auth-token.test.js 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455
  1. var fs = require('fs')
  2. var path = require('path')
  3. var mocha = require('mocha')
  4. var assert = require('assert')
  5. var requireUncached = require('require-uncached')
  6. var npmRcPath = path.join(__dirname, '..', '.npmrc')
  7. var afterEach = mocha.afterEach
  8. var describe = mocha.describe
  9. var it = mocha.it
  10. var base64 = require('../base64')
  11. var decodeBase64 = base64.decodeBase64
  12. var encodeBase64 = base64.encodeBase64
  13. /* eslint max-nested-callbacks: ["error", 4] */
  14. describe('auth-token', function () {
  15. afterEach(function (done) {
  16. fs.unlink(npmRcPath, function () {
  17. done()
  18. })
  19. })
  20. it('should read global if no local is found', function () {
  21. var getAuthToken = requireUncached('../index')
  22. getAuthToken()
  23. })
  24. it('should return undefined if no auth token is given for registry', function (done) {
  25. fs.writeFile(npmRcPath, 'registry=http://registry.npmjs.eu/', function (err) {
  26. var getAuthToken = requireUncached('../index')
  27. assert(!err, err)
  28. assert(!getAuthToken())
  29. done()
  30. })
  31. })
  32. describe('legacy auth token', function () {
  33. it('should return auth token if it is defined in the legacy way via the `_auth` key', function (done) {
  34. var content = [
  35. '_auth=foobar',
  36. 'registry=http://registry.foobar.eu/'
  37. ].join('\n')
  38. fs.writeFile(npmRcPath, content, function (err) {
  39. var getAuthToken = requireUncached('../index')
  40. assert(!err, err)
  41. assert.deepEqual(getAuthToken(), {token: 'foobar', type: 'Basic'})
  42. done()
  43. })
  44. })
  45. it('should return legacy auth token defined by reference to an environment variable (with curly braces)', function (done) {
  46. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  47. var content = [
  48. '_auth=${' + environmentVariable + '}',
  49. 'registry=http://registry.foobar.eu/'
  50. ].join('\n')
  51. process.env[environmentVariable] = 'foobar'
  52. fs.writeFile(npmRcPath, content, function (err) {
  53. var getAuthToken = requireUncached('../index')
  54. assert(!err, err)
  55. assert.deepEqual(getAuthToken(), {token: 'foobar', type: 'Basic'})
  56. delete process.env[environmentVariable]
  57. done()
  58. })
  59. })
  60. it('should return legacy auth token defined by reference to an environment variable (without curly braces)', function (done) {
  61. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  62. var content = [
  63. '_auth=$' + environmentVariable,
  64. 'registry=http://registry.foobar.eu/'
  65. ].join('\n')
  66. process.env[environmentVariable] = 'foobar'
  67. fs.writeFile(npmRcPath, content, function (err) {
  68. var getAuthToken = requireUncached('../index')
  69. assert(!err, err)
  70. assert.deepEqual(getAuthToken(), {token: 'foobar', type: 'Basic'})
  71. delete process.env[environmentVariable]
  72. done()
  73. })
  74. })
  75. })
  76. describe('bearer token', function () {
  77. it('should return auth token if registry is defined', function (done) {
  78. var content = [
  79. 'registry=http://registry.foobar.eu/',
  80. '//registry.foobar.eu/:_authToken=foobar', ''
  81. ].join('\n')
  82. fs.writeFile(npmRcPath, content, function (err) {
  83. var getAuthToken = requireUncached('../index')
  84. assert(!err, err)
  85. assert.deepEqual(getAuthToken(), {token: 'foobar', type: 'Bearer'})
  86. done()
  87. })
  88. })
  89. it('should use npmrc passed in', function (done) {
  90. var content = [
  91. 'registry=http://registry.foobar.eu/',
  92. '//registry.foobar.eu/:_authToken=foobar', ''
  93. ].join('\n')
  94. fs.writeFile(npmRcPath, content, function (err) {
  95. var getAuthToken = requireUncached('../index')
  96. assert(!err, err)
  97. const npmrc = {
  98. 'registry': 'http://registry.foobar.eu/',
  99. '//registry.foobar.eu/:_authToken': 'qar'
  100. }
  101. assert.deepEqual(getAuthToken({npmrc: npmrc}), {token: 'qar', type: 'Bearer'})
  102. done()
  103. })
  104. })
  105. it('should return auth token if registry url has port specified', function (done) {
  106. var content = [
  107. 'registry=http://localhost:8770/',
  108. // before the patch this token was selected.
