Registry metadata mirrors were keyed on host[:port], so several registries served from one host under different path prefixes shared one directory and could answer with each other's versions, integrity hashes and tarball URLs. Both stacks now key the mirror on <scheme>%3A+<host>[+<port>][%2F<path>][%5F<sha256>]. The host and every path segment are percent-escaped down to [A-Za-z0-9._-], so a `%` or `+` in a key is always one the encoder wrote and the key can carry no path separator, no character Windows rejects in a filename, and no glob metacharacter — the cache commands feed the key to a glob whose matches `pnpm cache delete` removes. The scheme is included because http and https at one host and path are two different trust domains: metadata served over http can be rewritten in transit and must never reach a resolution configured for https. The separators are percent-escapes because every key pnpm wrote before this change was a URL host, which can never hold a `%`; no new key can therefore land on the stale directory of an unrelated one whose hostname held a separator, which would otherwise let `https://nexus/npm/` read what was cached for `https://nexus_npm/`. A path that is not all lowercase gets a sha256 suffix, the guard encodePkgName already applies to package names, so HFS+ and NTFS cannot merge two registries; a trailing `.` is escaped because Win32 strips one; and a key too long for a 255-byte filename is replaced by its own hash. Only the one trailing slash the resolver itself appends is normalized away; a repeated slash reaches the registry as a distinct request path and stays in the key. Every cache directory is renamed, so the first install after upgrading refetches registry metadata once. The package store is untouched. `pnpm cache view` decodes the key back to the registry rather than replacing `+` with `:`, the registry URL is redacted in both stacks' errors, and the Rust diagnostic codes now match pnpm's. Closes pnpm/pnpm#13558. --------- Co-authored-by: Zoltan Kochan <z@kochan.io>
118 lines
3.1 KiB
TypeScript
118 lines
3.1 KiB
TypeScript
import path from 'node:path'
|
|
|
|
import { beforeEach, describe, expect, test } from '@jest/globals'
|
|
import { cache } from '@pnpm/cache.commands'
|
|
import { prepare } from '@pnpm/prepare'
|
|
import { REGISTRY_MOCK_PORT } from '@pnpm/testing.registry-mock'
|
|
import { rimrafSync } from '@zkochan/rimraf'
|
|
import { safeExeca as execa } from 'execa'
|
|
|
|
const pnpmBin = path.join(import.meta.dirname, '../../../pnpm/bin/pnpm.mjs')
|
|
const REGISTRY = `http://localhost:${REGISTRY_MOCK_PORT}/`
|
|
|
|
describe('cache view', () => {
|
|
let cacheDir: string
|
|
let storeDir: string
|
|
beforeEach(async () => {
|
|
prepare()
|
|
cacheDir = path.resolve('cache')
|
|
storeDir = path.resolve('store')
|
|
|
|
await execa('node', [
|
|
pnpmBin,
|
|
'add',
|
|
'is-negative@2.1.0',
|
|
`--store-dir=${storeDir}`,
|
|
`--cache-dir=${cacheDir}`,
|
|
'--config.resolution-mode=highest',
|
|
`--registry=${REGISTRY}`,
|
|
])
|
|
rimrafSync('node_modules')
|
|
rimrafSync('pnpm-lock.yaml')
|
|
await execa('node', [
|
|
pnpmBin,
|
|
'add',
|
|
'is-negative@2.1.0',
|
|
`--store-dir=${storeDir}`,
|
|
`--cache-dir=${cacheDir}`,
|
|
'--config.resolution-mode=highest',
|
|
])
|
|
})
|
|
test('lists all metadata for requested package', async () => {
|
|
const result = await cache.handler({
|
|
cacheDir,
|
|
cliOptions: {},
|
|
pnpmHomeDir: process.cwd(),
|
|
storeDir,
|
|
}, ['view', 'is-negative'])
|
|
|
|
expect(JSON.parse(result!)).toMatchObject({
|
|
[`http://localhost:${REGISTRY_MOCK_PORT}/`]: {
|
|
cachedVersions: ['2.1.0'],
|
|
nonCachedVersions: [
|
|
'1.0.0',
|
|
'1.0.1',
|
|
'2.0.0',
|
|
'2.0.1',
|
|
'2.0.2',
|
|
],
|
|
},
|
|
'https://registry.npmjs.org/': {
|
|
cachedVersions: ['2.1.0'],
|
|
nonCachedVersions: [
|
|
'1.0.0',
|
|
'1.0.1',
|
|
'2.0.0',
|
|
'2.0.1',
|
|
'2.0.2',
|
|
],
|
|
},
|
|
})
|
|
})
|
|
test('lists metadata for requested package from specified registry', async () => {
|
|
const result = await cache.handler({
|
|
cacheDir,
|
|
cliOptions: {
|
|
registry: 'https://registry.npmjs.org/',
|
|
},
|
|
pnpmHomeDir: process.cwd(),
|
|
storeDir,
|
|
}, ['view', 'is-negative'])
|
|
|
|
expect(JSON.parse(result!)).toMatchObject({
|
|
'https://registry.npmjs.org/': {
|
|
cachedVersions: ['2.1.0'],
|
|
nonCachedVersions: [
|
|
'1.0.0',
|
|
'1.0.1',
|
|
'2.0.0',
|
|
'2.0.1',
|
|
'2.0.2',
|
|
],
|
|
},
|
|
})
|
|
})
|
|
|
|
test('lists all metadata for requested package should specify a package name', async () => {
|
|
await expect(
|
|
cache.handler({
|
|
cacheDir,
|
|
cliOptions: {},
|
|
pnpmHomeDir: process.cwd(),
|
|
storeDir,
|
|
}, ['view'])
|
|
).rejects.toThrow('`pnpm cache view` requires the package name')
|
|
})
|
|
|
|
test('lists all metadata for requested package should not accept more than one package name', async () => {
|
|
await expect(
|
|
cache.handler({
|
|
cacheDir,
|
|
cliOptions: {},
|
|
pnpmHomeDir: process.cwd(),
|
|
storeDir,
|
|
}, ['view', 'is-negative', 'is-positive'])
|
|
).rejects.toThrow('`pnpm cache view` only accepts one package name')
|
|
})
|
|
})
|