radroots_sdk_boundary_inventory.test.mjs (1408B)
1 import assert from "node:assert/strict"; 2 import { mkdirSync, mkdtempSync, writeFileSync } from "node:fs"; 3 import { tmpdir } from "node:os"; 4 import { dirname, join } from "node:path"; 5 import test from "node:test"; 6 7 import { 8 GENERATED_FILES, 9 validateProductionSources, 10 validateTrackedInventory, 11 } from "./radroots_sdk_boundary_lib.mjs"; 12 13 test("generated source inventory is exact", () => { 14 assert.doesNotThrow(() => validateTrackedInventory(GENERATED_FILES)); 15 assert.throws( 16 () => validateTrackedInventory(GENERATED_FILES.slice(1)), 17 /generated source inventory is not exact/, 18 ); 19 assert.throws( 20 () => validateTrackedInventory([...GENERATED_FILES, "generated/extra.ts"]), 21 /generated source inventory is not exact/, 22 ); 23 }); 24 25 test("tracked credential paths fail closed", () => { 26 assert.throws( 27 () => validateTrackedInventory([...GENERATED_FILES, "packages/core/.env"]), 28 /sensitive credential path is tracked/, 29 ); 30 }); 31 32 test("production credential material fails closed", () => { 33 const root = mkdtempSync(join(tmpdir(), "radroots-sdk-boundary-")); 34 const path = "packages/core/src/index.ts"; 35 mkdirSync(dirname(join(root, path)), { recursive: true }); 36 writeFileSync(join(root, path), `export const leaked = "AKIAABCDEFGHIJKLMNOP";\n`); 37 assert.throws( 38 () => validateProductionSources(root, [path]), 39 /production source contains credential material/, 40 ); 41 });