  109. '//localhost/:_authToken=ohno',
  110. '//localhost:8770/:_authToken=beepboop', ''
  111. ].join('\n')
  112. fs.writeFile(npmRcPath, content, function (err) {
  113. var getAuthToken = requireUncached('../index')
  114. assert(!err, err)
  115. assert.deepEqual(getAuthToken(), {token: 'beepboop', type: 'Bearer'})
  116. done()
  117. })
  118. })
  119. it('should return auth token defined by reference to an environment variable (with curly braces)', function (done) {
  120. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  121. var content = [
  122. 'registry=http://registry.foobar.cc/',
  123. '//registry.foobar.cc/:_authToken=${' + environmentVariable + '}', ''
  124. ].join('\n')
  125. process.env[environmentVariable] = 'foobar'
  126. fs.writeFile(npmRcPath, content, function (err) {
  127. var getAuthToken = requireUncached('../index')
  128. assert(!err, err)
  129. assert.deepEqual(getAuthToken(), {token: 'foobar', type: 'Bearer'})
  130. delete process.env[environmentVariable]
  131. done()
  132. })
  133. })
  134. it('should return auth token defined by reference to an environment variable (without curly braces)', function (done) {
  135. var environmentVariable = '__REGISTRY_AUTH_TOKEN_NPM_TOKEN__'
  136. var content = [
  137. 'registry=http://registry.foobar.cc/',
  138. '//registry.foobar.cc/:_authToken=$' + environmentVariable, ''
  139. ].join('\n')
  140. process.env[environmentVariable] = 'foobar'
  141. fs.writeFile(npmRcPath, content, function (err) {
  142. var getAuthToken = requireUncached('../index')
  143. assert(!err, err)
  144. assert.deepEqual(getAuthToken(), {token: 'foobar', type: 'Bearer'})
  145. delete process.env[environmentVariable]
  146. done()
  147. })
  148. })
  149. it('should try with and without a slash at the end of registry url', function (done) {
  150. var content = [
  151. 'registry=http://registry.foobar.eu',
  152. '//registry.foobar.eu:_authToken=barbaz', ''
  153. ].join('\n')
  154. fs.writeFile(npmRcPath, content, function (err) {
  155. var getAuthToken = requireUncached('../index')
  156. assert(!err, err)
  157. assert.deepEqual(getAuthToken(), {token: 'barbaz', type: 'Bearer'})
  158. done()
  159. })
  160. })
  161. it('should fetch for the registry given (if defined)', function (done) {
  162. var content = [
  163. '//registry.foobar.eu:_authToken=barbaz',
  164. '//registry.blah.foo:_authToken=whatev',
  165. '//registry.last.thing:_authToken=yep', ''
  166. ].join('\n')
  167. fs.writeFile(npmRcPath, content, function (err) {
  168. var getAuthToken = requireUncached('../index')
  169. assert(!err, err)
  170. assert.deepEqual(getAuthToken('//registry.blah.foo'), {token: 'whatev', type: 'Bearer'})
  171. done()
  172. })
  173. })
  174. it('recursively finds registries for deep url if option is set', function (done, undef) {
  175. var opts = {recursive: true}
  176. var content = [
  177. '//registry.blah.com/foo:_authToken=whatev',
  178. '//registry.blah.org/foo/bar:_authToken=recurseExactlyOneLevel',
  179. '//registry.blah.edu/foo/bar/baz:_authToken=recurseNoLevel',
  180. '//registry.blah.eu:_authToken=yep', ''
  181. ].join('\n')
  182. fs.writeFile(npmRcPath, content, function (err) {
  183. var getAuthToken = requireUncached('../index')
  184. assert(!err, err)
  185. assert.deepEqual(getAuthToken('https://registry.blah.edu/foo/bar/baz', opts), {token: 'recurseNoLevel', type: 'Bearer'})
  186. assert.deepEqual(getAuthToken('https://registry.blah.org/foo/bar/baz', opts), {token: 'recurseExactlyOneLevel', type: 'Bearer'})
  187. assert.deepEqual(getAuthToken('https://registry.blah.com/foo/bar/baz', opts), {token: 'whatev', type: 'Bearer'})
  188. assert.deepEqual(getAuthToken('http://registry.blah.eu/what/ever', opts), {token: 'yep', type: 'Bearer'})
  189. assert.deepEqual(getAuthToken('http://registry.blah.eu//what/ever', opts), undefined, 'does not hang')
  190. assert.equal(getAuthToken('//some.registry', opts), undef)
  191. done()
  192. })
  193. })
  194. it('should try both with and without trailing slash', function (done) {
