2020-02-15 22:13:50 +00:00
|
|
|
package dehub
|
|
|
|
|
|
|
|
import (
|
|
|
|
"dehub/sigcred"
|
|
|
|
"testing"
|
|
|
|
|
2020-02-29 20:02:25 +00:00
|
|
|
"gopkg.in/src-d/go-git.v4"
|
2020-02-15 22:13:50 +00:00
|
|
|
"gopkg.in/src-d/go-git.v4/plumbing"
|
|
|
|
yaml "gopkg.in/yaml.v2"
|
|
|
|
)
|
|
|
|
|
|
|
|
func TestConfigChange(t *testing.T) {
|
|
|
|
h := newHarness(t)
|
|
|
|
|
|
|
|
var hashes []plumbing.Hash
|
|
|
|
|
|
|
|
// commit the initial staged changes, which merely include the config and
|
|
|
|
// public key
|
2020-02-21 05:06:13 +00:00
|
|
|
_, hash := h.changeCommit("commit configuration", h.cfg.Accounts[0].ID, h.sig)
|
2020-02-15 22:13:50 +00:00
|
|
|
hashes = append(hashes, hash)
|
|
|
|
|
2020-02-29 20:02:25 +00:00
|
|
|
// create a new account and add it to the configuration. That commit should
|
|
|
|
// not be verifiable, though
|
2020-02-15 22:13:50 +00:00
|
|
|
newSig, newPubKeyBody := sigcred.SignifierPGPTmp(h.rand)
|
|
|
|
h.cfg.Accounts = append(h.cfg.Accounts, Account{
|
|
|
|
ID: "toot",
|
|
|
|
Signifiers: []sigcred.Signifier{{PGPPublicKey: &sigcred.SignifierPGP{
|
|
|
|
Body: string(newPubKeyBody),
|
|
|
|
}}},
|
|
|
|
})
|
2020-02-29 20:02:25 +00:00
|
|
|
h.cfg.AccessControls[0].ChangeAccessControls[0].Condition.Signature.AccountIDs = []string{"root", "toot"}
|
|
|
|
h.cfg.AccessControls[0].ChangeAccessControls[0].Condition.Signature.Count = "1"
|
2020-02-15 22:13:50 +00:00
|
|
|
|
|
|
|
cfgBody, err := yaml.Marshal(h.cfg)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
h.stage(map[string]string{ConfigPath: string(cfgBody)})
|
2020-02-29 20:02:25 +00:00
|
|
|
_, badHash := h.changeCommit("add toot user", h.cfg.Accounts[1].ID, newSig)
|
2020-02-15 22:13:50 +00:00
|
|
|
|
2020-03-04 23:34:02 +00:00
|
|
|
if err := h.repo.VerifyCommit(MainRefName, badHash); err == nil {
|
2020-02-29 20:02:25 +00:00
|
|
|
t.Fatal("toot user shouldn't be able to add itself to config")
|
2020-02-15 22:13:50 +00:00
|
|
|
}
|
2020-02-29 20:02:25 +00:00
|
|
|
h.reset(hash, git.HardReset)
|
2020-02-15 22:13:50 +00:00
|
|
|
|
|
|
|
// now add with the root user, this should work.
|
2020-02-29 20:02:25 +00:00
|
|
|
h.stage(map[string]string{ConfigPath: string(cfgBody)})
|
2020-02-21 05:06:13 +00:00
|
|
|
_, hash = h.changeCommit("add toot user", h.cfg.Accounts[0].ID, h.sig)
|
2020-02-15 22:13:50 +00:00
|
|
|
hashes = append(hashes, hash)
|
|
|
|
|
|
|
|
// _now_ the toot user should be able to do things.
|
|
|
|
h.stage(map[string]string{"foo/bar": "what a cool file"})
|
2020-02-21 05:06:13 +00:00
|
|
|
_, hash = h.changeCommit("add a cool file", h.cfg.Accounts[1].ID, newSig)
|
2020-02-15 22:13:50 +00:00
|
|
|
hashes = append(hashes, hash)
|
|
|
|
|
|
|
|
for i, hash := range hashes {
|
2020-03-04 23:34:02 +00:00
|
|
|
if err := h.repo.VerifyCommit(MainRefName, hash); err != nil {
|
2020-02-15 22:13:50 +00:00
|
|
|
t.Fatalf("commit %d (%v) should have been verified but wasn't: %v", i, hash, err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|