#!/usr/bin/env node // Acceptation P12a (sans navigateur, sans réseau/quota) : services git distants + clone. Vrai daemon // + credential factice + clone d'un dépôt bare LOCAL (chemin de fichier, pas de réseau). Couvre : // création de credential (secret chiffré), POST /repos/clone (202) → progression WS clone_update → // done → repo auto-enregistré, ET surtout : le secret en clair est ABSENT de l'API, de la DB et du // .git/config du dépôt cloné (garde-fou « jamais de fuite de secret »). import { spawn, execFileSync } from 'node:child_process'; import { mkdtempSync, mkdirSync, rmSync, writeFileSync, readFileSync, existsSync } from 'node:fs'; import { tmpdir } from 'node:os'; import { join, dirname } from 'node:path'; import { fileURLToPath } from 'node:url'; import { createRequire } from 'node:module'; const require = createRequire(import.meta.url); const WebSocket = require('ws'); const PORT = 7555; const ORIGIN = `http://127.0.0.1:${PORT}`; const SECRET = 'arb-secret-token-9876XYZ'; // token factice : ne doit JAMAIS fuiter en clair const sleep = (ms) => new Promise((r) => setTimeout(r, ms)); const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..'); const results = []; const check = (name, ok, detail = '') => { results.push({ name, ok, detail }); console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`); }; const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p12-')); const work = join(tmp, 'work'); // racine de scan + destination des clones const src = join(tmp, 'src'); // dépôt source (working) const bare = join(tmp, 'source.git'); // remote bare local (file path) const dbPath = join(tmp, 'a.db'); mkdirSync(work, { recursive: true }); mkdirSync(src, { recursive: true }); const g = (cwd, ...args) => execFileSync('git', args, { cwd, stdio: 'pipe' }); g(src, 'init', '-b', 'main'); g(src, 'config', 'user.email', 'test@arboretum.dev'); g(src, 'config', 'user.name', 'Test'); writeFileSync(join(src, 'README.md'), '# cloned demo\n'); g(src, 'add', '-A'); g(src, 'commit', '-m', 'init'); execFileSync('git', ['clone', '--bare', src, bare], { stdio: 'pipe' }); const srv = spawn( 'node', [join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', dbPath, '--claude-home', join(tmp, 'claude'), '--no-discover'], { env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] }, ); let srvOut = ''; srv.stdout.on('data', (d) => (srvOut += d)); srv.stderr.on('data', (d) => (srvOut += d)); function wsClient(cookie) { const ws = new WebSocket(`ws://127.0.0.1:${PORT}/ws`, { headers: { Origin: ORIGIN, Cookie: cookie } }); const state = { msgs: [] }; ws.on('message', (data, isBinary) => { if (!isBinary) state.msgs.push(JSON.parse(String(data))); }); const waitMsg = async (pred, timeout = 15000) => { const t0 = Date.now(); while (Date.now() - t0 < timeout) { const m = state.msgs.find(pred); if (m) return m; await sleep(50); } return null; }; return { ws, state, waitMsg, send: (m) => ws.send(JSON.stringify(m)) }; } const j = (path, method, cookie, body) => fetch(`${ORIGIN}${path}`, { method, headers: { Origin: ORIGIN, Cookie: cookie, ...(body ? { 'Content-Type': 'application/json' } : {}) }, ...(body ? { body: JSON.stringify(body) } : {}), }); try { await sleep(1500); const token = /arb_[0-9a-f]+/.exec(srvOut)?.[0]; check('boot + token bootstrap', !!token); const login = await fetch(`${ORIGIN}/api/v1/auth/login`, { method: 'POST', headers: { 'Content-Type': 'application/json', Origin: ORIGIN }, body: JSON.stringify({ token }), }); const cookie = login.headers.get('set-cookie')?.split(';')[0] ?? ''; check('login → cookie', login.status === 200); // racine de scan = work (confine la destination du clone). const patch = await j('/api/v1/settings', 'PATCH', cookie, { scanRoots: [work] }); check('PATCH scanRoots → 200', patch.status === 200); // credential factice (secret chiffré côté serveur). const createCred = await j('/api/v1/git-connections', 'POST', cookie, { label: 'fake', service: 'gitea', authType: 'pat', baseUrl: 'http://localhost:9999', secret: SECRET, }); const credBody = await createCred.json(); const credId = credBody.credential?.id; check('POST /git-connections → 201', createCred.status === 201 && !!credId); check('réponse de création SANS secret en clair', !JSON.stringify(credBody).includes(SECRET)); check('réponse expose secretLast4 (et hasSecret)', credBody.credential?.hasSecret === true && credBody.credential?.secretLast4 === SECRET.slice(-4)); // GET liste : pas de secret. const listed = await (await j('/api/v1/git-connections', 'GET', cookie)).json(); check('GET /git-connections SANS secret en clair', !JSON.stringify(listed).includes(SECRET)); // WS abonné aux clones. const c = wsClient(cookie); await new Promise((res, rej) => (c.ws.on('open', res), c.ws.on('error', rej))); c.send({ type: 'hello', protocol: 1 }); await c.waitMsg((m) => m.type === 'hello_ok'); c.send({ type: 'sub', topics: ['clones', 'worktrees'] }); // clone du bare local → dest sous la racine de scan. const dest = join(work, 'cloned'); const clone = await j('/api/v1/repos/clone', 'POST', cookie, { credentialId: credId, remoteUrl: bare, dest }); const cloneBody = await clone.json(); check('POST /repos/clone → 202 + operationId', clone.status === 202 && !!cloneBody.operationId); const doneMsg = await c.waitMsg((m) => m.type === 'clone_update' && m.operation?.id === cloneBody.operationId && m.operation?.state === 'done'); check('clone_update state=done reçu via WS', !!doneMsg, doneMsg ? `repoId=${doneMsg.operation.repoId}` : 'timeout'); check('le clone a produit un repoId (auto-enregistré)', !!doneMsg?.operation?.repoId); // repo enregistré + visible. const repos = await (await j('/api/v1/repos', 'GET', cookie)).json(); const cloned = (repos.repos ?? []).find((r) => r.path === dest); check('repo cloné enregistré et listé', !!cloned); check('le dépôt cloné existe sur disque (README.md)', existsSync(join(dest, 'README.md'))); // ---- garde-fou « pas de fuite de secret » ---- const gitConfig = existsSync(join(dest, '.git', 'config')) ? readFileSync(join(dest, '.git', 'config'), 'utf8') : ''; check('secret ABSENT du .git/config du clone', !gitConfig.includes(SECRET)); const dbBytes = [dbPath, `${dbPath}-wal`, `${dbPath}-shm`] .filter((p) => existsSync(p)) .map((p) => readFileSync(p).toString('latin1')) .join(''); check('secret ABSENT de la base (chiffré au repos)', !dbBytes.includes(SECRET)); c.ws.close(); } catch (err) { check('exception', false, String(err)); } finally { srv.kill('SIGTERM'); await sleep(1500); check('arrêt propre du daemon (SIGTERM)', srv.exitCode === 0 || srv.signalCode === null || srv.exitCode === null); rmSync(tmp, { recursive: true, force: true }); const failed = results.filter((r) => !r.ok); console.log(failed.length === 0 ? '\nACCEPTANCE P12: ALL GREEN' : `\nACCEPTANCE P12: ${failed.length} FAILURE(S)`); process.exit(failed.length === 0 ? 0 : 1); }