mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
The v3.0.1 authorization fix is intentionally small. Follow it with a separate structural pass so the implementation and documentation express the present-tense maintainer model directly instead of leaving the security behavior hidden behind owner-oriented names and repeated raw-tag interpretation.
Parse indexed roles once into a current-only snapshot of active maintainers, active lead targets, and announcement-author activity. Preserve detailed lead-resolution failures internally while policy callers continue to fail closed, distinguish selected authorization coordinates from physical owner views, and name broad announcement admission as discovery rather than authority.
Keep history relevant only while deriving current activity and retain active leads only for selected-coordinate resolution. Preserve the v3.0 public API through compatibility projections and deprecated aliases; this commit is not intended to change the authorization outcome established by 650cfb57.
Refresh architecture, inline authorization, storage, sync, and audit documentation. Correct the audit fixture description that claimed a listed maintainer authorized with no reciprocal announcement even though its setup already published one.
Validated with cargo test --lib (903 tests), cargo test --test state_authorization (53 tests), cargo test -p grasp-audit --lib (54 passed, 5 ignored), cargo test --test push_authorization (56 tests), and cargo clippy --tests -- -D warnings.
75 lines
2.8 KiB
Rust
75 lines
2.8 KiB
Rust
//! Push Authorization Integration Tests
|
|
//!
|
|
//! Tests that verify push authorization state events work correctly.
|
|
//!
|
|
//! # Test Strategy
|
|
//!
|
|
//! - Each test runs in complete isolation with its own fresh relay instance
|
|
//! - Uses macro to eliminate boilerplate while maintaining test isolation
|
|
//! - Calls individual test methods from grasp-audit for minimal duplication
|
|
//! - Automatic cleanup via TestRelay fixture (removes container and temp dirs)
|
|
//!
|
|
//! # Running Tests
|
|
//!
|
|
//! ```bash
|
|
//! # Run all push authorization tests
|
|
//! cargo test --test push_authorization
|
|
//!
|
|
//! # Run specific test
|
|
//! cargo test --test push_authorization test_push_authorized_by_owner_state
|
|
//!
|
|
//! # With output
|
|
//! cargo test --test push_authorization -- --nocapture
|
|
//! ```
|
|
|
|
mod common;
|
|
|
|
use common::TestRelay;
|
|
use grasp_audit::specs::grasp01::PushAuthorizationTests;
|
|
use grasp_audit::*;
|
|
|
|
/// Macro to generate isolated integration tests for push authorization
|
|
///
|
|
/// Each test runs with its own fresh relay instance to ensure complete isolation.
|
|
/// This eliminates issues with leftover repositories and ensures clean state.
|
|
/// Push authorization tests require git_data_dir and relay_domain parameters.
|
|
macro_rules! isolated_push_test {
|
|
($test_name:ident) => {
|
|
#[tokio::test]
|
|
async fn $test_name() {
|
|
let relay = TestRelay::start().await;
|
|
let config = AuditConfig::isolated();
|
|
let client = AuditClient::new(relay.url(), config)
|
|
.await
|
|
.expect("Failed to create audit client");
|
|
|
|
let result = PushAuthorizationTests::$test_name(&client, &relay.domain()).await;
|
|
|
|
relay.stop().await;
|
|
|
|
assert!(
|
|
result.passed,
|
|
"{} failed: {}",
|
|
stringify!($test_name),
|
|
result.error.as_deref().unwrap_or("unknown error")
|
|
);
|
|
}
|
|
};
|
|
}
|
|
|
|
// Generate isolated tests for all push authorization tests
|
|
isolated_push_test!(test_push_rejected_without_state_event);
|
|
isolated_push_test!(test_push_authorized_by_owner_state);
|
|
isolated_push_test!(test_push_rejected_wrong_commit);
|
|
isolated_push_test!(test_push_authorized_by_confirmed_maintainer_state);
|
|
isolated_push_test!(test_push_authorized_by_recursive_maintainer_state);
|
|
isolated_push_test!(test_push_to_nostr_ref_with_invalid_event_id_rejected);
|
|
isolated_push_test!(test_pr_push_to_nostr_ref_with_wrong_commit_accepted_before_event_received);
|
|
isolated_push_test!(test_pr_event_published_removes_nostr_ref_at_incorrect_commit);
|
|
isolated_push_test!(test_push_to_nostr_ref_with_wrong_commit_after_event_received_rejected);
|
|
isolated_push_test!(
|
|
test_push_to_nostr_ref_with_correct_commit_after_event_received_accepted_and_event_served
|
|
);
|
|
isolated_push_test!(test_head_set_after_state_event_with_existing_commit);
|
|
isolated_push_test!(test_head_set_after_git_push_with_required_oids);
|