sdk

Radroots SDK and bindings
git clone https://radroots.dev/git/sdk.git
Log | Files | Refs | README

radroots_sdk_boundary_inventory.test.mjs (1408B)


      1 import assert from "node:assert/strict";
      2 import { mkdirSync, mkdtempSync, writeFileSync } from "node:fs";
      3 import { tmpdir } from "node:os";
      4 import { dirname, join } from "node:path";
      5 import test from "node:test";
      6 
      7 import {
      8   GENERATED_FILES,
      9   validateProductionSources,
     10   validateTrackedInventory,
     11 } from "./radroots_sdk_boundary_lib.mjs";
     12 
     13 test("generated source inventory is exact", () => {
     14   assert.doesNotThrow(() => validateTrackedInventory(GENERATED_FILES));
     15   assert.throws(
     16     () => validateTrackedInventory(GENERATED_FILES.slice(1)),
     17     /generated source inventory is not exact/,
     18   );
     19   assert.throws(
     20     () => validateTrackedInventory([...GENERATED_FILES, "generated/extra.ts"]),
     21     /generated source inventory is not exact/,
     22   );
     23 });
     24 
     25 test("tracked credential paths fail closed", () => {
     26   assert.throws(
     27     () => validateTrackedInventory([...GENERATED_FILES, "packages/core/.env"]),
     28     /sensitive credential path is tracked/,
     29   );
     30 });
     31 
     32 test("production credential material fails closed", () => {
     33   const root = mkdtempSync(join(tmpdir(), "radroots-sdk-boundary-"));
     34   const path = "packages/core/src/index.ts";
     35   mkdirSync(dirname(join(root, path)), { recursive: true });
     36   writeFileSync(join(root, path), `export const leaked = "AKIAABCDEFGHIJKLMNOP";\n`);
     37   assert.throws(
     38     () => validateProductionSources(root, [path]),
     39     /production source contains credential material/,
     40   );
     41 });