mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-08 03:10:26 +00:00
style: rustfmt --all
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
ff6538b77c
commit
cdbbe87e38
12 changed files with 110 additions and 67 deletions
|
|
@ -1803,7 +1803,8 @@ async fn run_install_inner(
|
|||
.context("failed to parse generated settings.toml")?,
|
||||
args.storage_dir.as_deref(),
|
||||
);
|
||||
fabro_config::resolve_server_from_file(&install_settings).map_err(render_server_resolve_errors)?;
|
||||
fabro_config::resolve_server_from_file(&install_settings)
|
||||
.map_err(render_server_resolve_errors)?;
|
||||
|
||||
// Secrets and auth material
|
||||
{
|
||||
|
|
|
|||
|
|
@ -127,9 +127,9 @@ mod tests {
|
|||
|
||||
fn test_record(bind: Bind) -> ServerRecord {
|
||||
ServerRecord {
|
||||
pid: std::process::id(),
|
||||
pid: std::process::id(),
|
||||
bind,
|
||||
log_path: PathBuf::from("/tmp/storage/logs/server.log"),
|
||||
log_path: PathBuf::from("/tmp/storage/logs/server.log"),
|
||||
started_at: Utc::now(),
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -14,10 +14,10 @@ use fabro_server::bind::{Bind, BindRequest};
|
|||
use fabro_server::jwt_auth::auth_method_name;
|
||||
use fabro_server::serve;
|
||||
use fabro_server::serve::{DEFAULT_TCP_PORT, ServeArgs};
|
||||
use fabro_util::printer::Printer;
|
||||
use fabro_util::terminal::Styles;
|
||||
use fabro_util::session_secret;
|
||||
use fabro_types::settings::ServerAuthMethod;
|
||||
use fabro_util::printer::Printer;
|
||||
use fabro_util::session_secret;
|
||||
use fabro_util::terminal::Styles;
|
||||
use tokio::net::{TcpStream, UnixStream};
|
||||
use tokio::process::Command as TokioCommand;
|
||||
use tokio::task::spawn_blocking;
|
||||
|
|
@ -265,12 +265,14 @@ async fn execute_foreground(
|
|||
let session_secret = load_or_create_local_session_secret(&storage_dir)?;
|
||||
let prior_session_secret = std::env::var_os("SESSION_SECRET");
|
||||
std::env::set_var("SESSION_SECRET", &session_secret);
|
||||
let _env_guard = scopeguard::guard(prior_session_secret, |prior_session_secret| {
|
||||
match prior_session_secret {
|
||||
Some(value) => std::env::set_var("SESSION_SECRET", value),
|
||||
None => std::env::remove_var("SESSION_SECRET"),
|
||||
}
|
||||
});
|
||||
let _env_guard =
|
||||
scopeguard::guard(
|
||||
prior_session_secret,
|
||||
|prior_session_secret| match prior_session_secret {
|
||||
Some(value) => std::env::set_var("SESSION_SECRET", value),
|
||||
None => std::env::remove_var("SESSION_SECRET"),
|
||||
},
|
||||
);
|
||||
|
||||
let runtime_state = ServerRuntimeState::new(&storage_dir);
|
||||
let record_path = runtime_state.record_path();
|
||||
|
|
|
|||
|
|
@ -15,12 +15,7 @@ pub(crate) fn storage_dir(settings: &SettingsLayer) -> Result<PathBuf> {
|
|||
let storage_root = fabro_config::resolve_storage_root(settings);
|
||||
let resolved_root = storage_root
|
||||
.resolve(|name| std::env::var(name).ok())
|
||||
.map_err(|err| {
|
||||
anyhow::anyhow!(
|
||||
"failed to resolve {}: {err}",
|
||||
storage_root.as_source()
|
||||
)
|
||||
})?;
|
||||
.map_err(|err| anyhow::anyhow!("failed to resolve {}: {err}", storage_root.as_source()))?;
|
||||
Ok(PathBuf::from(resolved_root.value))
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -204,10 +204,7 @@ fn load_cli_dev_token() -> Option<String> {
