fix: close marketplace client review findings
This commit is contained in:
1 parent
8dfa542860
commit
1614f7efc1
25 files changed
+1224
-143
No files matched your search
@@ -14,6 +14,7 @@ import {
|
||||
collectForbiddenResourcePaths,
|
||||
verifyBundledCodingPluginResources,
|
||||
defaultProductExecutable,
|
||||
readPackagedMarketplaceTrustSource,
|
||||
validatePiArtifactMetadata,
|
||||
verifyMarketplaceClientArtifact,
|
||||
} from '../../scripts/lib/pi-product-artifact.mjs';
|
||||
@@ -198,7 +199,8 @@ describe('final Pi product artifact verification', () => {
|
||||
|
||||
const trustSource = `export const CODE_OWNED_PLUGIN_SIGNING_KEYS = Object.freeze(
|
||||
{} as Readonly<Record<string, string>>,
|
||||
);`;
|
||||
);
|
||||
export const sourceMarker = 'makelore.plugin-trust.code-owned.v1';`;
|
||||
expect(verifyMarketplaceClientArtifact(artifact, trustSource)).toMatchObject({
|
||||
schema2SkillOnly: true,
|
||||
productionTrust: 'official-key-absent-fail-closed',
|
||||
@@ -229,6 +231,50 @@ describe('final Pi product artifact verification', () => {
|
||||
)).toThrow('empty code-owned fail-closed store');
|
||||
});
|
||||
|
||||
it('proves Marketplace trust from the packaged app.asar rather than checkout source', async () => {
|
||||
const root = await mkdtemp(path.join(tmpdir(), 'makelore-marketplace-trust-asar-'));
|
||||
roots.push(root);
|
||||
const source = path.join(root, 'source');
|
||||
await mkdir(path.join(source, 'dist-electron'), { recursive: true });
|
||||
await writeFile(path.join(source, 'dist-electron', 'main.js'), [
|
||||
'const CODE_OWNED_PLUGIN_SIGNING_KEYS = Object.freeze({});',
|
||||
'const unrelatedConfiguration = process.env.NIANCODE_E2E;',
|
||||
'export const marketplace = true;',
|
||||
].join('\n'));
|
||||
const appAsar = path.join(root, 'app.asar');
|
||||
await createPackage(source, appAsar);
|
||||
await expect(readPackagedMarketplaceTrustSource(appAsar)).resolves.toBe(
|
||||
'CODE_OWNED_PLUGIN_SIGNING_KEYS = Object.freeze({})',
|
||||
);
|
||||
});
|
||||
|
||||
it('recognizes a minified trust table only when its packaged provenance marker is present', async () => {
|
||||
const root = await mkdtemp(path.join(tmpdir(), 'makelore-marketplace-compiled-trust-asar-'));
|
||||
roots.push(root);
|
||||
const source = path.join(root, 'source');
|
||||
await mkdir(path.join(source, 'dist-electron'), { recursive: true });
|
||||
await writeFile(path.join(source, 'dist-electron', 'main.js'), [
|
||||
'const dC = Object.freeze({});',
|
||||
'function createTrust() { return Object.freeze({ get: load, sourceMarker: "makelore.plugin-trust.code-owned.v1" }); }',
|
||||
].join('\n'));
|
||||
const appAsar = path.join(root, 'app.asar');
|
||||
await createPackage(source, appAsar);
|
||||
await expect(readPackagedMarketplaceTrustSource(appAsar)).resolves.toContain(
|
||||
'makelore.plugin-trust.code-owned.v1',
|
||||
);
|
||||
expect(verifyMarketplaceClientArtifact(
|
||||
Buffer.from([
|
||||
'makelore-plugin-release.v1', 'skill_only', 'plugin_signature_invalid',
|
||||
'signing key is not trusted', '/api/coding/plugin-marketplace',
|
||||
'plugin-marketplace\\/install\\/', 'plugin-marketplace\\/update\\/',
|
||||
'effectiveSkillIds', 'pluginReleaseIds',
|
||||
'/api/coding/plugin-marketplace/catalog', '/api/coding/plugin-marketplace/library',
|
||||
'免费获取', '我的插件',
|
||||
].join('\n')),
|
||||
'const dC = Object.freeze({}); sourceMarker: makelore.plugin-trust.code-owned.v1',
|
||||
)).toMatchObject({ productionTrust: 'official-key-absent-fail-closed' });
|
||||
});
|
||||
|
||||
it('rejects a packaged plugin tree that drops an SDK asset or catalog marker', async () => {
|
||||
const fixture = await bundledResourceFixture();
|
||||
await rm(path.join(
|
||||
|
||||
Reference in new issue
Block a user