mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat: Add support for environment protection (scrubbing) (#327)
* feat: Add support for environment variable protection for sandbox * chore: Update dangerous env var list * fix: Split profiles for improved environment protection * fix: pipx sandbox profile separation * chore: Show sandbox scrub info on error exit * fix: Code review fixes * test: Add e2e for sandbox environment scrubbing
This commit is contained in:
@@ -0,0 +1,55 @@
|
||||
package sandbox
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
)
|
||||
|
||||
func TestMergeWithParent_Environment(t *testing.T) {
|
||||
parent := &SandboxPolicy{
|
||||
Environment: EnvironmentPolicy{
|
||||
Allow: []string{"NPM_TOKEN"},
|
||||
Deny: []string{"PARENT_SECRET"},
|
||||
},
|
||||
}
|
||||
child := &SandboxPolicy{
|
||||
Environment: EnvironmentPolicy{
|
||||
Allow: []string{"NODE_AUTH_TOKEN"},
|
||||
Deny: []string{"CHILD_SECRET"},
|
||||
},
|
||||
}
|
||||
|
||||
child.MergeWithParent(parent)
|
||||
|
||||
assert.Equal(t, []string{"NPM_TOKEN", "NODE_AUTH_TOKEN"}, child.Environment.Allow)
|
||||
assert.Equal(t, []string{"PARENT_SECRET", "CHILD_SECRET"}, child.Environment.Deny)
|
||||
}
|
||||
|
||||
// An environment-only policy is a valid policy: EnvironmentPolicy is an
|
||||
// enforceable section, so it counts toward the "at least one access rule"
|
||||
// check.
|
||||
func TestValidateResolved_EnvironmentOnlyPolicy(t *testing.T) {
|
||||
p := &SandboxPolicy{
|
||||
Name: "env-only",
|
||||
PackageManagers: []string{"npm"},
|
||||
Environment: EnvironmentPolicy{Deny: []string{"*_TOKEN"}},
|
||||
}
|
||||
|
||||
assert.NoError(t, p.ValidateResolved())
|
||||
}
|
||||
|
||||
func TestResolveProfile_DeepCopiesEnvironment(t *testing.T) {
|
||||
r, err := newDefaultProfileRegistry()
|
||||
assert.NoError(t, err)
|
||||
|
||||
resolved, err := r.ResolveProfile("npm", ResolveOptions{})
|
||||
assert.NoError(t, err)
|
||||
|
||||
// Mutating the resolved copy must not corrupt the registry-cached policy.
|
||||
resolved.Environment.Allow = append(resolved.Environment.Allow, "MUTATED")
|
||||
|
||||
again, err := r.ResolveProfile("npm", ResolveOptions{})
|
||||
assert.NoError(t, err)
|
||||
assert.NotContains(t, again.Environment.Allow, "MUTATED")
|
||||
}
|
||||
Reference in New Issue
Block a user