|
|||
load_cli_dev_token_from_sources(env_token.as_deref(), &Home::from_env())
|
||||
}
|
||||
|
||||
fn load_cli_dev_token_from_sources(
|
||||
env_token: Option<&str>,
|
||||
home: &Home,
|
||||
) -> Option<String> {
|
||||
fn load_cli_dev_token_from_sources(env_token: Option<&str>, home: &Home) -> Option<String> {
|
||||
if let Some(token) = env_token.filter(|token| validate_dev_token_format(token)) {
|
||||
return Some(token.to_owned());
|
||||
}
|
||||
|
|
@ -304,7 +301,12 @@ fn resolve_local_tcp_credential_with_store(
|
|||
fn resolve_local_tcp_credential(target: &ServerTarget) -> Result<Option<Credential>> {
|
||||
let env_token = std::env::var("FABRO_DEV_TOKEN").ok();
|
||||
let store = AuthStore::default();
|
||||
resolve_local_tcp_credential_with_store(target, env_token.as_deref(), &store, chrono::Utc::now())
|
||||
resolve_local_tcp_credential_with_store(
|
||||
target,
|
||||
env_token.as_deref(),
|
||||
&store,
|
||||
chrono::Utc::now(),
|
||||
)
|
||||
}
|
||||
|
||||
fn resolve_target_credential(
|
||||
|
|
@ -323,8 +325,10 @@ fn resolve_target_credential(
|
|||
}
|
||||
|
||||
if allow_local_dev_token_fallback {
|
||||
return Ok(load_cli_dev_token_from_sources(env_token.as_deref(), &Home::from_env())
|
||||
.map(Credential::DevToken));
|
||||
return Ok(
|
||||
load_cli_dev_token_from_sources(env_token.as_deref(), &Home::from_env())
|
||||
.map(Credential::DevToken),
|
||||
);
|
||||
}
|
||||
|
||||
Ok(None)
|
||||
|
|
@ -418,9 +422,7 @@ mod tests {
|
|||
|
||||
let credential = resolve_local_tcp_credential_with_store(
|
||||
&target,
|
||||
Some(
|
||||
"fabro_dev_cdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcd",
|
||||
),
|
||||
Some("fabro_dev_cdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcd"),
|
||||
&store,
|
||||
Utc::now(),
|
||||
)
|
||||
|
|
@ -436,7 +438,13 @@ mod tests {
|
|||
let store = AuthStore::new(dir.path().join("auth.json"));
|
||||
let now = Utc::now();
|
||||
store
|
||||
.put(&target, oauth_entry(now + ChronoDuration::minutes(5), now - ChronoDuration::minutes(1)))
|
||||
.put(
|
||||
&target,
|
||||
oauth_entry(
|
||||
now + ChronoDuration::minutes(5),
|
||||
now - ChronoDuration::minutes(1),
|
||||
),
|
||||
)
|
||||
.unwrap();
|
||||
|
||||
let credential =
|
||||
|
|
@ -511,11 +519,19 @@ mod tests {
|
|||
|
||||
#[test]
|
||||
fn bypasses_proxy_for_loopback_http_targets() {
|
||||
assert!(should_bypass_proxy_for_http_target("http://127.0.0.1:32276"));
|
||||
assert!(should_bypass_proxy_for_http_target(
|
||||
"http://127.0.0.1:32276"
|
||||
));
|
||||
assert!(should_bypass_proxy_for_http_target("http://[::1]:32276"));
|
||||
assert!(should_bypass_proxy_for_http_target("http://localhost:32276"));
|
||||
assert!(!should_bypass_proxy_for_http_target("https://fabro.example.com"));
|
||||
assert!(!should_bypass_proxy_for_http_target("http://fabro.example.com"));
|
||||
assert!(should_bypass_proxy_for_http_target(
|
||||
"http://localhost:32276"
|
||||
));
|
||||
assert!(!should_bypass_proxy_for_http_target(
|
||||
"https://fabro.example.com"
|
||||
));
|
||||
assert!(!should_bypass_proxy_for_http_target(
|
||||
"http://fabro.example.com"
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
|
@ -535,18 +551,18 @@ mod tests {
|
|||
