Repositorio del curso CCOM4030 el semestre B91 del proyecto Artesanías con el Instituto de Cultura

auth-token.test.js 18KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507
  1. var fs = require('fs')
  2. var path = require('path')
  3. var mocha = require('mocha')
  4. var assert = require('assert')
  5. var requireUncached = require('require-uncached')
  6. var npmRcPath = path.join(__dirname, '..', '.npmrc')
  7. var beforeEach = mocha.beforeEach
  8. var afterEach = mocha.afterEach
  9. var describe = mocha.describe
  10. var it = mocha.it
  11. var base64 = require('../base64')
  12. var decodeBase64 = base64.decodeBase64
  13. var encodeBase64 = base64.encodeBase64
  14. /* eslint max-nested-callbacks: ["error", 4] */
  15. describe('auth-token', function () {
  16. afterEach(function (done) {
  17. fs.unlink(npmRcPath, function () {
  18. done()
  19. })
  20. })
  21. it('should read global if no local is found', function () {
  22. var getAuthToken = requireUncached('../index')
  23. getAuthToken()
  24. })
  25. it('should return undefined if no auth token is given for registry', function (done) {
  26. fs.writeFile(npmRcPath, 'registry=http://registry.npmjs.eu/', function (err) {
  27. var getAuthToken = requireUncached('../index')
  28. assert(!err, err)
  29. assert(!getAuthToken())
  30. done()
  31. })
  32. })
  33. describe('legacy auth token', function () {
  34. it('should return auth token if it is defined in the legacy way via the `_auth` key', function (done) {
  35. var content = [
  36. '_auth=foobar',
  37. 'registry=http://registry.foobar.eu/'
  38. ].join('\n')
  39. fs.writeFile(npmRcPath, content, function (err) {
  40. var getAuthToken = requireUncached('../index')
  41. assert(!err, err)
  42. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Basic' })
  43. done()
  44. })
  45. })
  46. it('should return legacy auth token defined by reference to an environment variable (with curly braces)', function (done) {
  47. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  48. var content = [
  49. '_auth=${' + environmentVariable + '}',
  50. 'registry=http://registry.foobar.eu/'
  51. ].join('\n')
  52. process.env[environmentVariable] = 'foobar'
  53. fs.writeFile(npmRcPath, content, function (err) {
  54. var getAuthToken = requireUncached('../index')
  55. assert(!err, err)
  56. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Basic' })
  57. delete process.env[environmentVariable]
  58. done()
  59. })
  60. })
  61. it('should return legacy auth token defined by reference to an environment variable (without curly braces)', function (done) {
  62. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  63. var content = [
  64. '_auth=$' + environmentVariable,
  65. 'registry=http://registry.foobar.eu/'
  66. ].join('\n')
  67. process.env[environmentVariable] = 'foobar'
  68. fs.writeFile(npmRcPath, content, function (err) {
  69. var getAuthToken = requireUncached('../index')
  70. assert(!err, err)
  71. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Basic' })
  72. delete process.env[environmentVariable]
  73. done()
  74. })
  75. })
  76. })
  77. describe('bearer token', function () {
  78. it('should return auth token if registry is defined', function (done) {
  79. var content = [
  80. 'registry=http://registry.foobar.eu/',
  81. '//registry.foobar.eu/:_authToken=foobar', ''
  82. ].join('\n')
  83. fs.writeFile(npmRcPath, content, function (err) {
  84. var getAuthToken = requireUncached('../index')
  85. assert(!err, err)
  86. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Bearer' })
  87. done()
  88. })
  89. })
  90. it('should use npmrc passed in', function (done) {
  91. var content = [
  92. 'registry=http://registry.foobar.eu/',
  93. '//registry.foobar.eu/:_authToken=foobar', ''
  94. ].join('\n')
  95. fs.writeFile(npmRcPath, content, function (err) {
  96. var getAuthToken = requireUncached('../index')
  97. assert(!err, err)
  98. const npmrc = {
  99. 'registry': 'http://registry.foobar.eu/',
  100. '//registry.foobar.eu/:_authToken': 'qar'
  101. }
  102. assert.deepStrictEqual(getAuthToken({ npmrc: npmrc }), { token: 'qar', type: 'Bearer' })
  103. done()
  104. })
  105. })
  106. it('should return auth token if registry url has port specified', function (done) {
  107. var content = [
  108. 'registry=http://localhost:8770/',
  109. // before the patch this token was selected.