  195. fs.writeFile(npmRcPath, '//registry.blah.com:_authToken=whatev', function (err) {
  196. var getAuthToken = requireUncached('../index')
  197. assert(!err, err)
  198. assert.deepEqual(getAuthToken('https://registry.blah.com'), {token: 'whatev', type: 'Bearer'})
  199. done()
  200. })
  201. })
  202. it('should prefer bearer token over basic token', function (done) {
  203. var content = [
  204. 'registry=http://registry.foobar.eu/',
  205. 'registry=http://registry.foobar.eu/',
  206. '//registry.foobar.eu/:_authToken=bearerToken',
  207. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  208. '//registry.foobar.eu/:username=foobar', ''
  209. ].join('\n')
  210. fs.writeFile(npmRcPath, content, function (err) {
  211. var getAuthToken = requireUncached('../index')
  212. assert(!err, err)
  213. assert.deepEqual(getAuthToken('//registry.foobar.eu'), {token: 'bearerToken', type: 'Bearer'})
  214. done()
  215. })
  216. })
  217. it('"nerf darts" registry urls', function (done, undef) {
  218. fs.writeFile(npmRcPath, '//contoso.pkgs.visualstudio.com/_packaging/MyFeed/npm/:_authToken=heider', function (err) {
  219. var getAuthToken = requireUncached('../index')
  220. assert(!err, err)
  221. assert.deepEqual(
  222. getAuthToken('https://contoso.pkgs.visualstudio.com/_packaging/MyFeed/npm/registry'),
  223. {token: 'heider', type: 'Bearer'}
  224. )
  225. done()
  226. })
  227. })
  228. })
  229. describe('basic token', function () {
  230. it('should return undefined if password or username are missing', function (done, undef) {
  231. var content = [
  232. 'registry=http://registry.foobar.eu/',
  233. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  234. '//registry.foobar.com/:username=foobar', ''
  235. ].join('\n')
  236. fs.writeFile(npmRcPath, content, function (err) {
  237. var getAuthToken = requireUncached('../index')
  238. assert(!err, err)
  239. assert.equal(getAuthToken('//registry.foobar.eu'), undef)
  240. assert.equal(getAuthToken('//registry.foobar.com'), undef)
  241. done()
  242. })
  243. })
  244. it('should return basic token if username and password are defined', function (done) {
  245. var content = [
  246. 'registry=http://registry.foobar.eu/',
  247. '//registry.foobar.eu/:_password=' + encodeBase64('foobar'),
  248. '//registry.foobar.eu/:username=foobar', ''
  249. ].join('\n')
  250. fs.writeFile(npmRcPath, content, function (err) {
  251. var getAuthToken = requireUncached('../index')
  252. assert(!err, err)
  253. var token = getAuthToken()
  254. assert.deepEqual(token, {
  255. token: 'Zm9vYmFyOmZvb2Jhcg==',
  256. type: 'Basic',
  257. username: 'foobar',
  258. password: 'foobar'
  259. })
  260. assert.equal(decodeBase64(token.token), 'foobar:foobar')
  261. done()
  262. })
  263. })
  264. it('should return basic token if registry url has port specified', function (done) {
  265. var content = [
  266. 'registry=http://localhost:8770/',
  267. // before the patch this token was selected.
  268. '//localhost/:_authToken=ohno',
  269. '//localhost:8770/:_password=' + encodeBase64('foobar'),
  270. '//localhost:8770/:username=foobar', ''
  271. ].join('\n')
  272. fs.writeFile(npmRcPath, content, function (err) {
  273. var getAuthToken = requireUncached('../index')
  274. assert(!err, err)
  275. var token = getAuthToken()
  276. assert.deepEqual(token, {
  277. token: 'Zm9vYmFyOmZvb2Jhcg==',
  278. type: 'Basic',
  279. username: 'foobar',
  280. password: 'foobar'
  281. })
  282. assert.equal(decodeBase64(token.token), 'foobar:foobar')
  283. done()
  284. })
  285. })
  286. it('should return password defined by reference to an environment variable (with curly braces)', function (done) {
  287. var environmentVariable = '__REGISTRY_PASSWORD__'
  288. var content = [
  289. 'registry=http://registry.foobar.cc/',
  290. '//registry.foobar.cc/:username=username',
  291. '//registry.foobar.cc/:_password=${' + environmentVariable + '}', ''
  292. ].join('\n')
  293. process.env[environmentVariable] = encodeBase64('password')
  294. fs.writeFile(npmRcPath, content, function (err) {