refresh_token_expires_at: chrono::DateTime<chrono::Utc>,
|
||||
) -> AuthEntry {
|
||||
AuthEntry {
|
||||
access_token: "access-token".to_string(),
|
||||
access_token: "access-token".to_string(),
|
||||
access_token_expires_at,
|
||||
refresh_token: "refresh-token".to_string(),
|
||||
refresh_token: "refresh-token".to_string(),
|
||||
refresh_token_expires_at,
|
||||
subject: StoredSubject {
|
||||
subject: StoredSubject {
|
||||
idp_issuer: "https://github.com/login/oauth".to_string(),
|
||||
idp_subject: "subject-123".to_string(),
|
||||
login: "octocat".to_string(),
|
||||
name: "Octo Cat".to_string(),
|
||||
email: "octocat@example.com".to_string(),
|
||||
},
|
||||
logged_in_at: Utc::now(),
|
||||
logged_in_at: Utc::now(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -248,7 +248,10 @@ url = "https://config.example.com"
|
|||
fn storage_dir_defaults_without_server_auth_methods() {
|
||||
let settings = SettingsLayer::default();
|
||||
|
||||
assert_eq!(storage_dir(&settings).unwrap(), fabro_config::user::default_storage_dir());
|
||||
assert_eq!(
|
||||
storage_dir(&settings).unwrap(),
|
||||
fabro_config::user::default_storage_dir()
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
|
|
|||
|
|
@ -275,7 +275,10 @@ fn detach_uses_configured_server_target_without_server_flag() {
|
|||
#[test]
|
||||
fn run_uses_vault_credentials_for_worker_execution() {
|
||||
let mut context = test_context!();
|
||||
context.write_home(".fabro/settings.toml", "[server.auth]\nmethods = [\"dev-token\"]\n");
|
||||
context.write_home(
|
||||
".fabro/settings.toml",
|
||||
"[server.auth]\nmethods = [\"dev-token\"]\n",
|
||||
);
|
||||
context.isolated_server();
|
||||
let run_id = unique_run_id();
|
||||
let llm_server = MockServer::start();
|
||||
|
|
|
|||
|
|
@ -33,11 +33,7 @@ fn write_dev_token_server_settings(config_path: &std::path::Path, rest: &str) {
|
|||
fn provision_dev_token_auth(home_dir: &std::path::Path, storage_dir: &std::path::Path) {
|
||||
let server_env_path = Storage::new(storage_dir).runtime_state().env_path();
|
||||
envfile::merge_env_file(&server_env_path, [("FABRO_DEV_TOKEN", TEST_DEV_TOKEN)]).unwrap();
|
||||
dev_token::write_dev_token(
|
||||
&home_dir.join(".fabro").join("dev-token"),
|
||||
TEST_DEV_TOKEN,
|
||||
)
|
||||
.unwrap();
|
||||
dev_token::write_dev_token(&home_dir.join(".fabro").join("dev-token"), TEST_DEV_TOKEN).unwrap();
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
|
@ -103,7 +99,10 @@ fn start_already_running_exits_with_error() {
|
|||
let context = test_context!();
|
||||
let storage_root = isolated_storage_dir();
|
||||
let storage_dir = storage_root.path().join("storage");
|
||||
context.write_home(".fabro/settings.toml", "[server.auth]\nmethods = [\"dev-token\"]\n");
|
||||
context.write_home(
|
||||
".fabro/settings.toml",
|
||||
"[server.auth]\nmethods = [\"dev-token\"]\n",
|
||||
);
|
||||
provision_dev_token_auth(&context.home_dir, &storage_dir);
|
||||
|
||||
let sock_dir = tempfile::tempdir_in("/tmp").unwrap();
|
||||
|
|
@ -699,7 +698,10 @@ fn start_without_bind_uses_home_socket_instead_of_storage_socket() {
|
|||
let context = test_context!();
|
||||
let storage_root = isolated_storage_dir();
|
||||
let storage_dir = storage_root.path().join("storage");
|
||||
