This commit is contained in:
@@ -154,10 +154,12 @@ build_release() {
|
||||
build_gitea_release_index() {
|
||||
local fixture=$1
|
||||
local origin=${2:-https://gitea.fixture.invalid}
|
||||
local artifact
|
||||
local artifact version tag
|
||||
artifact=$(jq -er '.artifact' "$fixture/release/release-manifest.json")
|
||||
jq -n --arg origin "$origin" --arg artifact "$artifact" \
|
||||
'{assets:[
|
||||
version=$(jq -er '.version' "$fixture/release/release-manifest.json")
|
||||
tag="v$version"
|
||||
jq -n --arg origin "$origin" --arg artifact "$artifact" --arg tag "$tag" \
|
||||
'{tag_name:$tag,assets:[
|
||||
{name:"release-manifest.json",browser_download_url:($origin + "/assets/release-manifest.json")},
|
||||
{name:"release-manifest.sig",browser_download_url:($origin + "/assets/release-manifest.sig")},
|
||||
{name:$artifact,browser_download_url:($origin + "/assets/" + $artifact)}
|
||||
@@ -267,7 +269,7 @@ assert_private_gitea_release_case() {
|
||||
|| fail 'authenticated private Gitea requests unexpectedly enabled redirects'
|
||||
}
|
||||
|
||||
assert_cross_origin_gitea_asset_rejected() {
|
||||
assert_cross_origin_gitea_browser_url_ignored() {
|
||||
local fixture="$WORK/cross-origin-gitea"
|
||||
local version='1.0.0-preview.2'
|
||||
mkdir -p "$fixture"
|
||||
@@ -276,18 +278,16 @@ assert_cross_origin_gitea_asset_rejected() {
|
||||
build_gitea_release_index "$fixture" https://assets.fixture.invalid
|
||||
prepare_installation "$fixture" "$version"
|
||||
|
||||
if FIXTURE_RELEASE_BASE_URL='' \
|
||||
FIXTURE_RELEASE_BASE_URL='' \
|
||||
FIXTURE_RELEASE_API_URL=https://gitea.fixture.invalid/api/v1/repos/ERP-Team/kaidi/releases/latest \
|
||||
FIXTURE_RELEASE_ORIGIN=https://gitea.fixture.invalid \
|
||||
FIXTURE_RELEASE_TOKEN=fixture-read-only-token \
|
||||
MOCK_CURL_LOG="$fixture/curl.log" \
|
||||
run_update "$fixture" success > "$fixture/update.log" 2>&1; then
|
||||
fail 'cross-origin Gitea asset unexpectedly succeeded'
|
||||
fi
|
||||
grep -q 'Release manifest asset is missing' "$fixture/update.log" \
|
||||
|| fail 'cross-origin Gitea asset rejection was not reported'
|
||||
run_update "$fixture" success
|
||||
[ "$(jq -r '.state' "$fixture/state/status.json")" = READY ] \
|
||||
|| fail 'misconfigured browser download URL prevented trusted same-origin download'
|
||||
! grep -Fq 'assets.fixture.invalid' "$fixture/curl.log" \
|
||||
|| fail 'cross-origin Gitea asset was requested'
|
||||
|| fail 'cross-origin browser download URL was requested'
|
||||
}
|
||||
|
||||
assert_success_case() {
|
||||
@@ -430,5 +430,5 @@ assert_database_failure_case
|
||||
assert_symlink_request_rejected
|
||||
assert_install_without_verified_cache_rejected
|
||||
assert_private_gitea_release_case
|
||||
assert_cross_origin_gitea_asset_rejected
|
||||
assert_cross_origin_gitea_browser_url_ignored
|
||||
printf 'Online update download, confirmation, success, rollback, failure, and unsafe-request fixtures passed\n'
|
||||
|
||||
Reference in New Issue
Block a user