auth-token.test.js 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474
  1. var fs = require('fs')
  2. var path = require('path')
  3. var mocha = require('mocha')
  4. var assert = require('assert')
  5. var requireUncached = require('require-uncached')
  6. var npmRcPath = path.join(__dirname, '..', '.npmrc')
  7. var afterEach = mocha.afterEach
  8. var describe = mocha.describe
  9. var it = mocha.it
  10. var base64 = require('../base64')
  11. var decodeBase64 = base64.decodeBase64
  12. var encodeBase64 = base64.encodeBase64
  13. /* eslint max-nested-callbacks: ["error", 4] */
  14. describe('auth-token', function () {
  15. afterEach(function (done) {
  16. fs.unlink(npmRcPath, function () {
  17. done()
  18. })
  19. })
  20. it('should read global if no local is found', function () {
  21. var getAuthToken = requireUncached('../index')
  22. getAuthToken()
  23. })
  24. it('should return undefined if no auth token is given for registry', function (done) {
  25. fs.writeFile(npmRcPath, 'registry=http://registry.npmjs.eu/', function (err) {
  26. var getAuthToken = requireUncached('../index')
  27. assert(!err, err)
  28. assert(!getAuthToken())
  29. done()
  30. })
  31. })
  32. describe('legacy auth token', function () {
  33. it('should return auth token if it is defined in the legacy way via the `_auth` key', function (done) {
  34. var content = [
  35. '_auth=foobar',
  36. 'registry=http://registry.foobar.eu/'
  37. ].join('\n')
  38. fs.writeFile(npmRcPath, content, function (err) {
  39. var getAuthToken = requireUncached('../index')
  40. assert(!err, err)
  41. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Basic' })
  42. done()
  43. })
  44. })
  45. it('should return legacy auth token defined by reference to an environment variable (with curly braces)', function (done) {
  46. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  47. var content = [
  48. '_auth=${' + environmentVariable + '}',
  49. 'registry=http://registry.foobar.eu/'
  50. ].join('\n')
  51. process.env[environmentVariable] = 'foobar'
  52. fs.writeFile(npmRcPath, content, function (err) {
  53. var getAuthToken = requireUncached('../index')
  54. assert(!err, err)
  55. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Basic' })
  56. delete process.env[environmentVariable]
  57. done()
  58. })
  59. })
  60. it('should return legacy auth token defined by reference to an environment variable (without curly braces)', function (done) {
  61. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  62. var content = [
  63. '_auth=$' + environmentVariable,
  64. 'registry=http://registry.foobar.eu/'
  65. ].join('\n')
  66. process.env[environmentVariable] = 'foobar'
  67. fs.writeFile(npmRcPath, content, function (err) {
  68. var getAuthToken = requireUncached('../index')
  69. assert(!err, err)
  70. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Basic' })
  71. delete process.env[environmentVariable]
  72. done()
  73. })
  74. })
  75. })
  76. describe('bearer token', function () {
  77. it('should return auth token if registry is defined', function (done) {
  78. var content = [
  79. 'registry=http://registry.foobar.eu/',
  80. '//registry.foobar.eu/:_authToken=foobar', ''
  81. ].join('\n')
  82. fs.writeFile(npmRcPath, content, function (err) {
  83. var getAuthToken = requireUncached('../index')
  84. assert(!err, err)
  85. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Bearer' })
  86. done()
  87. })
  88. })
  89. it('should use npmrc passed in', function (done) {
  90. var content = [
  91. 'registry=http://registry.foobar.eu/',
  92. '//registry.foobar.eu/:_authToken=foobar', ''
  93. ].join('\n')
  94. fs.writeFile(npmRcPath, content, function (err) {
  95. var getAuthToken = requireUncached('../index')
  96. assert(!err, err)
  97. const npmrc = {
  98. 'registry': 'http://registry.foobar.eu/',
  99. '//registry.foobar.eu/:_authToken': 'qar'
  100. }
  101. assert.deepStrictEqual(getAuthToken({ npmrc: npmrc }), { token: 'qar', type: 'Bearer' })
  102. done()
  103. })
  104. })
  105. it('should return auth token if registry url has port specified', function (done) {
  106. var content = [
  107. 'registry=http://localhost:8770/',
  108. // before the patch this token was selected.
