Files
pnpm/installing/commands/test/importRecursive.ts
Zoltan Kochan 45a6cb6b2a refactor(auth): unify auth/SSL into structured configByUri (#11201)
Replaces the dual `authConfig` (raw .npmrc) + `authInfos` (parsed auth) + `sslConfigs` (parsed SSL) pattern with a single structured `configByUri: Record<string, RegistryConfig>` field on Config.

### New types (`@pnpm/types`)
- **`RegistryConfig`** — per-registry config: `{ creds?: Creds, tls?: TlsConfig }`
- **`Creds`** — auth credentials: `{ authToken?, basicAuth?, tokenHelper? }`
- **`TlsConfig`** — TLS config: `{ cert?, key?, ca? }`

### Key changes
- Rewrite `createGetAuthHeaderByURI` to accept `Record<string, RegistryConfig>` instead of raw .npmrc key-value pairs
- Eliminate duplicate auth parsing between `getAuthHeadersFromConfig` and `getNetworkConfigs`
- Remove `authConfig` from the install pipeline (`StrictInstallOptions`, `HeadlessOptions`), replaced by `configByUri`
- Remove `sslConfigs` from Config — SSL fields now live in `configByUri[uri].tls`
- Remove `authConfig['registry']` mutation in `extendInstallOptions` (default registry now passed directly to `createGetAuthHeaderByURI`)
- `authConfig` remains on Config only for raw .npmrc access (config commands, error reporting, config inheritance)

### Security
- tokenHelper in project .npmrc now throws instead of being silently stripped
- tokenHelper execution uses `shell: false` to prevent shell metacharacter injection
- Basic auth uses `Buffer.from().toString('base64')` instead of `btoa()` for Unicode safety
- Dispatcher only creates custom agents when entries actually have TLS fields
2026-04-05 20:15:10 +02:00

118 lines
4.2 KiB
TypeScript

/// <reference path="../../../__typings__/index.d.ts" />
import path from 'node:path'
import { assertProject } from '@pnpm/assert-project'
import { importCommand } from '@pnpm/installing.commands'
import { REGISTRY_MOCK_PORT } from '@pnpm/registry-mock'
import { fixtures } from '@pnpm/test-fixtures'
import { filterProjectsBySelectorObjectsFromDir } from '@pnpm/workspace.projects-filter'
import { temporaryDirectory } from 'tempy'
const f = fixtures(import.meta.dirname)
const REGISTRY = `http://localhost:${REGISTRY_MOCK_PORT}`
const TMP = temporaryDirectory()
const DEFAULT_OPTS = {
ca: undefined,
cacheDir: path.join(TMP, 'cache'),
cert: undefined,
fetchRetries: 2,
fetchRetryFactor: 90,
fetchRetryMaxtimeout: 90,
fetchRetryMintimeout: 10,
httpsProxy: undefined,
key: undefined,
localAddress: undefined,
lock: false,
lockStaleDuration: 90,
minimumReleaseAge: 0,
networkConcurrency: 16,
offline: false,
preferWorkspacePackages: true,
proxy: undefined,
pnpmHomeDir: '',
configByUri: {},
registries: { default: REGISTRY },
registry: REGISTRY,
rootProjectManifestDir: '',
storeDir: path.join(TMP, 'store'),
strictSsl: false,
userAgent: 'pnpm',
userConfig: {},
useRunningStoreServer: false,
useStoreServer: false,
virtualStoreDirMaxLength: process.platform === 'win32' ? 60 : 120,
}
test('import from shared yarn.lock of monorepo', async () => {
f.prepare('workspace-has-shared-yarn-lock')
const { allProjects, allProjectsGraph, selectedProjectsGraph } = await filterProjectsBySelectorObjectsFromDir(process.cwd(), [])
await importCommand.handler({
...DEFAULT_OPTS,
allProjects: allProjects as any, // eslint-disable-line @typescript-eslint/no-explicit-any
allProjectsGraph,
selectedProjectsGraph,
workspaceDir: process.cwd(),
lockfileDir: process.cwd(),
dir: process.cwd(),
resolutionMode: 'highest', // TODO: this should work with the default resolution mode (TODOv8)
}, [])
const project = assertProject(process.cwd())
const lockfile = project.readLockfile()
expect(lockfile.packages).toHaveProperty(['is-positive@1.0.0'])
expect(lockfile.packages).toHaveProperty(['is-negative@1.0.1'])
// node_modules is not created
project.hasNot('is-positive')
project.hasNot('is-negative')
})
test('import from shared package-lock.json of monorepo', async () => {
f.prepare('workspace-has-shared-package-lock-json')
const { allProjects, allProjectsGraph, selectedProjectsGraph } = await filterProjectsBySelectorObjectsFromDir(process.cwd(), [])
await importCommand.handler({
...DEFAULT_OPTS,
allProjects: allProjects as any, // eslint-disable-line @typescript-eslint/no-explicit-any
allProjectsGraph,
selectedProjectsGraph,
workspaceDir: process.cwd(),
lockfileDir: process.cwd(),
dir: process.cwd(),
resolutionMode: 'highest', // TODO: this should work with the default resolution mode (TODOv8)
}, [])
const project = assertProject(process.cwd())
const lockfile = project.readLockfile()
expect(lockfile.packages).toHaveProperty(['is-positive@1.0.0'])
expect(lockfile.packages).toHaveProperty(['is-negative@1.0.1'])
// node_modules is not created
project.hasNot('is-positive')
project.hasNot('is-negative')
})
test('import from shared npm-shrinkwrap.json of monorepo', async () => {
f.prepare('workspace-has-shared-npm-shrinkwrap-json')
const { allProjects, allProjectsGraph, selectedProjectsGraph } = await filterProjectsBySelectorObjectsFromDir(process.cwd(), [])
await importCommand.handler({
...DEFAULT_OPTS,
allProjects: allProjects as any, // eslint-disable-line @typescript-eslint/no-explicit-any
allProjectsGraph,
selectedProjectsGraph,
workspaceDir: process.cwd(),
lockfileDir: process.cwd(),
dir: process.cwd(),
resolutionMode: 'highest', // TODO: this should work with the default resolution mode (TODOv8)
}, [])
const project = assertProject(process.cwd())
const lockfile = project.readLockfile()
expect(lockfile.packages).toHaveProperty(['is-positive@1.0.0'])
expect(lockfile.packages).toHaveProperty(['is-negative@1.0.1'])
// node_modules is not created
project.hasNot('is-positive')
project.hasNot('is-negative')
})