|
1 | 1 | import { describe, expect, it } from 'vitest'; |
2 | | -import { execFileSync } from 'node:child_process'; |
3 | | -import { existsSync, mkdtempSync, rmSync, symlinkSync } from 'node:fs'; |
| 2 | +import { execFile, execFileSync } from 'node:child_process'; |
| 3 | +import { promisify } from 'node:util'; |
| 4 | +import { copyFileSync, existsSync, mkdtempSync, rmSync, symlinkSync, writeFileSync } from 'node:fs'; |
| 5 | +import { createServer } from 'node:http'; |
| 6 | +import type { AddressInfo } from 'node:net'; |
4 | 7 | import { fileURLToPath } from 'node:url'; |
5 | 8 | import { tmpdir } from 'node:os'; |
6 | 9 | import path from 'node:path'; |
@@ -78,4 +81,100 @@ describe.skipIf(!built)('the packaged bin, invoked as npm invokes it', () => { |
78 | 81 | })); |
79 | 82 | expect(pkg['patchstack-connect']).toBe('./dist/cli.js'); |
80 | 83 | }); |
| 84 | + |
| 85 | + /** |
| 86 | + * A report the server refuses must not fail the build `scan` is hooked into, and must fail a direct run. |
| 87 | + * |
| 88 | + * Driven through the real bin against a local server that refuses everything, because the decision sits |
| 89 | + * between the network failure and the process exit code, and only the process can show both. |
| 90 | + */ |
| 91 | + describe('a report the server refuses', () => { |
| 92 | + async function refusingServer(): Promise<{ endpoint: string; close: () => Promise<void> }> { |
| 93 | + const server = createServer((_req, res) => { |
| 94 | + res.writeHead(401, { 'Content-Type': 'application/json' }); |
| 95 | + res.end('{"error":"unauthorized"}'); |
| 96 | + }); |
| 97 | + await new Promise<void>((resolve) => server.listen(0, '127.0.0.1', resolve)); |
| 98 | + const { port } = server.address() as AddressInfo; |
| 99 | + |
| 100 | + return { |
| 101 | + endpoint: `http://127.0.0.1:${port}/monitor/pulse/manifest`, |
| 102 | + close: () => new Promise<void>((resolve) => server.close(() => resolve())), |
| 103 | + }; |
| 104 | + } |
| 105 | + |
| 106 | + // An existing site with no credential anywhere: the state a deploy is in when the credential file |
| 107 | + // stayed behind on the developer's machine. |
| 108 | + function projectWithSite(): string { |
| 109 | + const dir = mkdtempSync(path.join(tmpdir(), 'ps-bin-hook-')); |
| 110 | + writeFileSync( |
| 111 | + path.join(dir, 'package.json'), |
| 112 | + JSON.stringify({ name: 'example-app', version: '1.0.0', dependencies: { axios: '^1.6.0', lodash: '^4.17.21' } }), |
| 113 | + ); |
| 114 | + copyFileSync(path.join(root, 'tests', 'fixtures', 'package-lock-v3.json'), path.join(dir, 'package-lock.json')); |
| 115 | + writeFileSync(path.join(dir, '.patchstackrc.json'), JSON.stringify({ siteUuid: '11111111-1111-4111-8111-111111111111' })); |
| 116 | + |
| 117 | + return dir; |
| 118 | + } |
| 119 | + |
| 120 | + // The environment is built from scratch rather than inherited: the parent may itself be running under |
| 121 | + // a package manager, and the lifecycle name it exported is the very thing under test. Asynchronous |
| 122 | + // because the refusing server lives on this thread's event loop, and a blocking spawn would starve it. |
| 123 | + async function runScan( |
| 124 | + cwd: string, |
| 125 | + endpoint: string, |
| 126 | + lifecycleEvent?: string, |
| 127 | + ): Promise<{ status: number; stderr: string }> { |
| 128 | + const env: NodeJS.ProcessEnv = { |
| 129 | + PATH: process.env.PATH, |
| 130 | + HOME: process.env.HOME, |
| 131 | + PATCHSTACK_ENDPOINT: endpoint, |
| 132 | + PATCHSTACK_TIMEOUT_MS: '5000', |
| 133 | + }; |
| 134 | + if (lifecycleEvent !== undefined) env.npm_lifecycle_event = lifecycleEvent; |
| 135 | + |
| 136 | + try { |
| 137 | + const { stderr } = await promisify(execFile)('node', [bin, 'scan'], { cwd, env, encoding: 'utf8' }); |
| 138 | + |
| 139 | + return { status: 0, stderr }; |
| 140 | + } catch (err) { |
| 141 | + const failed = err as { code?: unknown; stderr?: unknown }; |
| 142 | + |
| 143 | + return { |
| 144 | + status: typeof failed.code === 'number' ? failed.code : -1, |
| 145 | + stderr: typeof failed.stderr === 'string' ? failed.stderr : '', |
| 146 | + }; |
| 147 | + } |
| 148 | + } |
| 149 | + |
| 150 | + it('exits 0 from a build hook and says what was not reported', async () => { |
| 151 | + const server = await refusingServer(); |
| 152 | + const dir = projectWithSite(); |
| 153 | + try { |
| 154 | + const result = await runScan(dir, server.endpoint, 'build'); |
| 155 | + |
| 156 | + expect(result.status).toBe(0); |
| 157 | + expect(result.stderr).toContain('manifest not reported'); |
| 158 | + expect(result.stderr).toContain('PATCHSTACK_API_KEY'); |
| 159 | + } finally { |
| 160 | + await server.close(); |
| 161 | + rmSync(dir, { recursive: true, force: true }); |
| 162 | + } |
| 163 | + }); |
| 164 | + |
| 165 | + it('exits 1 for the same refusal when run directly', async () => { |
| 166 | + const server = await refusingServer(); |
| 167 | + const dir = projectWithSite(); |
| 168 | + try { |
| 169 | + const result = await runScan(dir, server.endpoint); |
| 170 | + |
| 171 | + expect(result.status).toBe(1); |
| 172 | + expect(result.stderr).toContain('Error (UNAUTHORIZED)'); |
| 173 | + expect(result.stderr).not.toContain('continuing the build'); |
| 174 | + } finally { |
| 175 | + await server.close(); |
| 176 | + rmSync(dir, { recursive: true, force: true }); |
| 177 | + } |
| 178 | + }); |
| 179 | + }); |
81 | 180 | }); |
0 commit comments