(t *testing.T)
| 280 | } |
| 281 | |
| 282 | func TestValidateSignerWorkflow(t *testing.T) { |
| 283 | type testcase struct { |
| 284 | name string |
| 285 | providedSignerWorkflow string |
| 286 | expectedWorkflowRegex string |
| 287 | host string |
| 288 | expectErr bool |
| 289 | errContains string |
| 290 | } |
| 291 | |
| 292 | testcases := []testcase{ |
| 293 | { |
| 294 | name: "workflow with no host specified", |
| 295 | providedSignerWorkflow: "github/artifact-attestations-workflows/.github/workflows/attest.yml", |
| 296 | expectErr: true, |
| 297 | errContains: "unknown signer workflow host", |
| 298 | }, |
| 299 | { |
| 300 | name: "workflow with default host", |
| 301 | providedSignerWorkflow: "github/artifact-attestations-workflows/.github/workflows/attest.yml", |
| 302 | expectedWorkflowRegex: `^https://github\.com/github/artifact-attestations-workflows/\.github/workflows/attest\.yml(@(refs/.*|[0-9a-fA-F]+))?$`, |
| 303 | host: "github.com", |
| 304 | }, |
| 305 | { |
| 306 | name: "workflow with workflow URL included", |
| 307 | providedSignerWorkflow: "github.com/github/artifact-attestations-workflows/.github/workflows/attest.yml", |
| 308 | expectedWorkflowRegex: `^https://github\.com/github/artifact-attestations-workflows/\.github/workflows/attest\.yml(@(refs/.*|[0-9a-fA-F]+))?$`, |
| 309 | host: "github.com", |
| 310 | }, |
| 311 | { |
| 312 | name: "workflow with GH_HOST set", |
| 313 | providedSignerWorkflow: "github/artifact-attestations-workflows/.github/workflows/attest.yml", |
| 314 | expectedWorkflowRegex: `^https://myhost\.github\.com/github/artifact-attestations-workflows/\.github/workflows/attest\.yml(@(refs/.*|[0-9a-fA-F]+))?$`, |
| 315 | host: "myhost.github.com", |
| 316 | }, |
| 317 | { |
| 318 | name: "workflow with authenticated host", |
| 319 | providedSignerWorkflow: "github/artifact-attestations-workflows/.github/workflows/attest.yml", |
| 320 | expectedWorkflowRegex: `^https://authedhost\.github\.com/github/artifact-attestations-workflows/\.github/workflows/attest\.yml(@(refs/.*|[0-9a-fA-F]+))?$`, |
| 321 | host: "authedhost.github.com", |
| 322 | }, |
| 323 | } |
| 324 | |
| 325 | for _, tc := range testcases { |
| 326 | // All host resolution is done verify.go:RunE |
| 327 | workflowRegex, err := validateSignerWorkflow(tc.host, tc.providedSignerWorkflow) |
| 328 | require.Equal(t, tc.expectedWorkflowRegex, workflowRegex) |
| 329 | |
| 330 | if tc.expectErr { |
| 331 | require.Error(t, err) |
| 332 | require.ErrorContains(t, err, tc.errContains) |
| 333 | } else { |
| 334 | require.NoError(t, err) |
| 335 | require.Equal(t, tc.expectedWorkflowRegex, workflowRegex) |
| 336 | } |
| 337 | } |
| 338 | } |
| 339 |
nothing calls this directly
no test coverage detected