package appbundle import ( "strings" "testing" ) // Check lexical rejection independently of missing-file rejection. Invalid paths // cannot always be materialized on Windows, so a missing file is not sufficient // evidence that the manifest validator enforces portable paths. func TestPortablePathValidation(t *testing.T) { for _, path := range []string{ "", "../escape", "a/../b", "a/./b", "/root", "c:/file", `a\b`, "a//b", "a/", ".env", "a/.secret", "a/secret ", "a/secret.", "con", "prn.txt", "aux.txt", "nul", "a/com1.log", "lpt9", "UPPER.txt", "a:stream", "café", strings.Repeat("a", 101), strings.Repeat("a/", 120) + "b", } { if validPath(path) { t.Errorf("accepted invalid path %q", path) } } for _, path := range []string{ "compose.yaml", "dir-a/1_config.json", "com0.txt", "lpt10.txt", strings.Repeat("a", 100), strings.Repeat("a", 100) + "/" + strings.Repeat("b", 100) + "/" + strings.Repeat("c", 38), } { if !validPath(path) { t.Errorf("rejected valid path %q", path) } } } func TestImageDigestAndRepositoryValidation(t *testing.T) { for _, image := range []string{ "api@sha256:" + strings.Repeat("a", 63), "api@sha256:" + strings.Repeat("A", 64), "api@sha256:" + strings.Repeat("a", 65), "api@sha512:" + strings.Repeat("a", 64), "api:tag@sha256:" + strings.Repeat("a", 64), "api@sha256:" + strings.Repeat("a", 64) + "@extra", } { if validImage(image) { t.Errorf("accepted invalid image %q", image) } } for _, repo := range []string{"a", "registry.example/team/api", "team_name/app-v2.0"} { if !validImage(repo + "@sha256:" + strings.Repeat("a", 64)) { t.Errorf("rejected valid repository %q", repo) } } }