context.write_home(".fabro/settings.toml", "[server.auth]\nmethods = [\"dev-token\"]\n");
|
||||
context.write_home(
|
||||
".fabro/settings.toml",
|
||||
"[server.auth]\nmethods = [\"dev-token\"]\n",
|
||||
);
|
||||
provision_dev_token_auth(&context.home_dir, &storage_dir);
|
||||
let expected_socket = context.home_dir.join(".fabro").join("fabro.sock");
|
||||
let storage_socket = storage_dir.join("fabro.sock");
|
||||
|
|
@ -794,7 +796,10 @@ fn start_with_tcp_host_only_bind_resolves_to_host_and_port() {
|
|||
let context = test_context!();
|
||||
let storage_root = isolated_storage_dir();
|
||||
let storage_dir = storage_root.path().join("storage");
|
||||
context.write_home(".fabro/settings.toml", "[server.auth]\nmethods = [\"dev-token\"]\n");
|
||||
context.write_home(
|
||||
".fabro/settings.toml",
|
||||
"[server.auth]\nmethods = [\"dev-token\"]\n",
|
||||
);
|
||||
provision_dev_token_auth(&context.home_dir, &storage_dir);
|
||||
|
||||
let mut cmd = context.command();
|
||||
|
|
@ -846,7 +851,10 @@ fn start_with_tcp_host_only_bind_warns_and_falls_back_when_default_port_is_unava
|
|||
let context = test_context!();
|
||||
let storage_root = isolated_storage_dir();
|
||||
let storage_dir = storage_root.path().join("storage");
|
||||
context.write_home(".fabro/settings.toml", "[server.auth]\nmethods = [\"dev-token\"]\n");
|
||||
context.write_home(
|
||||
".fabro/settings.toml",
|
||||
"[server.auth]\nmethods = [\"dev-token\"]\n",
|
||||
);
|
||||
let occupied = match std::net::TcpListener::bind(("127.0.0.1", 32276)) {
|
||||
Ok(listener) => listener,
|
||||
Err(error) if error.kind() == std::io::ErrorKind::AddrInUse => {
|
||||
|
|
@ -954,7 +962,10 @@ fn default_test_context_server_keeps_object_store_off_disk() {
|
|||
#[test]
|
||||
fn isolated_server_switches_context_to_separate_daemon() {
|
||||
let mut context = test_context!();
|
||||
context.write_home(".fabro/settings.toml", "[server.auth]\nmethods = [\"dev-token\"]\n");
|
||||
context.write_home(
|
||||
".fabro/settings.toml",
|
||||
"[server.auth]\nmethods = [\"dev-token\"]\n",
|
||||
);
|
||||
let shared_storage_dir = context.storage_dir.clone();
|
||||
let shared_status = context
|
||||
.command()
|
||||
|
|
|
|||
|
|
@ -6,15 +6,17 @@ fn start_status_stop_lifecycle() {
|
|||
let storage_root = tempfile::tempdir_in("/tmp").unwrap();
|
||||
let storage_dir = storage_root.path().join("storage");
|
||||
std::fs::create_dir_all(&storage_dir).unwrap();
|
||||
context.write_home(".fabro/settings.toml", "[server.auth]\nmethods = [\"dev-token\"]\n");
|
||||
let server_env_path = fabro_config::Storage::new(&storage_dir).runtime_state().env_path();
|
||||
fabro_config::envfile::merge_env_file(
|
||||
&server_env_path,
|
||||
[(
|
||||
"FABRO_DEV_TOKEN",
|
||||
"fabro_dev_abababababababababababababababababababababababababababababababab",
|
||||
)],
|
||||
)
|
||||
context.write_home(
|
||||
".fabro/settings.toml",
|
||||
"[server.auth]\nmethods = [\"dev-token\"]\n",
|
||||
);
|
||||
let server_env_path = fabro_config::Storage::new(&storage_dir)
|
||||
.runtime_state()
|
||||
.env_path();
|
||||
fabro_config::envfile::merge_env_file(&server_env_path, [(
|
||||
"FABRO_DEV_TOKEN",
|
||||
"fabro_dev_abababababababababababababababababababababababababababababababab",
|
||||
)])
|
||||
.unwrap();
|
||||
fabro_util::dev_token::write_dev_token(