  110. '//localhost/:_authToken=ohno',
  111. '//localhost:8770/:_authToken=beepboop', ''
  112. ].join('\n')
  113. fs.writeFile(npmRcPath, content, function (err) {
  114. var getAuthToken = requireUncached('../index')
  115. assert(!err, err)
  116. assert.deepStrictEqual(getAuthToken(), { token: 'beepboop', type: 'Bearer' })
  117. done()
  118. })
  119. })
  120. it('should return auth token defined by reference to an environment variable (with curly braces)', function (done) {
  121. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  122. var content = [
  123. 'registry=http://registry.foobar.cc/',
  124. '//registry.foobar.cc/:_authToken=${' + environmentVariable + '}', ''
  125. ].join('\n')
  126. process.env[environmentVariable] = 'foobar'
  127. fs.writeFile(npmRcPath, content, function (err) {
  128. var getAuthToken = requireUncached('../index')
  129. assert(!err, err)
  130. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Bearer' })
  131. delete process.env[environmentVariable]
  132. done()
  133. })
  134. })
  135. it('should return auth token defined by reference to an environment variable (without curly braces)', function (done) {
  136. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  137. var content = [
  138. 'registry=http://registry.foobar.cc/',
  139. '//registry.foobar.cc/:_authToken=$' + environmentVariable, ''
  140. ].join('\n')
  141. process.env[environmentVariable] = 'foobar'
  142. fs.writeFile(npmRcPath, content, function (err) {
  143. var getAuthToken = requireUncached('../index')
  144. assert(!err, err)
  145. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Bearer' })
  146. delete process.env[environmentVariable]
  147. done()
  148. })
  149. })
  150. it('should try with and without a slash at the end of registry url', function (done) {
  151. var content = [
  152. 'registry=http://registry.foobar.eu',
  153. '//registry.foobar.eu:_authToken=barbaz', ''
  154. ].join('\n')
  155. fs.writeFile(npmRcPath, content, function (err) {
  156. var getAuthToken = requireUncached('../index')
  157. assert(!err, err)
  158. assert.deepStrictEqual(getAuthToken(), { token: 'barbaz', type: 'Bearer' })
  159. done()
  160. })
  161. })
  162. it('should fetch for the registry given (if defined)', function (done) {
  163. var content = [
  164. '//registry.foobar.eu:_authToken=barbaz',
  165. '//registry.blah.foo:_authToken=whatev',
  166. '//registry.last.thing:_authToken=yep', ''
  167. ].join('\n')
  168. fs.writeFile(npmRcPath, content, function (err) {
  169. var getAuthToken = requireUncached('../index')
  170. assert(!err, err)
  171. assert.deepStrictEqual(getAuthToken('//registry.blah.foo'), { token: 'whatev', type: 'Bearer' })
  172. done()
  173. })
  174. })
  175. it('recursively finds registries for deep url if option is set', function (done, undef) {
  176. var opts = { recursive: true }
  177. var content = [
  178. '//registry.blah.com/foo:_authToken=whatev',
  179. '//registry.blah.org/foo/bar:_authToken=recurseExactlyOneLevel',
  180. '//registry.blah.edu/foo/bar/baz:_authToken=recurseNoLevel',
  181. '//registry.blah.eu:_authToken=yep', ''
  182. ].join('\n')
  183. fs.writeFile(npmRcPath, content, function (err) {
  184. var getAuthToken = requireUncached('../index')
  185. assert(!err, err)
  186. assert.deepStrictEqual(getAuthToken('https://registry.blah.edu/foo/bar/baz', opts), { token: 'recurseNoLevel', type: 'Bearer' })
  187. assert.deepStrictEqual(getAuthToken('https://registry.blah.org/foo/bar/baz', opts), { token: 'recurseExactlyOneLevel', type: 'Bearer' })
  188. assert.deepStrictEqual(getAuthToken('https://registry.blah.com/foo/bar/baz', opts), { token: 'whatev', type: 'Bearer' })
  189. assert.deepStrictEqual(getAuthToken('http://registry.blah.eu/what/ever', opts), { token: 'yep', type: 'Bearer' })
  190. assert.deepStrictEqual(getAuthToken('http://registry.blah.eu//what/ever', opts), undefined, 'does not hang')
