test.rules/rules/eslint/no-plaintext-transport.eslint.rule.test.ts

test.rules/rules/eslint/no-plaintext-transport.eslint.rule.test.ts is a file in Codebase Testing. 64 lines of code and 0 definitions.

import {
    EXTERNAL_PLAINTEXT_ENDPOINTS,
    URL_SHAPED_IDENTIFIERS,
} from "@ssot/govlab/shared/manifests/identifier.manifest.ts";
import { describe, expect, it } from "vitest";
import { Linter } from "eslint";
import rule from "@ssot/govlab/rules/eslint/no-plaintext-transport.eslint.rule.ts";

const linter = new Linter();
const config = [
    {
        files: ["**/*.ts"],
        languageOptions: { ecmaVersion: 2025 as const, sourceType: "module" as const },
        plugins: { t: { rules: { r: rule } } },
        rules: { "t/r": "error" as const },
    },
];

const FILE = "sample.ts";

const idsFor = function idsFor(code: string): string[] {
    return linter
        .verify(code, config, FILE)
        .map((message) => message.messageId)
        .filter((id): id is string => typeof id === "string");
};

describe("no-plaintext-transport", () => {
    it("reports a plaintext URL in a literal and in a template", () => {
        expect(idsFor('const url = "http://127.0.0.1:4204/";')).toStrictEqual(["plaintextUrl"]);
        const templated = ["const url = `http://", "{host}:", "{port}/`;"].join("$");
        expect(idsFor(templated)).toStrictEqual(["plaintextUrl"]);
    });

    it("accepts only the exact template shape of a registered external endpoint", () => {
        const [shape] = [...EXTERNAL_PLAINTEXT_ENDPOINTS];
        expect(shape).toBe("ws://127.0.0.1:…/devtools/…");
        const registered = ["const url = `ws://127.0.0.1:", "{port}/devtools/", "{target}`;"].join("$");
        expect(idsFor(registered)).toStrictEqual([]);
        const elsewhere = ["const url = `ws://127.0.0.1:", "{port}/other/", "{target}`;"].join("$");
        expect(idsFor(elsewhere)).toStrictEqual(["plaintextUrl"]);
    });

    it("reports a plaintext socket URL and accepts the encrypted socket scheme", () => {
        const socket = ["const url = `ws://127.0.0.1:", "{port}/devtools`;"].join("$");
        expect(idsFor(socket)).toStrictEqual(["plaintextUrl"]);
        expect(idsFor('const url = "wss://127.0.0.1:4204/";')).toStrictEqual([]);
    });

    it("accepts the encrypted scheme and a bare scheme token used for classification", () => {
        expect(idsFor('const url = "https://127.0.0.1:4204/";')).toStrictEqual([]);
        expect(idsFor('const SCHEMES = ["http://", "https://"];')).toStrictEqual([]);
    });

    it("accepts a URL-shaped identifier the registry classifies, which is never fetched", () => {
        const [namespace] = [...URL_SHAPED_IDENTIFIERS];
        expect(namespace?.startsWith("http://")).toBe(true);
        expect(idsFor(`const NAMESPACE = ${JSON.stringify(namespace)};`)).toStrictEqual([]);
    });

    it("reports a server block that listens on a port without declaring encrypted transport", () => {
        expect(idsFor("const config = { server: { port: 4203, strictPort: true } };")).toStrictEqual([
            "plaintextListener",
        ]);
        expect(idsFor("const config = { server: listen ? { port: 4204 } : { middlewareMode: true } };")).toStrictEqual([
            "plaintextListener",
        ]);
    });

    it("accepts a server block that declares its transport, and one that does not listen", () => {
        expect(idsFor("const config = { server: { https: certificate, port: 4203 } };")).toStrictEqual([]);
        expect(idsFor("const config = { server: { middlewareMode: true } };")).toStrictEqual([]);
    });
});