUrl,
|
|
pluginProtocolForProvider,
|
|
sanitizePluginConnection,
|
|
} from './pluginConnection.ts';
|
|
|
|
test('plugin connection profiles preserve opaque configuration when their provider is absent', () => {
|
|
const providerId = 'com.example.transport.connection';
|
|
const configuration = { endpoint: 'example', nested: { mode: 'safe' }, ports: [22, 443] };
|
|
const result = sanitizePluginConnection({
|
|
providerId,
|
|
configuration,
|
|
authenticationProviderId: 'com.example.transport.authentication',
|
|
credentialId: 'credential-reference-1234',
|
|
}, pluginProtocolForProvider(providerId));
|
|
assert.deepEqual(result, {
|
|
providerId,
|
|
configuration,
|
|
authenticationProviderId: 'com.example.transport.authentication',
|
|
credentialId: 'credential-reference-1234',
|
|
});
|
|
assert.notEqual(result?.configuration, configuration);
|
|
});
|
|
|
|
test('plugin connection profiles fail closed on protocol ownership mismatches and unsafe JSON', () => {
|
|
const providerId = 'com.example.transport.connection';
|
|
assert.equal(sanitizePluginConnection({ providerId, configuration: {} }, 'plugin:other.plugin.connection'), undefined);
|
|
assert.equal(sanitizePluginConnection({ providerId, configuration: { value: Number.NaN } }, pluginProtocolForProvider(providerId)), undefined);
|
|
assert.equal(sanitizePluginConnection({ providerId, configuration: { constructor: 'spoof' } }, pluginProtocolForProvider(providerId)), undefined);
|
|
});
|
|
|
|
test('plugin connection profiles preserve explicit null configuration', () => {
|
|
const providerId = 'com.example.transport.connection';
|
|
assert.deepEqual(
|
|
sanitizePluginConnection(
|
|
{ providerId, configuration: null },
|
|
pluginProtocolForProvider(providerId),
|
|
),
|
|
{ providerId, configuration: null },
|
|
);
|
|
});
|
|
|
|
test('plugin credentials are selectable only after secure catalog publication', () => {
|
|
const credentialId = 'credential-reference-0001';
|
|
const published = new Set([credentialId]);
|
|
assert.equal(isPluginCredentialCatalogEntryAvailable(credentialId, 'secret', published), true);
|
|
assert.equal(isPluginCredentialCatalogEntryAvailable(credentialId, 'secret', new Set()), false);
|
|
assert.equal(
|
|
isPluginCredentialCatalogEntryAvailable(credentialId, 'enc:v1:djEwdGVzdAAAAAAAAAAAAAAAAA==', published),
|
|
false,
|
|
);
|
|
assert.equal(
|
|
isPluginCredentialCatalogEntryAvailable(credentialId, 'x'.repeat((64 * 1024) + 1), published),
|
|
false,
|
|
);
|
|
});
|
|
|
|
test('plugin authentication URLs require HTTPS except for loopback HTTP callbacks', () => {
|
|
assert.equal(isSafePluginAuthenticationUrl('https://login.example.com/authorize'), true);
|
|
assert.equal(isSafePluginAuthenticationUrl('http://localhost:44123/callback'), true);
|
|
assert.equal(isSafePluginAuthenticationUrl('http://127.0.0.1:44123/callback'), true);
|
|
assert.equal(isSafePluginAuthenticationUrl('http://[::1]:44123/callback'), true);
|
|
assert.equal(isSafePluginAuthenticationUrl('http://login.example.com/authorize'), false);
|
|
assert.equal(isSafePluginAuthenticationUrl('https://user:password@login.example.com/authorize'), false);
|
|
assert.equal(isSafePluginAuthenticationUrl('javascript:alert(1)'), false);
|
|
});
|