Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Check for null in addition to undefined; extend tests accordingly
  • Loading branch information
mbg committed Jun 27, 2025
commit 6b83dc33ed025a7347650a5953f523cddd9d5c9f
14 changes: 11 additions & 3 deletions lib/start-proxy.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion lib/start-proxy.js.map

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

14 changes: 10 additions & 4 deletions lib/start-proxy.test.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion lib/start-proxy.test.js.map

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

34 changes: 19 additions & 15 deletions src/start-proxy.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -69,22 +69,26 @@ test("getCredentials throws error when credential is not an object", async (t) =
});

test("getCredentials throws error when credential missing host and url", async (t) => {
const registryCredentials = Buffer.from(
JSON.stringify([{ type: "npm_registry", token: "abc" }]),
).toString("base64");
const testCredentials = [
[{ type: "npm_registry", token: "abc" }],
[{ type: "npm_registry", token: "abc", host: null }],
[{ type: "npm_registry", token: "abc", url: null }],
].map(toEncodedJSON);

t.throws(
() =>
startProxyExports.getCredentials(
getRunnerLogger(true),
undefined,
registryCredentials,
undefined,
),
{
message: "Invalid credentials - must specify host or url",
},
);
for (const testCredential of testCredentials) {
t.throws(
() =>
startProxyExports.getCredentials(
getRunnerLogger(true),
undefined,
testCredential,
undefined,
),
Comment on lines +81 to +86

Check failure

Code scanning / CodeQL

Untrusted data passed to external API with additional heuristic sources

Call to ava.\[callback\].\[param 't'\].throws() \[callback 0 result\] with untrusted data from [getToke ... word(e)](1).
{
message: "Invalid credentials - must specify host or url",
},
);
}
});

test("getCredentials filters by language when specified", async (t) => {
Expand Down
15 changes: 12 additions & 3 deletions src/start-proxy.ts
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,15 @@ const LANGUAGE_TO_REGISTRY_TYPE: Record<Language, string> = {
swift: "",
} as const;

/**
* Checks that `value` is neither `undefined` nor `null`.
* @param value The value to test.
* @returns Narrows the type of `value` to exclude `undefined` and `null`.
*/
function isDefined<T>(value: T | null | undefined): value is T {
return value !== undefined && value !== null;
}

// getCredentials returns registry credentials from action inputs.
// It prefers `registries_credentials` over `registry_secrets`.
// If neither is set, it returns an empty array.
Expand Down Expand Up @@ -77,14 +86,14 @@ export function getCredentials(
}

// Mask credentials to reduce chance of accidental leakage in logs.
if (e.password !== undefined) {
if (isDefined(e.password)) {
core.setSecret(e.password);
}
if (e.token !== undefined) {
if (isDefined(e.token)) {
core.setSecret(e.token);
}

if (e.url === undefined && e.host === undefined) {
if (!isDefined(e.url) && !isDefined(e.host)) {
// The proxy needs one of these to work. If both are defined, the url has the precedence.
throw new ConfigurationError(
"Invalid credentials - must specify host or url",
Expand Down