From f53aedf32b6132f1bf4e7c11517cfb85f1ba61a8 Mon Sep 17 00:00:00 2001 From: "kubestellar-hive[bot]" Date: Mon, 21 Sep 2026 12:08:07 -0400 Subject: [PATCH] test: repair architecture catalog fixture and cover sourceUrl, id and asset rules PR #334 added mandatory sourceUrl, id-slug and asset-containment rules to scripts/validate-architectures.mjs without updating the test fixtures. The validRecord fixture has no sourceUrl, so 'accepts a valid catalog' and 'accepts records without an assets array' both fail, leaving npm run test:unit red on main and the ci.yml 'Validate repository' check red on every open PR. Add sourceUrl to the fixture and cover the three rules #334 introduced: sourceUrl absent / http: / javascript: / unparseable / non-string, a non-slug id, and assets outside the prefix, escaping it via .., or not a string. Closes #397 Signed-off-by: kubestellar-hive[bot] --- tests/validate-architectures.test.mjs | 67 +++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) diff --git a/tests/validate-architectures.test.mjs b/tests/validate-architectures.test.mjs index 35e592ba..f8b808bd 100644 --- a/tests/validate-architectures.test.mjs +++ b/tests/validate-architectures.test.mjs @@ -8,6 +8,7 @@ const validRecord = { id: 'acme-platform', title: 'Acme Platform', organization: 'Acme Corp', + sourceUrl: 'https://github.com/cncf/architecture/blob/main/acme-platform.md', assets: ['/img/architectures/acme-platform/diagram.svg'], }; @@ -44,6 +45,72 @@ test('rejects duplicate ids', () => { assert.match(result.stderr, /duplicate id/); }); +test('rejects a record whose sourceUrl is absent', () => { + const { sourceUrl, ...noSource } = validRecord; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([noSource])); + assert.equal(result.status, 1); + assert.match(result.stderr, /sourceUrl must be an https URL/); +}); + +test('rejects a non-https sourceUrl', () => { + const record = { ...validRecord, sourceUrl: 'http://example.com/a' }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /sourceUrl must be an https URL/); +}); + +test('rejects a javascript: sourceUrl', () => { + const record = { ...validRecord, sourceUrl: 'javascript:alert(1)' }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /sourceUrl must be an https URL/); +}); + +test('rejects a sourceUrl that is not a parseable URL', () => { + const record = { ...validRecord, sourceUrl: 'not a url' }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /sourceUrl must be an https URL/); +}); + +test('rejects a sourceUrl that is not a string', () => { + const record = { ...validRecord, sourceUrl: 42 }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /sourceUrl must be an https URL/); +}); + +test('rejects an id that is not a lowercase slug', () => { + const record = { ...validRecord, id: 'Acme_Platform' }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /id must be a lowercase slug/); +}); + +test('rejects an asset outside the architectures prefix', () => { + const record = { ...validRecord, assets: ['/img/logos/acme.svg'] }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /must be a site-absolute path contained in/); +}); + +test('rejects an asset that escapes the architectures prefix with ..', () => { + const record = { + ...validRecord, + assets: ['/img/architectures/../../../etc/passwd'], + }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /must be a site-absolute path contained in/); +}); + +test('rejects an asset that is not a string', () => { + const record = { ...validRecord, assets: [42] }; + const result = runScriptWithFixtures(SCRIPT, catalogFixture([record])); + assert.equal(result.status, 1); + assert.match(result.stderr, /must be a site-absolute path contained in/); +}); + test('rejects assets missing from static/', () => { const fixtures = { 'data/architectures/catalog.json': JSON.stringify([validRecord]),