  191. assert.strictEqual(getAuthToken('//some.registry', opts), undef)
  192. done()
  193. })
  194. })
  195. it('should try both with and without trailing slash', function (done) {
  196. fs.writeFile(npmRcPath, '//registry.blah.com:_authToken=whatev', function (err) {
  197. var getAuthToken = requireUncached('../index')
  198. assert(!err, err)
  199. assert.deepStrictEqual(getAuthToken('https://registry.blah.com'), { token: 'whatev', type: 'Bearer' })
  200. done()
  201. })
  202. })
  203. it('should prefer bearer token over basic token', function (done) {
  204. var content = [
  205. 'registry=http://registry.foobar.eu/',
  206. 'registry=http://registry.foobar.eu/',
  207. '//registry.foobar.eu/:_authToken=bearerToken',
  208. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  209. '//registry.foobar.eu/:username=foobar', ''
  210. ].join('\n')
  211. fs.writeFile(npmRcPath, content, function (err) {
  212. var getAuthToken = requireUncached('../index')
  213. assert(!err, err)
  214. assert.deepStrictEqual(getAuthToken('//registry.foobar.eu'), { token: 'bearerToken', type: 'Bearer' })
  215. done()
  216. })
  217. })
  218. it('"nerf darts" registry urls', function (done, undef) {
  219. fs.writeFile(npmRcPath, '//contoso.pkgs.visualstudio.com/_packaging/MyFeed/npm/:_authToken=heider', function (err) {
  220. var getAuthToken = requireUncached('../index')
  221. assert(!err, err)
  222. assert.deepStrictEqual(
  223. getAuthToken('https://contoso.pkgs.visualstudio.com/_packaging/MyFeed/npm/registry'),
  224. { token: 'heider', type: 'Bearer' }
  225. )
  226. done()
  227. })
  228. })
  229. })
  230. describe('basic token', function () {
  231. it('should return undefined if password or username are missing', function (done, undef) {
  232. var content = [
  233. 'registry=http://registry.foobar.eu/',
  234. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  235. '//registry.foobar.com/:username=foobar', ''
  236. ].join('\n')
  237. fs.writeFile(npmRcPath, content, function (err) {
  238. var getAuthToken = requireUncached('../index')
  239. assert(!err, err)
  240. assert.strictEqual(getAuthToken('//registry.foobar.eu'), undef)
  241. assert.strictEqual(getAuthToken('//registry.foobar.com'), undef)
  242. done()
  243. })
  244. })
  245. it('should return basic token if username and password are defined', function (done) {
  246. var content = [
  247. 'registry=http://registry.foobar.eu/',
  248. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  249. '//registry.foobar.eu/:username=foobar', ''
  250. ].join('\n')
  251. fs.writeFile(npmRcPath, content, function (err) {
  252. var getAuthToken = requireUncached('../index')
  253. assert(!err, err)
  254. var token = getAuthToken()
  255. assert.deepStrictEqual(token, {
  256. token: 'Zm9vYmFyOmZvb2Jhcg==',
  257. type: 'Basic',
  258. username: 'foobar',
  259. password: 'foobar'
  260. })
  261. assert.strictEqual(decodeBase64(token.token), 'foobar:foobar')
  262. done()
  263. })
  264. })
  265. it('should return basic token if _auth is base64 encoded', function (done) {
  266. var content = [
  267. 'registry=http://registry.foobar.eu/',
  268. '//registry.foobar.eu/:_auth=' + encodeBase64('foobar:foobar')
  269. ].join('\n')
  270. fs.writeFile(npmRcPath, content, function (err) {
  271. var getAuthToken = requireUncached('../index')
  272. assert(!err, err)
  273. var token = getAuthToken()
  274. assert.deepStrictEqual(token, {
  275. token: 'Zm9vYmFyOmZvb2Jhcg==',
  276. type: 'Basic'
  277. })
  278. assert.strictEqual(decodeBase64(token.token), 'foobar:foobar')
  279. done()
  280. })
  281. })
  282. it('should return basic token if registry url has port specified', function (done) {
  283. var content = [
  284. 'registry=http://localhost:8770/',
  285. // before the patch this token was selected.
