MCPcopy Create free account
hub / github.com/codehamr/codehamr / TestStrictYAMLRejectsUnknownKey

Function TestStrictYAMLRejectsUnknownKey

internal/config/config_test.go:535–548  ·  view source on GitHub ↗

TestStrictYAMLRejectsUnknownKey: unknown top-level keys in config.yaml must fail loud, not be silently ignored: surfaces typos immediately.

(t *testing.T)

Source from the content-addressed store, hash-verified

533 }
534 _, _, err := Bootstrap(root)
535 if err == nil {
536 t.Fatal("Bootstrap accepted a symlinked .codehamr: config-injection vector left open")
537 }
538 if !strings.Contains(err.Error(), "symlink") {
539 t.Fatalf("error should name the symlink defence: %v", err)
540 }
541 // Target must stay untouched, nothing dropped into the attacker controlled dir.
542 if _, err := os.Stat(filepath.Join(target, "config.yaml")); err == nil {
543 t.Fatal("Bootstrap wrote into the symlink target despite the rejection")
544 }
545}
546
547func TestBootstrapRefusesSymlinkedConfigYAML(t *testing.T) {
548 root := t.TempDir()
549 dir := filepath.Join(root, DirName)
550 if err := os.MkdirAll(dir, 0o700); err != nil {
551 t.Fatal(err)

Callers

nothing calls this directly

Calls 1

BootstrapFunction · 0.85

Tested by

no test coverage detected