import assert from "node:assert/strict"; import { test } from "node:test"; // What the forge's holder does for a delivery (novox/hq ADR 0239): a note appended once, in the forge's own // repository as its own user; one view per pull request; only the mesh's statuses. test("a note line is appended once, as the forge's user, in its own repository", async () => { const { appendNote, noteArgs } = await import("../delivery.ts"); const notes: Record = {}; const calls: string[][] = []; const runner = async (file: string, args: string[]) => { calls.push([file, ...args]); const commit = args[args.length - 1]; if (args.includes("show")) { const lines = notes[commit]; return lines ? { stdout: lines.join("\n") + "\n", code: 0 } : { stdout: "", code: 1 }; } const line = args[args.indexOf("-m") + 1]; (notes[commit] ??= []).push(line); return { stdout: "", code: 0 }; }; const sha = "0123456789abcdef0123456789abcdef01234567"; assert.deepEqual(await appendNote(runner, "gitea", "Novox", "Mesh-Catalog", sha, "mesh-plan", "a -> b\n(merged)"), { added: true, lines: 1 }); assert.deepEqual(await appendNote(runner, "gitea", "Novox", "Mesh-Catalog", sha, "mesh-plan", "a -> b (merged)"), { added: false, lines: 1 }, "the same line twice adds nothing"); assert.deepEqual(await appendNote(runner, "gitea", "Novox", "Mesh-Catalog", sha, "mesh-plan", "b -> c"), { added: true, lines: 2 }); const append = calls.find((c) => c.includes("append"))!; assert.deepEqual(append.slice(0, 7), ["docker", "exec", "-u", "git", "gitea", "git", "--git-dir"]); assert.equal(append[7], "/data/git/repositories/novox/mesh-catalog.git"); assert.ok(append.includes("--ref=mesh-plan")); assert.throws(() => noteArgs("gitea", "novox", "x; rm -rf /", sha, "mesh-plan"), /not a repository/); assert.throws(() => noteArgs("gitea", "novox", "x", "HEAD", "mesh-plan"), /not a commit/); assert.throws(() => noteArgs("gitea", "novox", "x", sha, "../commits"), /not a notes ref/); }); test("a note that cannot be written is said, never read as written", async () => { const { appendNote } = await import("../delivery.ts"); const runner = async (_file: string, args: string[]) => ({ stdout: "", code: args.includes("append") ? 128 : 1 }); await assert.rejects(appendNote(runner, "gitea", "novox", "x", "abcdef1234567", "mesh-plan", "l"), /could not be appended/); }); test("one view per pull request, found by its marker; only the mesh's statuses", async () => { const { viewBody, viewComment, deliveryStatus, VIEW_MARKER } = await import("../delivery.ts"); assert.ok(viewBody("**Delivery**").startsWith(VIEW_MARKER)); assert.equal(viewBody(`${VIEW_MARKER}\nx`), `${VIEW_MARKER}\nx`, "a marked body is kept as it is"); const comments = [{ id: 1, body: "a review" }, { id: 2, body: `${VIEW_MARKER}\nold` }, { id: 3, body: `${VIEW_MARKER}\nlater` }]; assert.equal(viewComment(comments)?.id, 2); assert.equal(viewComment([{ id: 1, body: "x" }]), undefined); const s = deliveryStatus("mesh/delivery", "pending", "y".repeat(300), "https://forge.invalid/novox/x/pulls/1"); assert.ok(s.description.length <= 140 && s.target_url); assert.throws(() => deliveryStatus("ci/other", "success", "x"), /mesh's own/); assert.throws(() => deliveryStatus("mesh/delivery", "green", "x"), /not a status/); assert.equal(deliveryStatus("mesh/delivery", "success", "x", "javascript:alert(1)").target_url, undefined); });