Skip to content
100 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Settings: fine-grained tokens, workspace token Admin, workspace personal access token rules1import assert from "node:assert/strict";
2import { test } from "node:test";
3
4import { PERMISSIONS } from "@g1t/contracts/fine-grained";
5
6import {
7 accessLabel,
8 expiryChoices,
9 fineGrainedFromForm,
10 lifetimeFromForm,
11 permissionChips,
12 permissionsFor,
13 policyNote,
14 reachSummary,
15 statusBadge,
16} from "./fine-grained.ts";
17
18function form(fields: Record<string, string | string[]>) {
19 return {
20 get: (name: string) => {
21 const value = fields[name];
22 return Array.isArray(value) ? (value[0] ?? null) : (value ?? null);
23 },
24 getAll: (name: string) => {
25 const value = fields[name];
26 return value === undefined ? [] : Array.isArray(value) ? value : [value];
27 },
28 };
29}
30
31const policy = { allowClassic: true, allowFineGrained: true, requireApproval: true, maxLifetimeDays: null, forbidNoExpiry: false };
32
33test("a workspace's token reads its form into permissions, always with metadata", () => {
34 const parsed = fineGrainedFromForm(
35 form({
36 name: "release bot",
37 owner: "Acme",
38 expires: "30",
39 repository_selection: "selected",
40 repo: ["web", "acme/api", "web"],
41 "perm.contents": "write",
42 "perm.issues": "none",
43 "perm.workflows": "write",
44 // Not for a workspace: left out.
45 "perm.email_addresses": "write",
46 }),
47 );
48 assert.ok(parsed.ok);
49 assert.equal(parsed.value.workspace, "acme");
50 assert.equal(parsed.value.ttlSeconds, 30 * 86_400);
51 assert.deepEqual(parsed.value.repositories, ["web", "acme/api"]);
52 assert.deepEqual(parsed.value.permissions, { contents: "write", workflows: "write", metadata: "read" });
53});
54
55test("your own account takes only account permissions and no repositories", () => {
56 const parsed = fineGrainedFromForm(form({ name: "inbox", owner: "", expires: "7", "perm.notifications": "write", "perm.contents": "write" }));
57 assert.ok(parsed.ok);
58 assert.equal(parsed.value.workspace, null);
59 assert.equal(parsed.value.repositorySelection, "public");
60 assert.deepEqual(parsed.value.permissions, { notifications: "write" });
61 assert.equal(fineGrainedFromForm(form({ name: "x", owner: "", expires: "7" })).ok, false, "at least one permission");
62});
63
64test("mistakes are named", () => {
65 assert.match((fineGrainedFromForm(form({ owner: "acme" })) as { error: string }).error, /Name/);
66 assert.match((fineGrainedFromForm(form({ name: "x", owner: "acme", expires: "400" })) as { error: string }).error, /366/);
67 assert.match((fineGrainedFromForm(form({ name: "x", owner: "acme", expires: "30", repository_selection: "selected" })) as { error: string }).error, /repository/);
68 assert.match((fineGrainedFromForm(form({ name: "x", owner: "acme", expires: "30", "perm.workflows": "read" })) as { error: string }).error, /Workflows/);
69});
70
71test("the form offers each group to the right resource owner", () => {
72 assert.ok(permissionsFor(true).every((permission) => permission.group !== "account"));
73 assert.ok(permissionsFor(false).every((permission) => permission.group === "account"));
74 assert.equal(permissionsFor(true).length + permissionsFor(false).length, PERMISSIONS.length);
75 assert.equal(accessLabel("write", PERMISSIONS.find((p) => p.name === "workflows")), "Write");
76 assert.equal(accessLabel("write", PERMISSIONS.find((p) => p.name === "contents")), "Read and write");
77});
78
79test("lifetimes follow the workspace's rules", () => {
80 assert.deepEqual(expiryChoices(null), [7, 30, 60, 90, 180, 366]);
81 assert.deepEqual(expiryChoices({ ...policy, maxLifetimeDays: 90 }), [7, 30, 60, 90]);
82 assert.deepEqual(expiryChoices({ ...policy, maxLifetimeDays: 45 }), [7, 30, 45]);
83 assert.deepEqual(lifetimeFromForm(""), { ok: true, value: null });
84 assert.deepEqual(lifetimeFromForm("90"), { ok: true, value: 90 });
85 assert.equal(lifetimeFromForm("0").ok, false);
86});
87
88test("lists read a fine-grained token in a line", () => {
89 const token = {
90 id: "tok_1", name: "ci", createdAt: "", lastUsedAt: null, createdBy: null, scopes: [], legacy: false, expiresAt: null,
91 fineGrained: { workspace: "acme", repositorySelection: "selected" as const, repositories: ["acme/web", "acme/api"], permissions: { metadata: "read" as const, issues: "read" as const, contents: "write" as const }, status: "pending" as const },
92 };
93 assert.equal(reachSummary(token), "acme · 2 repositories");
94 assert.deepEqual(permissionChips(token.fineGrained.permissions), ["Contents: write", "Issues: read"]);
95 assert.deepEqual(statusBadge("pending"), { label: "Pending approval", tone: "warn" });
96 assert.equal(statusBadge("active"), null);
97 assert.match(policyNote("acme", policy, false) ?? "", /must approve/);
98 assert.equal(policyNote("acme", policy, true), null, "owners' own tokens never wait");
99 assert.match(policyNote("acme", { ...policy, allowFineGrained: false }, true) ?? "", /does not allow/);
100});