587ff2cf47
Publish snapshot / snapshot (push) Failing after 1m58s
Publishing infrastructure - Three Gitea workflows: ci.yml (PRs, non-main pushes), publish-snapshot.yml (main -> Gitea under dist-tag @main) and release.yml (tags -> Gitea + npmjs) - Tag-driven releases as <package-dir>-v<version>; the manifest stays the source of truth and release.yml refuses to run if tag and manifest disagree - Every publish is idempotent: each step checks the registry first, so a run that fails on the second registry can simply be re-run - Hard coverage gate (85% branches) shared by CI, the pre-push hook and local runs, since the thresholds live in vitest.config.ts rather than a CI flag - README.PUBLISH.md documents the whole mechanism Toolchain - TypeScript 7 native compiler; drop tsgo and ts-node, use tsx for dev runs - Biome 1.9 -> 2.x, Vitest 1 -> 4, zod 3 -> 4, inquirer 8 -> 14, pnpm 11.17.0 - Replace inquirer-checkbox-plus-prompt, which is peer-capped at inquirer <9, with enquirer's AutoComplete; the CubeSelection contract is unchanged - Stand in for zod 4's removed z.AnyZodObject with a local AnyObjectSchema Repo hygiene - Stop tracking dist/; ignore coverage/, *.tsbuildinfo, .npmrc* and release.json - Drop package-lock.json in favour of pnpm-lock.yaml Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
80 lines
2.4 KiB
TypeScript
80 lines
2.4 KiB
TypeScript
/**
|
|
* Tests for extractAgePublicKey.
|
|
*
|
|
* Runs against real files in a temp directory: the function is a thin wrapper
|
|
* around fs plus a regex, and faking fs would only test the fake.
|
|
*/
|
|
|
|
import fs from 'node:fs';
|
|
import os from 'node:os';
|
|
import path from 'node:path';
|
|
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
|
|
import { extractAgePublicKey } from '../src/keyman.utils.js';
|
|
|
|
describe('extractAgePublicKey', () => {
|
|
let tmpDir: string;
|
|
let errorSpy: ReturnType<typeof vi.spyOn>;
|
|
|
|
const keyFile = (contents: string) => {
|
|
const file = path.join(tmpDir, 'age.key');
|
|
fs.writeFileSync(file, contents);
|
|
return file;
|
|
};
|
|
|
|
beforeEach(() => {
|
|
tmpDir = fs.realpathSync(fs.mkdtempSync(path.join(os.tmpdir(), 'keyman-utils-')));
|
|
errorSpy = vi.spyOn(console, 'error').mockImplementation(() => {});
|
|
});
|
|
|
|
afterEach(() => {
|
|
vi.restoreAllMocks();
|
|
fs.rmSync(tmpDir, { recursive: true, force: true });
|
|
});
|
|
|
|
it('returns the public key from a standard age key file', () => {
|
|
const file = keyFile(
|
|
[
|
|
'# created: 2026-01-01T00:00:00Z',
|
|
'# public key: age1abc123xyz',
|
|
'AGE-SECRET-KEY-1QQQ',
|
|
].join('\n')
|
|
);
|
|
|
|
expect(extractAgePublicKey(file)).toBe('age1abc123xyz');
|
|
});
|
|
|
|
it('tolerates extra whitespace after the label', () => {
|
|
const file = keyFile('# public key: age1spaced\n');
|
|
|
|
expect(extractAgePublicKey(file)).toBe('age1spaced');
|
|
});
|
|
|
|
it('returns null and reports when the file does not exist', () => {
|
|
const missing = path.join(tmpDir, 'nope.key');
|
|
|
|
expect(extractAgePublicKey(missing)).toBeNull();
|
|
expect(errorSpy.mock.calls[0][0]).toContain('Age key file not found');
|
|
});
|
|
|
|
it('returns null when the file has no public key line', () => {
|
|
const file = keyFile('AGE-SECRET-KEY-1QQQ\n');
|
|
|
|
expect(extractAgePublicKey(file)).toBeNull();
|
|
expect(errorSpy).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it('ignores a key that is not on its own line', () => {
|
|
const file = keyFile('prefix # public key: age1inline\n');
|
|
|
|
expect(extractAgePublicKey(file)).toBeNull();
|
|
});
|
|
|
|
it('returns null and reports when the file cannot be read', () => {
|
|
const asDirectory = path.join(tmpDir, 'age.key');
|
|
fs.mkdirSync(asDirectory);
|
|
|
|
expect(extractAgePublicKey(asDirectory)).toBeNull();
|
|
expect(errorSpy.mock.calls[0][0]).toContain('Failed to read key file');
|
|
});
|
|
});
|