File size: 3,029 Bytes
25d91a4
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
// Verifies startup environment merge behavior for Node subprocesses.
import { describe, expect, it } from "vitest";
import { resolveNodeStartupTlsEnvironment } from "./node-startup-env.js";

const FEDORA_CA_BUNDLE_PATH = "/etc/pki/tls/certs/ca-bundle.crt";
const GENERIC_CA_BUNDLE_PATH = "/etc/ssl/ca-bundle.pem";

function allowOnly(path: string) {
  return (candidate: string) => {
    if (candidate !== path) {
      throw new Error("ENOENT");
    }
  };
}

describe("resolveNodeStartupTlsEnvironment", () => {
  it("defaults macOS launch env values", () => {
    expect(
      resolveNodeStartupTlsEnvironment({
        env: {},
        platform: "darwin",
      }),
    ).toEqual({
      NODE_EXTRA_CA_CERTS: "/etc/ssl/cert.pem",
      NODE_USE_SYSTEM_CA: "1",
    });
  });

  it("keeps user-provided env values", () => {
    expect(
      resolveNodeStartupTlsEnvironment({
        env: {
          NODE_EXTRA_CA_CERTS: "/custom/ca.pem",
          NODE_USE_SYSTEM_CA: "0",
        },
        platform: "darwin",
      }),
    ).toEqual({
      NODE_EXTRA_CA_CERTS: "/custom/ca.pem",
      NODE_USE_SYSTEM_CA: "0",
    });
  });

  it.each([
    ["empty Linux value", "", "linux", FEDORA_CA_BUNDLE_PATH],
    ["whitespace macOS value", " \t ", "darwin", "/etc/ssl/cert.pem"],
  ] as const)("treats %s as unset", (_label, value, platform, expected) => {
    const startupEnv = resolveNodeStartupTlsEnvironment({
      env: { NODE_EXTRA_CA_CERTS: value, NVM_DIR: "/home/test/.nvm" },
      platform,
      execPath: "/usr/bin/node",
      accessSync: allowOnly(FEDORA_CA_BUNDLE_PATH),
    });

    expect(startupEnv.NODE_EXTRA_CA_CERTS).toBe(expected);
  });

  it("preserves a nonblank CA path byte-for-byte", () => {
    expect(
      resolveNodeStartupTlsEnvironment({
        env: { NODE_EXTRA_CA_CERTS: " /custom/ca.pem " },
        platform: "darwin",
      }).NODE_EXTRA_CA_CERTS,
    ).toBe(" /custom/ca.pem ");
  });

  it("resolves Linux CA env for version-manager Node runtimes", () => {
    expect(
      resolveNodeStartupTlsEnvironment({
        env: { NVM_DIR: "/home/test/.nvm" },
        platform: "linux",
        execPath: "/usr/bin/node",
        accessSync: allowOnly(FEDORA_CA_BUNDLE_PATH),
      }),
    ).toEqual({
      NODE_EXTRA_CA_CERTS: FEDORA_CA_BUNDLE_PATH,
      NODE_USE_SYSTEM_CA: undefined,
    });
  });

  it("can skip macOS defaults for CLI-only pre-start planning", () => {
    expect(
      resolveNodeStartupTlsEnvironment({
        env: {},
        platform: "darwin",
        includeDarwinDefaults: false,
      }),
    ).toEqual({
      NODE_EXTRA_CA_CERTS: undefined,
      NODE_USE_SYSTEM_CA: undefined,
    });
  });

  it("uses the Linux CA bundle heuristic when available", () => {
    const value = resolveNodeStartupTlsEnvironment({
      env: { NVM_DIR: "/home/test/.nvm" },
      platform: "linux",
      execPath: "/usr/bin/node",
      accessSync: allowOnly(GENERIC_CA_BUNDLE_PATH),
    }).NODE_EXTRA_CA_CERTS;
    expect(value).toBe(GENERIC_CA_BUNDLE_PATH);
  });
});