  109. '//localhost/:_authToken=ohno',
  110. '//localhost:8770/:_authToken=beepboop', ''
  111. ].join('\n')
  112. fs.writeFile(npmRcPath, content, function (err) {
  113. var getAuthToken = requireUncached('../index')
  114. assert(!err, err)
  115. assert.deepStrictEqual(getAuthToken(), { token: 'beepboop', type: 'Bearer' })
  116. done()
  117. })
  118. })
  119. it('should return auth token defined by reference to an environment variable (with curly braces)', function (done) {
  120. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  121. var content = [
  122. 'registry=http://registry.foobar.cc/',
  123. '//registry.foobar.cc/:_authToken=${' + environmentVariable + '}', ''
  124. ].join('\n')
  125. process.env[environmentVariable] = 'foobar'
  126. fs.writeFile(npmRcPath, content, function (err) {
  127. var getAuthToken = requireUncached('../index')
  128. assert(!err, err)
  129. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Bearer' })
  130. delete process.env[environmentVariable]
  131. done()
  132. })
  133. })
  134. it('should return auth token defined by reference to an environment variable (without curly braces)', function (done) {
  135. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  136. var content = [
  137. 'registry=http://registry.foobar.cc/',
  138. '//registry.foobar.cc/:_authToken=$' + environmentVariable, ''
  139. ].join('\n')
  140. process.env[environmentVariable] = 'foobar'
  141. fs.writeFile(npmRcPath, content, function (err) {
  142. var getAuthToken = requireUncached('../index')
  143. assert(!err, err)
  144. assert.deepStrictEqual(getAuthToken(), { token: 'foobar', type: 'Bearer' })
  145. delete process.env[environmentVariable]
  146. done()
  147. })
  148. })
  149. it('should try with and without a slash at the end of registry url', function (done) {
  150. var content = [
  151. 'registry=http://registry.foobar.eu',
  152. '//registry.foobar.eu:_authToken=barbaz', ''
  153. ].join('\n')
  154. fs.writeFile(npmRcPath, content, function (err) {
  155. var getAuthToken = requireUncached('../index')
  156. assert(!err, err)
  157. assert.deepStrictEqual(getAuthToken(), { token: 'barbaz', type: 'Bearer' })
  158. done()
  159. })
  160. })
  161. it('should fetch for the registry given (if defined)', function (done) {
  162. var content = [
  163. '//registry.foobar.eu:_authToken=barbaz',
  164. '//registry.blah.foo:_authToken=whatev',
  165. '//registry.last.thing:_authToken=yep', ''
  166. ].join('\n')
  167. fs.writeFile(npmRcPath, content, function (err) {
  168. var getAuthToken = requireUncached('../index')
  169. assert(!err, err)
  170. assert.deepStrictEqual(getAuthToken('//registry.blah.foo'), { token: 'whatev', type: 'Bearer' })
  171. done()
  172. })
  173. })
  174. it('recursively finds registries for deep url if option is set', function (done, undef) {
  175. var opts = { recursive: true }
  176. var content = [
  177. '//registry.blah.com/foo:_authToken=whatev',
  178. '//registry.blah.org/foo/bar:_authToken=recurseExactlyOneLevel',
  179. '//registry.blah.edu/foo/bar/baz:_authToken=recurseNoLevel',
  180. '//registry.blah.eu:_authToken=yep', ''
  181. ].join('\n')
  182. fs.writeFile(npmRcPath, content, function (err) {
  183. var getAuthToken = requireUncached('../index')
  184. assert(!err, err)
  185. assert.deepStrictEqual(getAuthToken('https://registry.blah.edu/foo/bar/baz', opts), { token: 'recurseNoLevel', type: 'Bearer' })
  186. assert.deepStrictEqual(getAuthToken('https://registry.blah.org/foo/bar/baz', opts), { token: 'recurseExactlyOneLevel', type: 'Bearer' })
  187. assert.deepStrictEqual(getAuthToken('https://registry.blah.com/foo/bar/baz', opts), { token: 'whatev', type: 'Bearer' })
  188. assert.deepStrictEqual(getAuthToken('http://registry.blah.eu/what/ever', opts), { token: 'yep', type: 'Bearer' })
