mirror of
https://github.com/go-gitea/gitea.git
synced 2026-07-28 03:26:25 +00:00
Migrations should never use model structs directly, because the model structs can be different in different releases. e.g. if one migration uses "User" model, it works in the early releases, then one day, when the User model changes, the migration breaks because it will use the new (incorrect) User model, it should only use the old User model. The same to "modules/structs". --------- Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: delvh <dev.lh@web.de>
88 lines
2.4 KiB
Go
88 lines
2.4 KiB
Go
// Copyright 2022 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package v1_19
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"gitea.dev/modelmigration/migrationtest"
|
|
"gitea.dev/modules/json"
|
|
"gitea.dev/modules/secret"
|
|
"gitea.dev/modules/setting"
|
|
webhook_module "gitea.dev/modules/webhook"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func Test_AddHeaderAuthorizationEncryptedColWebhook(t *testing.T) {
|
|
// Create Webhook table
|
|
type Webhook struct {
|
|
ID int64 `xorm:"pk autoincr"`
|
|
Type webhook_module.HookType `xorm:"VARCHAR(16) 'type'"`
|
|
Meta string `xorm:"TEXT"` // store hook-specific attributes
|
|
|
|
// HeaderAuthorizationEncrypted should be accessed using HeaderAuthorization() and SetHeaderAuthorization()
|
|
HeaderAuthorizationEncrypted string `xorm:"TEXT"`
|
|
}
|
|
|
|
type ExpectedWebhook struct {
|
|
ID int64 `xorm:"pk autoincr"`
|
|
Meta string
|
|
HeaderAuthorization string
|
|
}
|
|
|
|
type HookTask struct {
|
|
ID int64 `xorm:"pk autoincr"`
|
|
HookID int64
|
|
PayloadContent string `xorm:"LONGTEXT"`
|
|
}
|
|
|
|
// Prepare and load the testing database
|
|
x, deferable := migrationtest.PrepareTestEnv(t, 0, new(Webhook), new(ExpectedWebhook), new(HookTask))
|
|
defer deferable()
|
|
if x == nil || t.Failed() {
|
|
return
|
|
}
|
|
|
|
if err := AddHeaderAuthorizationEncryptedColWebhook(x); err != nil {
|
|
assert.NoError(t, err)
|
|
return
|
|
}
|
|
|
|
expected := []ExpectedWebhook{}
|
|
if err := x.Table("expected_webhook").Asc("id").Find(&expected); !assert.NoError(t, err) {
|
|
return
|
|
}
|
|
|
|
got := []Webhook{}
|
|
if err := x.Table("webhook").Select("id, meta, header_authorization_encrypted").Asc("id").Find(&got); !assert.NoError(t, err) {
|
|
return
|
|
}
|
|
|
|
for i, e := range expected {
|
|
assert.Equal(t, e.Meta, got[i].Meta)
|
|
|
|
if e.HeaderAuthorization == "" {
|
|
assert.Empty(t, got[i].HeaderAuthorizationEncrypted)
|
|
} else {
|
|
cipherhex := got[i].HeaderAuthorizationEncrypted
|
|
cleartext, err := secret.DecryptSecret(setting.SecretKey, cipherhex)
|
|
assert.NoError(t, err)
|
|
assert.Equal(t, e.HeaderAuthorization, cleartext)
|
|
}
|
|
}
|
|
|
|
// ensure that no hook_task has some remaining "access_token"
|
|
hookTasks := []HookTask{}
|
|
if err := x.Table("hook_task").Select("id, payload_content").Asc("id").Find(&hookTasks); !assert.NoError(t, err) {
|
|
return
|
|
}
|
|
for _, h := range hookTasks {
|
|
var m map[string]any
|
|
err := json.Unmarshal([]byte(h.PayloadContent), &m)
|
|
assert.NoError(t, err)
|
|
assert.Nil(t, m["access_token"])
|
|
}
|
|
}
|