test(app-catalog): pin the signed-catalog body gate
This commit is contained in:
@@ -661,4 +661,23 @@ mod tests {
|
|||||||
]
|
]
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The signed-catalog body served to the browser must be the anchored,
|
||||||
|
// release-root-verified bytes — and nothing else. Unsigned caches (the
|
||||||
|
// migration-window form) and self-consistent-but-unanchored signatures
|
||||||
|
// must both be refused so a tampered mirror can never become an install
|
||||||
|
// button (same posture as the OTA manifest supply-chain gate).
|
||||||
|
#[tokio::test]
|
||||||
|
async fn verified_catalog_body_rejects_unsigned_cache() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
write_cache(dir.path(), r#"{"schema":1,"apps":{"demo":{"version":"1"}}}"#).unwrap();
|
||||||
|
let err = verified_catalog_body(dir.path()).await.unwrap_err();
|
||||||
|
assert!(err.to_string().contains("unsigned"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn verified_catalog_body_rejects_missing_cache() {
|
||||||
|
let dir = tempfile::tempdir().unwrap();
|
||||||
|
assert!(verified_catalog_body(dir.path()).await.is_err());
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user