  189. assert.deepStrictEqual(getAuthToken('http://registry.blah.eu//what/ever', opts), undefined, 'does not hang')
  190. assert.strictEqual(getAuthToken('//some.registry', opts), undef)
  191. done()
  192. })
  193. })
  194. it('should try both with and without trailing slash', function (done) {
  195. fs.writeFile(npmRcPath, '//registry.blah.com:_authToken=whatev', function (err) {
  196. var getAuthToken = requireUncached('../index')
  197. assert(!err, err)
  198. assert.deepStrictEqual(getAuthToken('https://registry.blah.com'), { token: 'whatev', type: 'Bearer' })
  199. done()
  200. })
  201. })
  202. it('should prefer bearer token over basic token', function (done) {
  203. var content = [
  204. 'registry=http://registry.foobar.eu/',
  205. 'registry=http://registry.foobar.eu/',
  206. '//registry.foobar.eu/:_authToken=bearerToken',
  207. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  208. '//registry.foobar.eu/:username=foobar', ''
  209. ].join('\n')
  210. fs.writeFile(npmRcPath, content, function (err) {
  211. var getAuthToken = requireUncached('../index')
  212. assert(!err, err)
  213. assert.deepStrictEqual(getAuthToken('//registry.foobar.eu'), { token: 'bearerToken', type: 'Bearer' })
  214. done()
  215. })
  216. })
  217. it('"nerf darts" registry urls', function (done, undef) {
  218. fs.writeFile(npmRcPath, '//contoso.pkgs.visualstudio.com/_packaging/MyFeed/npm/:_authToken=heider', function (err) {
  219. var getAuthToken = requireUncached('../index')
  220. assert(!err, err)
  221. assert.deepStrictEqual(
  222. getAuthToken('https://contoso.pkgs.visualstudio.com/_packaging/MyFeed/npm/registry'),
  223. { token: 'heider', type: 'Bearer' }
  224. )
  225. done()
  226. })
  227. })
  228. })
  229. describe('basic token', function () {
  230. it('should return undefined if password or username are missing', function (done, undef) {
  231. var content = [
  232. 'registry=http://registry.foobar.eu/',
  233. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  234. '//registry.foobar.com/:username=foobar', ''
  235. ].join('\n')
  236. fs.writeFile(npmRcPath, content, function (err) {
  237. var getAuthToken = requireUncached('../index')
  238. assert(!err, err)
  239. assert.strictEqual(getAuthToken('//registry.foobar.eu'), undef)
  240. assert.strictEqual(getAuthToken('//registry.foobar.com'), undef)
  241. done()
  242. })
  243. })
  244. it('should return basic token if username and password are defined', function (done) {
  245. var content = [
  246. 'registry=http://registry.foobar.eu/',
  247. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  248. '//registry.foobar.eu/:username=foobar', ''
  249. ].join('\n')
  250. fs.writeFile(npmRcPath, content, function (err) {
  251. var getAuthToken = requireUncached('../index')
  252. assert(!err, err)
  253. var token = getAuthToken()
  254. assert.deepStrictEqual(token, {
  255. token: 'Zm9vYmFyOmZvb2Jhcg==',
  256. type: 'Basic',
  257. username: 'foobar',
  258. password: 'foobar'
  259. })
  260. assert.strictEqual(decodeBase64(token.token), 'foobar:foobar')
  261. done()
  262. })
  263. })
  264. it('should return basic token if _auth is base64 encoded', function (done) {
  265. var content = [
  266. 'registry=http://registry.foobar.eu/',
  267. '//registry.foobar.eu/:_auth=' + encodeBase64('foobar:foobar')
  268. ].join('\n')
  269. fs.writeFile(npmRcPath, content, function (err) {
  270. var getAuthToken = requireUncached('../index')
  271. assert(!err, err)
  272. var token = getAuthToken()
  273. assert.deepStrictEqual(token, {
  274. token: 'Zm9vYmFyOmZvb2Jhcg==',
  275. type: 'Basic'
  276. })
  277. assert.strictEqual(decodeBase64(token.token), 'foobar:foobar')
  278. done()
  279. })
  280. })
  281. it('should return basic token if registry url has port specified', function (done) {
  282. var content = [
  283. 'registry=http://localhost:8770/',
  284. // before the patch this token was selected.
