Files
msd-core/tests/prepush-enterprise-email-hook.test.cjs
Jakub Zych a9a7a328e6 refactor: hard-fork GSD -> MSD (Make Software Done)
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00

105 lines
3.2 KiB
JavaScript

'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const { runHook } = require('./helpers/process-seam.cjs');
const { throwIfFailed } = require('./helpers/git-fixture.cjs');
const { createTempDir, cleanup } = require('./helpers.cjs');
const ROOT = path.resolve(__dirname, '..');
const HOOK_PATH = path.join(ROOT, '.githooks', 'pre-push');
// #3271: class-norm timeout, HOOK_FANOUT_TIMEOUT_MS not a per-suite value — see
// helpers/timeouts.cjs. This file is the fan-out class: the hook runs under
// `bash` and shells to a mock `git` that is itself a bash script, so a single
// runHook call is several nested spawns, not the single short probe the base
// PROBE_TIMEOUT_MS class describes.
const { HOOK_FANOUT_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
/**
* Write a mock bash script to a .sh file in tmpDir and return its absolute path.
* The hook invokes it via GIT_OVERRIDE — bash executes the path directly via the
* env-var seam, bypassing PATH entirely. No NTFS execute-ACL fight, no MSYS2
* PATH-type inheritance dance needed.
*/
function writeMock(tmpDir, name, content) {
const filePath = path.join(tmpDir, `${name}.sh`);
fs.writeFileSync(filePath, content, { mode: 0o755 });
return filePath;
}
describe('.githooks/pre-push enterprise email guard', () => {
test('blocks push when any to-be-pushed commit matches local blocked regex', (t) => {
const tmpDir = createTempDir('msd-prepush-hook-');
t.after(() => cleanup(tmpDir));
const mockGit = writeMock(tmpDir, 'git', `#!/usr/bin/env bash
set -euo pipefail
if [[ "$1" == "rev-list" ]]; then
echo "c1"
echo "c2"
exit 0
fi
if [[ "$1" == "show" ]]; then
commit="$(printf '%s\n' "$@" | tail -n 1)"
if [[ "$commit" == "c1" ]]; then
echo "trekkie@nomorestars.com"
else
echo "person@example-corp.com"
fi
exit 0
fi
exit 1
`);
assert.throws(() => {
const r = runHook(HOOK_PATH, [], {
interpreter: 'bash',
cwd: ROOT,
env: {
...process.env,
GIT_OVERRIDE: mockGit,
MSD_BLOCKED_AUTHOR_REGEX: '@example-corp\\.com$',
},
input: 'refs/heads/pr refs-local-sha refs/heads/pr refs-remote-sha\n',
timeoutMs: HOOK_FANOUT_TIMEOUT_MS,
});
throwIfFailed(r, `bash ${HOOK_PATH}`);
}, /Push blocked: commit author email matched local blocked regex/);
});
test('allows push when to-be-pushed commits are non-enterprise emails', (t) => {
const tmpDir = createTempDir('msd-prepush-hook-');
t.after(() => cleanup(tmpDir));
const mockGit = writeMock(tmpDir, 'git', `#!/usr/bin/env bash
set -euo pipefail
if [[ "$1" == "rev-list" ]]; then
echo "c1"
echo "c2"
exit 0
fi
if [[ "$1" == "show" ]]; then
echo "trekkie@nomorestars.com"
exit 0
fi
exit 1
`);
const r = runHook(HOOK_PATH, [], {
interpreter: 'bash',
cwd: ROOT,
env: {
...process.env,
GIT_OVERRIDE: mockGit,
MSD_BLOCKED_AUTHOR_REGEX: '@example-corp\\.com$',
},
input: 'refs/heads/pr refs-local-sha refs/heads/pr refs-remote-sha\n',
timeoutMs: HOOK_FANOUT_TIMEOUT_MS,
});
throwIfFailed(r, `bash ${HOOK_PATH}`);
});
});