Files
pmg/proxy/interceptors/cooldown_test.go
T
Sahil BansalandGitHub 544b38b278 feat: Add PyPI dependency cooldown support (#221)
* refactor: Extract shared cooldown helpers to package-level functions

* feat: Add PyPI cooldown handler with PEP 691 file parsing

* feat: Add PyPI cooldown file stripping logic

* feat: Implement PyPI cooldown HandleMetadataRequest with PEP 691 filtering

* feat: Wire PyPI cooldown into pypi_registry interceptor

* update headers for no cache

* fix: Strip conditional GET headers to prevent 304 bypass in cooldown handlers

pip and npm clients cache Simple API / registry responses with ETags. On
subsequent requests they send If-None-Match, which causes the server to
return 304 Not Modified with no body. The cooldown response modifier
received an empty body, failed to parse it, and failed-open — letting
the client use its stale cached (unfiltered) response.

Fix: delete If-None-Match and If-Modified-Since from the request before
forwarding, forcing a full 200 response so the modifier always has a
body to filter.

Also removes the Content-Type guard from the PyPI modifier (the empty
Content-Type on 304 responses was a symptom of the same root cause) and
replaces Cache-Control: no-cache with the more targeted header deletion.

* docs: Add PyPI cooldown limitation for pip < 22.3 to dependency-cooldown docs
2026-04-20 21:10:05 +05:30

165 lines
4.6 KiB
Go

package interceptors
import (
"testing"
"time"
"github.com/stretchr/testify/assert"
)
func TestCooldownIsWithinWindow(t *testing.T) {
now := time.Now()
day := 24 * time.Hour
tests := []struct {
name string
publishDate time.Time
cooldownDays int
wantWithinCooldown bool
wantDaysSincePublish int
wantDaysRemaining int
}{
{
name: "published today with 30 day cooldown",
publishDate: now,
cooldownDays: 30,
wantWithinCooldown: true,
wantDaysSincePublish: 0,
wantDaysRemaining: 30,
},
{
name: "published exactly at cooldown boundary",
publishDate: now.Add(-30 * day),
cooldownDays: 30,
wantWithinCooldown: false,
wantDaysSincePublish: 30,
wantDaysRemaining: 0,
},
{
name: "published one day before cooldown expires",
publishDate: now.Add(-29 * day),
cooldownDays: 30,
wantWithinCooldown: true,
wantDaysSincePublish: 29,
wantDaysRemaining: 1,
},
{
name: "published well beyond cooldown",
publishDate: now.Add(-365 * day),
cooldownDays: 30,
wantWithinCooldown: false,
wantDaysSincePublish: 365,
wantDaysRemaining: 0,
},
{
name: "zero cooldown days",
publishDate: now,
cooldownDays: 0,
wantWithinCooldown: false,
wantDaysSincePublish: 0,
wantDaysRemaining: 0,
},
{
name: "future publish date clamped to zero days",
publishDate: now.Add(5 * day),
cooldownDays: 30,
wantWithinCooldown: true,
wantDaysSincePublish: 0,
wantDaysRemaining: 30,
},
{
name: "one day cooldown with publish today",
publishDate: now,
cooldownDays: 1,
wantWithinCooldown: true,
wantDaysSincePublish: 0,
wantDaysRemaining: 1,
},
{
name: "one day cooldown with publish yesterday",
publishDate: now.Add(-1 * day),
cooldownDays: 1,
wantWithinCooldown: false,
wantDaysSincePublish: 1,
wantDaysRemaining: 0,
},
{
name: "max int cooldown days does not overflow",
publishDate: now.Add(-1 * day),
cooldownDays: int(^uint(0) >> 1),
wantWithinCooldown: true,
wantDaysSincePublish: 1,
wantDaysRemaining: int(^uint(0)>>1) - 1,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
withinCooldown, daysSincePublish, daysRemaining := cooldownIsWithinWindow(tt.publishDate, tt.cooldownDays)
assert.Equal(t, tt.wantWithinCooldown, withinCooldown, "withinCooldown")
assert.Equal(t, tt.wantDaysSincePublish, daysSincePublish, "daysSincePublish")
assert.Equal(t, tt.wantDaysRemaining, daysRemaining, "daysRemaining")
})
}
}
func TestCooldownOldestVersion(t *testing.T) {
now := time.Now()
day := 24 * time.Hour
t.Run("returns version with earliest publish date", func(t *testing.T) {
dates := map[string]time.Time{
"1.0.0": now.Add(-30 * day),
"2.0.0": now.Add(-10 * day),
"3.0.0": now.Add(-1 * day),
}
ver, ts := cooldownOldestVersion(dates)
assert.Equal(t, "1.0.0", ver)
assert.False(t, ts.IsZero())
})
t.Run("single version", func(t *testing.T) {
dates := map[string]time.Time{"1.0.0": now.Add(-5 * day)}
ver, _ := cooldownOldestVersion(dates)
assert.Equal(t, "1.0.0", ver)
})
t.Run("empty map returns empty string and zero time", func(t *testing.T) {
ver, ts := cooldownOldestVersion(map[string]time.Time{})
assert.Empty(t, ver)
assert.True(t, ts.IsZero())
})
}
func TestCooldownLatestEligibleVersion(t *testing.T) {
now := time.Now()
day := 24 * time.Hour
t.Run("returns most recently published non-blocked version", func(t *testing.T) {
dates := map[string]time.Time{
"1.0.0": now.Add(-30 * day),
"2.0.0": now.Add(-10 * day),
"3.0.0": now.Add(-1 * day),
}
tooNew := map[string]bool{"3.0.0": true}
ver := cooldownLatestEligibleVersion(dates, tooNew)
assert.Equal(t, "2.0.0", ver)
})
t.Run("all versions blocked returns empty string", func(t *testing.T) {
dates := map[string]time.Time{"1.0.0": now, "2.0.0": now.Add(-1 * day)}
tooNew := map[string]bool{"1.0.0": true, "2.0.0": true}
ver := cooldownLatestEligibleVersion(dates, tooNew)
assert.Empty(t, ver)
})
t.Run("empty tooNew returns latest version", func(t *testing.T) {
dates := map[string]time.Time{
"1.0.0": now.Add(-30 * day),
"2.0.0": now.Add(-10 * day),
}
ver := cooldownLatestEligibleVersion(dates, map[string]bool{})
assert.Equal(t, "2.0.0", ver)
})
}