  285. '//localhost/:_authToken=ohno',
  286. '//localhost:8770/:_password=' + encodeBase64('foobar'),
  287. '//localhost:8770/:username=foobar', ''
  288. ].join('\n')
  289. fs.writeFile(npmRcPath, content, function (err) {
  290. var getAuthToken = requireUncached('../index')
  291. assert(!err, err)
  292. var token = getAuthToken()
  293. assert.deepStrictEqual(token, {
  294. token: 'Zm9vYmFyOmZvb2Jhcg==',
  295. type: 'Basic',
  296. username: 'foobar',
  297. password: 'foobar'
  298. })
  299. assert.strictEqual(decodeBase64(token.token), 'foobar:foobar')
  300. done()
  301. })
  302. })
  303. it('should return password defined by reference to an environment variable (with curly braces)', function (done) {
  304. var environmentVariable = '__REGISTRY_PASSWORD__'
  305. var content = [
  306. 'registry=http://registry.foobar.cc/',
  307. '//registry.foobar.cc/:username=username',
  308. '//registry.foobar.cc/:_password=${' + environmentVariable + '}', ''
  309. ].join('\n')
  310. process.env[environmentVariable] = encodeBase64('password')
  311. fs.writeFile(npmRcPath, content, function (err) {
  312. var getAuthToken = requireUncached('../index')
  313. assert(!err, err)
  314. var token = getAuthToken()
  315. assert.deepStrictEqual(token, {
  316. type: 'Basic',
  317. username: 'username',
  318. password: 'password',
  319. token: 'dXNlcm5hbWU6cGFzc3dvcmQ='
  320. })
  321. assert.strictEqual(decodeBase64(token.token), 'username:password')
  322. delete process.env[environmentVariable]
  323. done()
  324. })
  325. })
  326. it('should return password defined by reference to an environment variable (without curly braces)', function (done) {
  327. var environmentVariable = '__REGISTRY_PASSWORD__'
  328. var content = [
  329. 'registry=http://registry.foobar.cc/',
  330. '//registry.foobar.cc/:username=username',
  331. '//registry.foobar.cc/:_password=$' + environmentVariable, ''
  332. ].join('\n')
  333. process.env[environmentVariable] = encodeBase64('password')
  334. fs.writeFile(npmRcPath, content, function (err) {
  335. var getAuthToken = requireUncached('../index')
  336. assert(!err, err)
  337. var token = getAuthToken()
  338. assert.deepStrictEqual(token, {
  339. type: 'Basic',
  340. username: 'username',
  341. password: 'password',
  342. token: 'dXNlcm5hbWU6cGFzc3dvcmQ='
  343. })
  344. assert.strictEqual(decodeBase64(token.token), 'username:password')
  345. delete process.env[environmentVariable]
  346. done()
  347. })
  348. })
  349. it('should try with and without a slash at the end of registry url', function (done) {
  350. var content = [
  351. 'registry=http://registry.foobar.eu',
  352. '//registry.foobar.eu:_password=' + encodeBase64('barbay'),
  353. '//registry.foobar.eu:username=barbaz', ''
  354. ].join('\n')
  355. fs.writeFile(npmRcPath, content, function (err) {
  356. var getAuthToken = requireUncached('../index')
  357. assert(!err, err)
  358. var token = getAuthToken()
  359. assert.deepStrictEqual(token, {
  360. token: 'YmFyYmF6OmJhcmJheQ==',
  361. type: 'Basic',
  362. password: 'barbay',
  363. username: 'barbaz'
  364. })
  365. assert.strictEqual(decodeBase64(token.token), 'barbaz:barbay')
  366. done()
  367. })
  368. })
  369. it('should fetch for the registry given (if defined)', function (done) {
  370. var content = [
  371. '//registry.foobar.eu:_authToken=barbaz',
  372. '//registry.blah.foo:_password=' + encodeBase64('barbay'),
  373. '//registry.blah.foo:username=barbaz',
  374. '//registry.last.thing:_authToken=yep', ''
  375. ].join('\n')
  376. fs.writeFile(npmRcPath, content, function (err) {
  377. var getAuthToken = requireUncached('../index')
  378. assert(!err, err)
  379. var token = getAuthToken('//registry.blah.foo')
  380. assert.deepStrictEqual(token, {
  381. token: 'YmFyYmF6OmJhcmJheQ==',
  382. type: 'Basic',
  383. password: 'barbay',
  384. username: 'barbaz'
  385. })
  386. assert.strictEqual(decodeBase64(token.token), 'barbaz:barbay')
  387. done()
  388. })
  389. })
  390. it('recursively finds registries for deep url if option is set', function (done, undef) {
  391. var opts = { recursive: true }
  392. var content = [
  393. '//registry.blah.com/foo:_password=' + encodeBase64('barbay'),
  394. '//registry.blah.com/foo:username=barbaz',
  395. '//registry.blah.eu:username=barbaz',
  396. '//registry.blah.eu:_password=' + encodeBase64('foobaz'), ''
  397. ].join('\n')
  398. fs.writeFile(npmRcPath, content, function (err) {
  399. var getAuthToken = requireUncached('../index')
  400. assert(!err, err)
  401. var token = getAuthToken('https://registry.blah.com/foo/bar/baz', opts)
  402. assert.deepStrictEqual(token, {
  403. token: 'YmFyYmF6OmJhcmJheQ==',
  404. type: 'Basic',
  405. password: 'barbay',
  406. username: 'barbaz'
  407. })
  408. assert.strictEqual(decodeBase64(token.token), 'barbaz:barbay')
  409. token = getAuthToken('https://registry.blah.eu/foo/bar/baz', opts)
  410. assert.deepStrictEqual(token, {
  411. token: 'YmFyYmF6OmZvb2Jheg==',
  412. type: 'Basic',
  413. password: 'foobaz',
  414. username: 'barbaz'
  415. })
  416. assert.strictEqual(decodeBase64(token.token), 'barbaz:foobaz')
  417. assert.strictEqual(getAuthToken('//some.registry', opts), undef)
  418. done()
  419. })
  420. })
  421. })
  422. })