  295. var getAuthToken = requireUncached('../index')
  296. assert(!err, err)
  297. var token = getAuthToken()
  298. assert.deepEqual(token, {
  299. type: 'Basic',
  300. username: 'username',
  301. password: 'password',
  302. token: 'dXNlcm5hbWU6cGFzc3dvcmQ='
  303. })
  304. assert.equal(decodeBase64(token.token), 'username:password')
  305. delete process.env[environmentVariable]
  306. done()
  307. })
  308. })
  309. it('should return password defined by reference to an environment variable (without curly braces)', function (done) {
  310. var environmentVariable = '__REGISTRY_PASSWORD__'
  311. var content = [
  312. 'registry=http://registry.foobar.cc/',
  313. '//registry.foobar.cc/:username=username',
  314. '//registry.foobar.cc/:_password=$' + environmentVariable, ''
  315. ].join('\n')
  316. process.env[environmentVariable] = encodeBase64('password')
  317. fs.writeFile(npmRcPath, content, function (err) {
  318. var getAuthToken = requireUncached('../index')
  319. assert(!err, err)
  320. var token = getAuthToken()
  321. assert.deepEqual(token, {
  322. type: 'Basic',
  323. username: 'username',
  324. password: 'password',
  325. token: 'dXNlcm5hbWU6cGFzc3dvcmQ='
  326. })
  327. assert.equal(decodeBase64(token.token), 'username:password')
  328. delete process.env[environmentVariable]
  329. done()
  330. })
  331. })
  332. it('should try with and without a slash at the end of registry url', function (done) {
  333. var content = [
  334. 'registry=http://registry.foobar.eu',
  335. '//registry.foobar.eu:_password=' + encodeBase64('barbay'),
  336. '//registry.foobar.eu:username=barbaz', ''
  337. ].join('\n')
  338. fs.writeFile(npmRcPath, content, function (err) {
  339. var getAuthToken = requireUncached('../index')
  340. assert(!err, err)
  341. var token = getAuthToken()
  342. assert.deepEqual(token, {
  343. token: 'YmFyYmF6OmJhcmJheQ==',
  344. type: 'Basic',
  345. password: 'barbay',
  346. username: 'barbaz'
  347. })
  348. assert.equal(decodeBase64(token.token), 'barbaz:barbay')
  349. done()
  350. })
  351. })
  352. it('should fetch for the registry given (if defined)', function (done) {
  353. var content = [
  354. '//registry.foobar.eu:_authToken=barbaz',
  355. '//registry.blah.foo:_password=' + encodeBase64('barbay'),
  356. '//registry.blah.foo:username=barbaz',
  357. '//registry.last.thing:_authToken=yep', ''
  358. ].join('\n')
  359. fs.writeFile(npmRcPath, content, function (err) {
  360. var getAuthToken = requireUncached('../index')
  361. assert(!err, err)
  362. var token = getAuthToken('//registry.blah.foo')
  363. assert.deepEqual(token, {
  364. token: 'YmFyYmF6OmJhcmJheQ==',
  365. type: 'Basic',
  366. password: 'barbay',
  367. username: 'barbaz'
  368. })
  369. assert.equal(decodeBase64(token.token), 'barbaz:barbay')
  370. done()
  371. })
  372. })
  373. it('recursively finds registries for deep url if option is set', function (done, undef) {
  374. var opts = {recursive: true}
  375. var content = [
  376. '//registry.blah.com/foo:_password=' + encodeBase64('barbay'),
  377. '//registry.blah.com/foo:username=barbaz',
  378. '//registry.blah.eu:username=barbaz',
  379. '//registry.blah.eu:_password=' + encodeBase64('foobaz'), ''
  380. ].join('\n')
  381. fs.writeFile(npmRcPath, content, function (err) {
  382. var getAuthToken = requireUncached('../index')
  383. assert(!err, err)
  384. var token = getAuthToken('https://registry.blah.com/foo/bar/baz', opts)
  385. assert.deepEqual(token, {
  386. token: 'YmFyYmF6OmJhcmJheQ==',
  387. type: 'Basic',
  388. password: 'barbay',
  389. username: 'barbaz'
  390. })
  391. assert.equal(decodeBase64(token.token), 'barbaz:barbay')
  392. token = getAuthToken('https://registry.blah.eu/foo/bar/baz', opts)
  393. assert.deepEqual(token, {
  394. token: 'YmFyYmF6OmZvb2Jheg==',
  395. type: 'Basic',
  396. password: 'foobaz',
  397. username: 'barbaz'
  398. })
  399. assert.equal(decodeBase64(token.token), 'barbaz:foobaz')
  400. assert.equal(getAuthToken('//some.registry', opts), undef)
  401. done()
  402. })
  403. })
  404. })
  405. })