  286. '//localhost/:_authToken=ohno',
  287. '//localhost:8770/:_password=' + encodeBase64('foobar'),
  288. '//localhost:8770/:username=foobar', ''
  289. ].join('\n')
  290. fs.writeFile(npmRcPath, content, function (err) {
  291. var getAuthToken = requireUncached('../index')
  292. assert(!err, err)
  293. var token = getAuthToken()
  294. assert.deepStrictEqual(token, {
  295. token: 'Zm9vYmFyOmZvb2Jhcg==',
  296. type: 'Basic',
  297. username: 'foobar',
  298. password: 'foobar'
  299. })
  300. assert.strictEqual(decodeBase64(token.token), 'foobar:foobar')
  301. done()
  302. })
  303. })
  304. it('should return password defined by reference to an environment variable (with curly braces)', function (done) {
  305. var environmentVariable = '__REGISTRY_PASSWORD__'
  306. var content = [
  307. 'registry=http://registry.foobar.cc/',
  308. '//registry.foobar.cc/:username=username',
  309. '//registry.foobar.cc/:_password=${' + environmentVariable + '}', ''
  310. ].join('\n')
  311. process.env[environmentVariable] = encodeBase64('password')
  312. fs.writeFile(npmRcPath, content, function (err) {
  313. var getAuthToken = requireUncached('../index')
  314. assert(!err, err)
  315. var token = getAuthToken()
  316. assert.deepStrictEqual(token, {
  317. type: 'Basic',
  318. username: 'username',
  319. password: 'password',
  320. token: 'dXNlcm5hbWU6cGFzc3dvcmQ='
  321. })
  322. assert.strictEqual(decodeBase64(token.token), 'username:password')
  323. delete process.env[environmentVariable]
  324. done()
  325. })
  326. })
  327. it('should return password defined by reference to an environment variable (without curly braces)', function (done) {
  328. var environmentVariable = '__REGISTRY_PASSWORD__'
  329. var content = [
  330. 'registry=http://registry.foobar.cc/',
  331. '//registry.foobar.cc/:username=username',
  332. '//registry.foobar.cc/:_password=$' + environmentVariable, ''
  333. ].join('\n')
  334. process.env[environmentVariable] = encodeBase64('password')
  335. fs.writeFile(npmRcPath, content, function (err) {
  336. var getAuthToken = requireUncached('../index')
  337. assert(!err, err)
  338. var token = getAuthToken()
  339. assert.deepStrictEqual(token, {
  340. type: 'Basic',
  341. username: 'username',
  342. password: 'password',
  343. token: 'dXNlcm5hbWU6cGFzc3dvcmQ='
  344. })
  345. assert.strictEqual(decodeBase64(token.token), 'username:password')
  346. delete process.env[environmentVariable]
  347. done()
  348. })
  349. })
  350. it('should try with and without a slash at the end of registry url', function (done) {
  351. var content = [
  352. 'registry=http://registry.foobar.eu',
  353. '//registry.foobar.eu:_password=' + encodeBase64('barbay'),
  354. '//registry.foobar.eu:username=barbaz', ''
  355. ].join('\n')
  356. fs.writeFile(npmRcPath, content, function (err) {
  357. var getAuthToken = requireUncached('../index')
  358. assert(!err, err)
  359. var token = getAuthToken()
  360. assert.deepStrictEqual(token, {
  361. token: 'YmFyYmF6OmJhcmJheQ==',
  362. type: 'Basic',
  363. password: 'barbay',
  364. username: 'barbaz'
  365. })
