File
Blob: test/receive-invalid-ref.worker.test.ts
| 1 | import { it, expect } from "vitest"; |
| 2 | import { env } from "cloudflare:workers"; |
| 3 | import { decodePktLines, pktLine, flushPkt, concatChunks } from "@/worker/git"; |
| 4 | import { buildPack, postReceivePack, uniqueRepoId } from "./util/test-helpers"; |
| 5 | import { setupRepoForTests } from "./util/repoSeed"; |
| 6 | |
| 7 | function zero40() { |
| 8 | return "0".repeat(40); |
| 9 | } |
| 10 | |
| 11 | it("receive-pack: rejects update to HEAD ref as invalid", async () => { |
| 12 | const owner = "o"; |
| 13 | const repo = uniqueRepoId("r-push-invalid-head"); |
| 14 | await setupRepoForTests(env, owner, repo); |
| 15 | const url = `https://example.com/${owner}/${repo}/git-receive-pack`; |
| 16 | |
| 17 | // Empty pack (no objects) is sufficient to trigger ref-name validation, which happens before unpack |
| 18 | const pack = await buildPack([]); |
| 19 | const cmd = `${zero40()} ${"a".repeat(40)} HEAD\0 report-status ofs-delta agent=test\n`; |
| 20 | const body = concatChunks([pktLine(cmd), flushPkt(), pack]); |
| 21 | |
| 22 | const res = await postReceivePack(url, body); |
| 23 | expect(res.status).toBe(200); |
| 24 | const lines = decodePktLines(new Uint8Array(await res.arrayBuffer())) |
| 25 | .filter((i) => i.type === "line") |
| 26 | .map((i: any) => (i.text as string).trim()); |
| 27 | // Should report invalid ref |
| 28 | const ng = lines.find((l) => l.startsWith("ng HEAD ")); |
| 29 | expect(ng && /invalid$/.test(ng)).toBeTruthy(); |
| 30 | }); |
| 31 | |
| 32 | it("receive-pack: rejects invalid ref name with spaces", async () => { |
| 33 | const owner = "o"; |
| 34 | const repo = uniqueRepoId("r-push-invalid-ref"); |
| 35 | await setupRepoForTests(env, owner, repo); |
| 36 | const url = `https://example.com/${owner}/${repo}/git-receive-pack`; |
| 37 | |
| 38 | const pack = await buildPack([]); |
| 39 | const badRef = "refs/heads/invalid name"; // contains space |
| 40 | const cmd = `${zero40()} ${"b".repeat(40)} ${badRef}\0 report-status ofs-delta agent=test\n`; |
| 41 | const body = concatChunks([pktLine(cmd), flushPkt(), pack]); |
| 42 | |
| 43 | const res = await postReceivePack(url, body); |
| 44 | expect(res.status).toBe(200); |
| 45 | const lines = decodePktLines(new Uint8Array(await res.arrayBuffer())) |
| 46 | .filter((i) => i.type === "line") |
| 47 | .map((i: any) => (i.text as string).trim()); |
| 48 | const ng = lines.find((l) => l.startsWith(`ng ${badRef} `)); |
| 49 | expect(ng && /invalid$/.test(ng)).toBeTruthy(); |
| 50 | }); |