返回 DeepSeek-Reasonix
write_access_test.go
根目录 / internal / config / write_access_test.go
1 package config
2
3 import (
4 "os"
5 "path/filepath"
6 "slices"
7 "testing"
8 )
9
10 // A write-access grant is the user's, so it lands under their home and never
11 // in the checkout, where the project file could not have granted it anyway.
12 func TestPersistWorkspaceWriteAccessRecordsBothGrants(t *testing.T) {
13 home, root, extra := t.TempDir(), t.TempDir(), t.TempDir()
14 if err := os.WriteFile(filepath.Join(root, "reasonix.toml"), []byte("# keep\n"), 0o644); err != nil {
15 t.Fatal(err)
16 }
17 if err := PersistWorkspaceWriteAccess(home, root, []string{extra}, "Edit"); err != nil {
18 t.Fatal(err)
19 }
20 grant, err := NewProjectGrantStore(home).Grant(root)
21 if err != nil {
22 t.Fatal(err)
23 }
24 if !slices.Equal(grant.Allow, []string{"Edit"}) || len(grant.AllowWrite) != 1 {
25 t.Fatalf("grant = %+v, want the rule and the directory", grant)
26 }
27 if raw, _ := os.ReadFile(filepath.Join(root, "reasonix.toml")); string(raw) != "# keep\n" {
28 t.Fatalf("the checkout's reasonix.toml changed: %q", raw)
29 }
30 }
31
32 func TestPersistWorkspaceWriteAccessDoesNotDuplicateAncestor(t *testing.T) {
33 home, root := t.TempDir(), t.TempDir()
34 parent := filepath.Join(t.TempDir(), "home")
35 if err := os.MkdirAll(parent, 0o755); err != nil {
36 t.Fatal(err)
37 }
38 if err := PersistWorkspaceWriteAccess(home, root, []string{parent}, ""); err != nil {
39 t.Fatal(err)
40 }
41 if err := PersistWorkspaceWriteAccess(home, root, []string{filepath.Join(parent, "bin")}, ""); err != nil {
42 t.Fatal(err)
43 }
44 grant, err := NewProjectGrantStore(home).Grant(root)
45 if err != nil {
46 t.Fatal(err)
47 }
48 if len(grant.AllowWrite) != 1 {
49 t.Fatalf("allow_write = %v, want the ancestor alone", grant.AllowWrite)
50 }
51 }
52
52 lines GO