  366. assert.strictEqual(decodeBase64(token.token), 'barbaz:barbay')
  367. done()
  368. })
  369. })
  370. it('should fetch for the registry given (if defined)', function (done) {
  371. var content = [
  372. '//registry.foobar.eu:_authToken=barbaz',
  373. '//registry.blah.foo:_password=' + encodeBase64('barbay'),
  374. '//registry.blah.foo:username=barbaz',
  375. '//registry.last.thing:_authToken=yep', ''
  376. ].join('\n')
  377. fs.writeFile(npmRcPath, content, function (err) {
  378. var getAuthToken = requireUncached('../index')
  379. assert(!err, err)
  380. var token = getAuthToken('//registry.blah.foo')
  381. assert.deepStrictEqual(token, {
  382. token: 'YmFyYmF6OmJhcmJheQ==',
  383. type: 'Basic',
  384. password: 'barbay',
  385. username: 'barbaz'
  386. })
  387. assert.strictEqual(decodeBase64(token.token), 'barbaz:barbay')
  388. done()
  389. })
  390. })
  391. it('recursively finds registries for deep url if option is set', function (done, undef) {
  392. var opts = { recursive: true }
  393. var content = [
  394. '//registry.blah.com/foo:_password=' + encodeBase64('barbay'),
  395. '//registry.blah.com/foo:username=barbaz',
  396. '//registry.blah.eu:username=barbaz',
  397. '//registry.blah.eu:_password=' + encodeBase64('foobaz'), ''
  398. ].join('\n')
  399. fs.writeFile(npmRcPath, content, function (err) {
  400. var getAuthToken = requireUncached('../index')
  401. assert(!err, err)
  402. var token = getAuthToken('https://registry.blah.com/foo/bar/baz', opts)
  403. assert.deepStrictEqual(token, {
  404. token: 'YmFyYmF6OmJhcmJheQ==',
  405. type: 'Basic',
  406. password: 'barbay',
  407. username: 'barbaz'
  408. })
  409. assert.strictEqual(decodeBase64(token.token), 'barbaz:barbay')
  410. token = getAuthToken('https://registry.blah.eu/foo/bar/baz', opts)
  411. assert.deepStrictEqual(token, {
  412. token: 'YmFyYmF6OmZvb2Jheg==',
  413. type: 'Basic',
  414. password: 'foobaz',
  415. username: 'barbaz'
  416. })
  417. assert.strictEqual(decodeBase64(token.token), 'barbaz:foobaz')
  418. assert.strictEqual(getAuthToken('//some.registry', opts), undef)
  419. done()
  420. })
  421. })
  422. })
  423. describe('npmrc file resolution', function () {
  424. let npmRcPath
  425. beforeEach(function () {
  426. process.env.npm_config_userconfig = ''
  427. process.env.NPM_CONFIG_USERCONFIG = ''
  428. })
  429. afterEach(function (done) {
  430. process.env.npm_config_userconfig = ''
  431. process.env.NPM_CONFIG_USERCONFIG = ''
  432. fs.unlink(npmRcPath, function () {
  433. done()
  434. })
  435. })
  436. it('should use npmrc from environment npm_config_userconfig', function (done) {
  437. var content = [
  438. 'registry=http://registry.foobar.eu/',
  439. '//registry.foobar.eu/:_authToken=foobar', ''
  440. ].join('\n')
  441. npmRcPath = path.join(__dirname, '..', '.npmrc.env')
  442. process.env.NPM_CONFIG_USERCONFIG = npmRcPath
  443. fs.writeFile(npmRcPath, content, function (err) {
  444. var getAuthToken = requireUncached('../index')
  445. assert(!err, err)
  446. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Bearer' })
  447. done()
  448. })
  449. })
  450. })
  451. })