mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* fix(proxy): do not override explicitly-set CI env var pmg forces CI=true for non-interactive (non-PTY) proxy runs so package managers behave non-interactively. This clobbered a CI value the user set explicitly (e.g. CI=false on a build server), changing downstream tool behavior unexpectedly. Only inject CI=true when CI is not already present in the environment, preserving the user's intent. mergeEnv override semantics are left intact since other overrides (HTTP_PROXY, etc.) must clobber. Fixes #335 * test(proxy): snapshot/restore CI env explicitly in override test Address review feedback: make the unset-CI subtest's intent explicit by snapshotting the original CI value, unsetting it for the test, and restoring it in t.Cleanup instead of relying on t.Setenv cleanup. --------- Co-authored-by: Claude <noreply@anthropic.com>
70 lines
2.1 KiB
Go
70 lines
2.1 KiB
Go
package flows
|
|
|
|
import (
|
|
"os"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func envToMap(env []string) map[string]string {
|
|
m := make(map[string]string, len(env))
|
|
for _, e := range env {
|
|
k, v, ok := strings.Cut(e, "=")
|
|
if ok {
|
|
m[k] = v
|
|
}
|
|
}
|
|
return m
|
|
}
|
|
|
|
// TestSetupEnvForProxyConfiguresYarn proves the root cause of #319: yarn Berry
|
|
// (yarn 2+) ignores the standard HTTP_PROXY/HTTPS_PROXY env vars and only honors
|
|
// its own config, which can be set via YARN_* env overrides. Without these,
|
|
// yarn bypasses the MITM proxy entirely and no packages are analyzed.
|
|
func TestSetupEnvForProxyConfiguresYarn(t *testing.T) {
|
|
f := &proxyFlow{}
|
|
const proxyAddr = "127.0.0.1:54321"
|
|
const caCertPath = "/tmp/pmg-ca-cert.pem"
|
|
|
|
env := envToMap(f.setupEnvForProxy(proxyAddr, caCertPath))
|
|
|
|
proxyURL := "http://" + proxyAddr
|
|
|
|
assert.Equal(t, proxyURL, env["YARN_HTTP_PROXY"],
|
|
"yarn ignores HTTP_PROXY; YARN_HTTP_PROXY is required to route yarn through the proxy")
|
|
assert.Equal(t, proxyURL, env["YARN_HTTPS_PROXY"],
|
|
"yarn ignores HTTPS_PROXY; YARN_HTTPS_PROXY is required to route yarn through the proxy")
|
|
assert.Equal(t, caCertPath, env["YARN_HTTPS_CA_FILE_PATH"],
|
|
"yarn ignores NODE_EXTRA_CA_CERTS; YARN_HTTPS_CA_FILE_PATH is required to trust the MITM CA")
|
|
}
|
|
|
|
// TestCIEnvOverride proves the fix for #335: pmg forces CI=true for
|
|
// non-interactive runs but must not clobber a CI value the user set
|
|
// explicitly (e.g. CI=false on a build server).
|
|
func TestCIEnvOverride(t *testing.T) {
|
|
t.Run("sets CI=true when unset", func(t *testing.T) {
|
|
original, hadCI := os.LookupEnv("CI")
|
|
require.NoError(t, os.Unsetenv("CI"))
|
|
t.Cleanup(func() {
|
|
if hadCI {
|
|
require.NoError(t, os.Setenv("CI", original))
|
|
}
|
|
})
|
|
|
|
assert.Equal(t, []string{"CI=true"}, ciEnvOverride())
|
|
})
|
|
|
|
t.Run("does not override explicitly set CI", func(t *testing.T) {
|
|
t.Setenv("CI", "false")
|
|
assert.Nil(t, ciEnvOverride())
|
|
})
|
|
|
|
t.Run("does not override CI set to empty", func(t *testing.T) {
|
|
t.Setenv("CI", "")
|
|
assert.Nil(t, ciEnvOverride())
|
|
})
|
|
}
|