88 LEGACY_POSTGRES_PASSWORD ,
99 postgresUser ,
1010} from './compose-database'
11+ import { SetupError } from './errors'
1112
1213const REPO_ROOT = path . resolve ( path . dirname ( fileURLToPath ( import . meta. url ) ) , '../../..' )
1314const COMPOSE_FILES = [
@@ -34,43 +35,77 @@ afterEach(() => {
3435} )
3536
3637describe ( 'choosePostgresPassword' , ( ) => {
38+ const noShell = { }
39+
3740 it ( 'leaves a password already in .env alone without looking for a volume' , ( ) => {
3841 const hasDatabaseVolume = vi . fn ( ( ) => true )
3942 expect (
40- choosePostgresPassword ( 'in-env-file' , 'sim-abc' , {
41- shellValue : 'in-shell' ,
42- hasDatabaseVolume,
43- } )
43+ choosePostgresPassword ( 'in-env-file' , 'sim-abc' , { shell : noShell , hasDatabaseVolume } )
4444 ) . toBeNull ( )
4545 expect ( hasDatabaseVolume ) . not . toHaveBeenCalled ( )
4646 } )
4747
48- it ( 'persists a shell-exported password, which is what Compose is using' , ( ) => {
49- const hasDatabaseVolume = vi . fn ( ( ) => true )
50- expect (
51- choosePostgresPassword ( undefined , 'sim-abc' , { shellValue : 'in-shell' , hasDatabaseVolume } )
52- ) . toEqual ( { value : 'in-shell' , source : 'environment' } )
53- expect ( hasDatabaseVolume ) . not . toHaveBeenCalled ( )
54- } )
55-
5648 it ( 'generates a password for a project with no database volume yet' , ( ) => {
5749 const hasDatabaseVolume = vi . fn ( ( ) => false )
58- const choice = choosePostgresPassword ( '' , 'sim-abc' , { shellValue : '' , hasDatabaseVolume } )
50+ const choice = choosePostgresPassword ( undefined , 'sim-abc' , {
51+ shell : noShell ,
52+ hasDatabaseVolume,
53+ } )
5954 expect ( hasDatabaseVolume ) . toHaveBeenCalledWith ( 'sim-abc' )
6055 expect ( choice ?. source ) . toBe ( 'generated' )
6156 expect ( choice ?. value ) . toMatch ( / ^ [ 0 - 9 a - f ] { 64 } $ / )
6257 } )
6358
6459 it ( 'keeps the legacy password for a volume created before it was required' , ( ) => {
60+ expect (
61+ choosePostgresPassword ( '' , 'sim-abc' , { shell : noShell , hasDatabaseVolume : ( ) => true } )
62+ ) . toEqual ( { value : LEGACY_POSTGRES_PASSWORD , source : 'legacy' } )
63+ } )
64+
65+ it ( 'persists a shell-only password, which is what Compose is using' , ( ) => {
66+ const hasDatabaseVolume = vi . fn ( ( ) => true )
6567 expect (
6668 choosePostgresPassword ( undefined , 'sim-abc' , {
67- shellValue : '' ,
68- hasDatabaseVolume : ( ) => true ,
69+ shell : { POSTGRES_PASSWORD : 'in-shell' } ,
70+ hasDatabaseVolume,
6971 } )
70- ) . toEqual ( { value : LEGACY_POSTGRES_PASSWORD , source : 'legacy' } )
72+ ) . toEqual ( { value : 'in-shell' , source : 'environment' } )
73+ expect ( hasDatabaseVolume ) . not . toHaveBeenCalled ( )
74+ } )
75+
76+ it ( 'accepts a shell password that matches .env' , ( ) => {
77+ expect (
78+ choosePostgresPassword ( 'same' , 'sim-abc' , { shell : { POSTGRES_PASSWORD : 'same' } } )
79+ ) . toBeNull ( )
7180 } )
7281
73- it ( 'reads the shell environment by default' , ( ) => {
82+ it ( 'refuses a shell password that differs from .env' , ( ) => {
83+ expect ( ( ) =>
84+ choosePostgresPassword ( 'in-env-file' , 'sim-abc' , { shell : { POSTGRES_PASSWORD : 'other' } } )
85+ ) . toThrow ( SetupError )
86+ } )
87+
88+ it ( 'refuses an empty shell export, which Compose would use over .env' , ( ) => {
89+ for ( const envFileValue of [ undefined , 'in-env-file' ] ) {
90+ expect ( ( ) =>
91+ choosePostgresPassword ( envFileValue , 'sim-abc' , { shell : { POSTGRES_PASSWORD : '' } } )
92+ ) . toThrow ( / e x p o r t e d b u t e m p t y / )
93+ }
94+ } )
95+
96+ it . each ( [ 'pa ss' , 'pass#word' , 'pa"ss' , "pa'ss" , 'pa\\ss' , 'pa$ss' ] ) (
97+ 'refuses to persist %s, which .env cannot store verbatim' ,
98+ ( value ) => {
99+ expect ( ( ) =>
100+ choosePostgresPassword ( undefined , 'sim-abc' , {
101+ shell : { POSTGRES_PASSWORD : value } ,
102+ hasDatabaseVolume : ( ) => false ,
103+ } )
104+ ) . toThrow ( / c a n n o t s t o r e v e r b a t i m / )
105+ }
106+ )
107+
108+ it ( 'reads the process environment by default' , ( ) => {
74109 vi . stubEnv ( 'POSTGRES_PASSWORD' , 'from-process' )
75110 expect ( choosePostgresPassword ( undefined , 'sim-abc' , { hasDatabaseVolume : ( ) => true } ) ) . toEqual (
76111 { value : 'from-process' , source : 'environment' }
0 commit comments