policy.test.mjs 1.7 KB

123456789101112131415161718192021222324252627282930313233
  1. import { test } from 'node:test'
  2. import assert from 'node:assert/strict'
  3. import fs from 'node:fs'
  4. import os from 'node:os'
  5. import path from 'node:path'
  6. import { checkPublicPath, checkPublicText, checkMarkdownLinks } from '../check-public-tree.mjs'
  7. import { releaseVersion } from '../version.mjs'
  8. test('public policy rejects private files and permits runtime Markdown', () => {
  9. for (const file of ['.trellis/prd.md', 'session.jsonl', 'packages/bundle/.env', '../README.md', 'packages/bundle/dsh-local.yml']) assert.throws(() => checkPublicPath(file))
  10. checkPublicPath('packages/bundle/skills/novel-director/SKILL.md')
  11. checkPublicPath('docs/user/install.md')
  12. })
  13. test('credential and personal-path checks do not echo their values', () => {
  14. for (const value of ['sk-' + 'a'.repeat(40), 'ghp_' + 'b'.repeat(40), ['C:', 'Users', 'private', 'book'].join('/')]) {
  15. assert.throws(() => checkPublicText('README.md', value), error => !error.message.includes(value))
  16. }
  17. checkPublicText('example.md', 'API key: <YOUR_API_KEY>')
  18. })
  19. test('release version binds exact tag, package and changelog', () => {
  20. const value = releaseVersion()
  21. assert.equal(value.tag, `scriptor-v${value.version}`)
  22. assert.throws(() => releaseVersion(undefined, 'v6.2.1'))
  23. })
  24. test('documentation links cannot escape the exported tree', () => {
  25. const root = fs.mkdtempSync(path.join(os.tmpdir(), 'scriptor-links-'))
  26. try {
  27. fs.writeFileSync(path.join(root, 'README.md'), 'ok')
  28. checkMarkdownLinks(root, 'README.md', '[self](README.md)')
  29. assert.throws(() => checkMarkdownLinks(root, 'README.md', '[private](../secret.md)'))
  30. assert.throws(() => checkMarkdownLinks(root, 'README.md', '[missing](missing.md)'))
  31. } finally { fs.unlinkSync(path.join(root, 'README.md')); fs.rmdirSync(root) }
  32. })