From ec8ca4f0fe7c9eb51b6f9103dad02cbcdd22c1b0 Mon Sep 17 00:00:00 2001 From: Borozdenets Ilya Date: Wed, 17 Jun 2026 14:54:53 +0300 Subject: [PATCH] test(server): use mkdtemp for GITNEXUS_HOME path-root test temp dirs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CodeQL js/insecure-temporary-file flagged the two writes that used a fixed os.tmpdir() name (gitnexus-home-roots-test, gitnexus-fallback-home): a co-located process could pre-create or symlink the predictable path before the test write lands. Switch both to fs.mkdtemp(), which atomically creates a uniquely-named directory — the canonical sanitizer this repo already uses (see core/group/storage.ts). Behavior is unchanged; tests still pass with and without GITNEXUS_HOME set. Co-Authored-By: Claude Opus 4.8 (1M context) --- gitnexus/test/unit/gitnexus-home-roots.test.ts | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/gitnexus/test/unit/gitnexus-home-roots.test.ts b/gitnexus/test/unit/gitnexus-home-roots.test.ts index ba51507a7..a8e51030a 100644 --- a/gitnexus/test/unit/gitnexus-home-roots.test.ts +++ b/gitnexus/test/unit/gitnexus-home-roots.test.ts @@ -1,4 +1,4 @@ -import { describe, it, expect, afterEach, vi } from 'vitest'; +import { describe, it, expect, beforeEach, afterEach, vi } from 'vitest'; import path from 'node:path'; import os from 'node:os'; import fs from 'node:fs/promises'; @@ -20,7 +20,14 @@ import fs from 'node:fs/promises'; */ describe('GITNEXUS_HOME path roots', () => { const savedHome = process.env.GITNEXUS_HOME; - const customHome = path.join(os.tmpdir(), 'gitnexus-home-roots-test'); + // mkdtemp (not a fixed os.tmpdir() name) so a co-located process cannot + // pre-create or symlink the path before our writes land + // (CodeQL js/insecure-temporary-file). + let customHome: string; + + beforeEach(async () => { + customHome = await fs.mkdtemp(path.join(os.tmpdir(), 'gitnexus-home-roots-')); + }); afterEach(async () => { if (savedHome === undefined) delete process.env.GITNEXUS_HOME; @@ -46,7 +53,6 @@ describe('GITNEXUS_HOME path roots', () => { it('server-mapping file is read from GITNEXUS_HOME', async () => { process.env.GITNEXUS_HOME = customHome; - await fs.mkdir(customHome, { recursive: true }); await fs.writeFile( path.join(customHome, 'server-mapping.json'), JSON.stringify({ 'my-repo': 'payments-service' }), @@ -73,7 +79,7 @@ describe('GITNEXUS_HOME path roots', () => { // home dir to a tmp path to exercise the real fallback (getGlobalDir() -> // ~/.gitnexus) without writing into the developer's actual // ~/.gitnexus/server-mapping.json. - const fakeHome = path.join(os.tmpdir(), 'gitnexus-fallback-home'); + const fakeHome = await fs.mkdtemp(path.join(os.tmpdir(), 'gitnexus-fallback-home-')); const savedHome = process.env.HOME; const savedUserProfile = process.env.USERPROFILE; delete process.env.GITNEXUS_HOME;