vault/api/tokenhelper/helper_internal_test.go
Vault Automation 0c6c13dd38
license: update headers to IBM Corp. (#10229) (#10233)
* license: update headers to IBM Corp.
* `make proto`
* update offset because source file changed

Signed-off-by: Ryan Cragun <me@ryan.ec>
Co-authored-by: Ryan Cragun <me@ryan.ec>
2025-10-21 15:20:20 -06:00

65 lines
1.2 KiB
Go

// Copyright IBM Corp. 2016, 2025
// SPDX-License-Identifier: MPL-2.0
package tokenhelper
import (
"os"
"path/filepath"
"testing"
)
// TestCommand re-uses the existing Test function to ensure proper behavior of
// the internal token helper
func TestCommand(t *testing.T) {
helper, err := NewInternalTokenHelper()
if err != nil {
t.Fatal(err)
}
test(t, helper)
}
func TestInternalHelperFilePerms(t *testing.T) {
tmpDir, err := os.MkdirTemp("", t.Name())
if err != nil {
t.Fatal(err)
}
defer os.RemoveAll(tmpDir)
helper, err := NewInternalTokenHelper()
if err != nil {
t.Fatal(err)
}
helper.homeDir = tmpDir
tmpFile := filepath.Join(tmpDir, ".vault-token")
f, err := os.Create(tmpFile)
if err != nil {
t.Fatal(err)
}
defer f.Close()
fi, err := os.Stat(tmpFile)
if err != nil {
t.Fatal(err)
}
if fi.Mode().Perm()&0o04 != 0o04 {
t.Fatalf("expected world-readable/writable permission bits, got: %o", fi.Mode().Perm())
}
err = helper.Store("bogus_token")
if err != nil {
t.Fatal(err)
}
fi, err = os.Stat(tmpFile)
if err != nil {
t.Fatal(err)
}
if fi.Mode().Perm()&0o04 != 0 {
t.Fatalf("expected no world-readable/writable permission bits, got: %o", fi.Mode().Perm())
}
}