|
||||
&context.home_dir.join(".fabro").join("dev-token"),
|
||||
|
|
|
|||
|
|
@ -1,8 +1,8 @@
|
|||
use fabro_config::parse_settings_layer;
|
||||
use fabro_config::user::default_storage_dir;
|
||||
use fabro_types::settings::server::{
|
||||
GithubIntegrationStrategy, IpAllowEntry, ObjectStoreSettings, ServerListenSettings,
|
||||
ServerAuthMethod,
|
||||
GithubIntegrationStrategy, IpAllowEntry, ObjectStoreSettings, ServerAuthMethod,
|
||||
ServerListenSettings,
|
||||
};
|
||||
use fabro_types::settings::{InterpString, SettingsLayer};
|
||||
use fabro_util::Home;
|
||||
|
|
@ -486,7 +486,10 @@ root = "/srv/fabro"
|
|||
"#,
|
||||
);
|
||||
|
||||
assert_eq!(fabro_config::resolve_storage_root(&file).as_source(), "/srv/fabro");
|
||||
assert_eq!(
|
||||
fabro_config::resolve_storage_root(&file).as_source(),
|
||||
"/srv/fabro"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
|
@ -536,5 +539,7 @@ methods = ["dev-token", "github"]
|
|||
assert!(fabro_config::dev_token_auth_enabled(&dev_token_only));
|
||||
assert!(!fabro_config::dev_token_auth_enabled(&github_only));
|
||||
assert!(fabro_config::dev_token_auth_enabled(&both));
|
||||
assert!(!fabro_config::dev_token_auth_enabled(&SettingsLayer::default()));
|
||||
assert!(!fabro_config::dev_token_auth_enabled(
|
||||
&SettingsLayer::default()
|
||||
));
|
||||
}
|
||||
|
|
|
|||
|
|
@ -7837,7 +7837,8 @@ type = "http"
|
|||
#[test]
|
||||
fn worker_command_injects_dev_token_only_when_enabled() {
|
||||
let github_only = tempfile::tempdir().unwrap();
|
||||
let github_state = worker_command_test_state(github_only.path(), &["github"], Some(TEST_DEV_TOKEN));
|
||||
let github_state =
|
||||
worker_command_test_state(github_only.path(), &["github"], Some(TEST_DEV_TOKEN));
|
||||
let github_cmd = worker_command(
|
||||
github_state.as_ref(),
|
||||
RunId::new(),
|
||||
|
|
@ -7845,7 +7846,10 @@ type = "http"
|
|||
github_only.path(),
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(command_env_value(&github_cmd, "FABRO_DEV_TOKEN"), Some(None));
|
||||
assert_eq!(
|
||||
command_env_value(&github_cmd, "FABRO_DEV_TOKEN"),
|
||||
Some(None)
|
||||
);
|
||||
|
||||
let dev_token = tempfile::tempdir().unwrap();
|
||||
let dev_token_state =
|
||||
|
|
@ -7911,7 +7915,8 @@ allowed_usernames = ["octocat"]
|
|||
#[cfg(unix)]
|
||||
fn command_env_value(cmd: &Command, key: &str) -> Option<Option<String>> {
|
||||
cmd.as_std().get_envs().find_map(|(name, value)| {
|
||||
(name.to_str() == Some(key)).then(|| value.map(|value| value.to_string_lossy().into_owned()))
|
||||
(name.to_str() == Some(key))
|
||||
.then(|| value.map(|value| value.to_string_lossy().into_owned()))
|
||||
})
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -53,8 +53,8 @@ pub fn read_dev_token_file(path: &Path) -> Option<String> {
|
|||
}
|
||||
|
||||
pub fn read_dev_token_or_err(path: &Path) -> Result<String> {
|
||||
let contents = fs::read_to_string(path)
|
||||
.with_context(|| format!("read dev token {}", path.display()))?;
|
||||
let contents =
|
||||
fs::read_to_string(path).with_context(|| format!("read dev token {}", path.display()))?;
|
||||
let token = contents.trim().to_string();
|
||||
if validate_dev_token_format(&token) {
|
||||
Ok(token)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue