// node --test TheseusNavigator/dev/signin-sites.test.cjs "use strict"; const test = require("node:test"); const assert = require("node:assert/strict"); const fs = require("node:fs"); const os = require("node:os"); const path = require("node:path"); const { createSigninSites, keepOrigins, normHost } = require("../lib/signin-sites.cjs"); const fakeSafe = { isEncryptionAvailable: () => true, getSelectedStorageBackend: () => "gnome_libsecret", encryptString: (s) => Buffer.from("SEALED:" + s), decryptString: (b) => { const s = b.toString(); if (!s.startsWith("SEALED:")) throw new Error("bad seal"); return s.slice(7); }, }; const tmpFile = () => path.join(fs.mkdtempSync(path.join(os.tmpdir(), "sis-")), "signin-sites.json"); test("keepOrigins: www twin for names, none for IPs or one-label hosts", () => { assert.deepEqual(keepOrigins(["github.com"]).sort(), ["http://github.com", "http://www.github.com", "https://github.com", "https://www.github.com"]); assert.deepEqual(keepOrigins(["www.example.org"]).sort(), ["http://example.org", "http://www.example.org", "https://example.org", "https://www.example.org"]); assert.deepEqual(keepOrigins(["127.0.0.1"]).sort(), ["http://127.0.0.1", "https://127.0.0.1"]); assert.deepEqual(keepOrigins(["localhost"]).sort(), ["http://localhost", "https://localhost"]); assert.deepEqual(keepOrigins(["bad host", "", "a/b", "evil.com:80"]), []); }); test("normHost lower-cases and trims a trailing dot", () => { assert.equal(normHost("GitHub.COM."), "github.com"); assert.equal(normHost("x y"), ""); }); test("the list is sealed on disk and survives a reload", () => { const file = tmpFile(); const a = createSigninSites({ file, safeStorage: fakeSafe }); assert.equal(a.save(["b.com", "a.com", "a.com", "nope nope"]), true); assert.ok(!fs.readFileSync(file, "utf8").includes("a.com"), "hostnames must not be readable in the file"); const b = createSigninSites({ file, safeStorage: fakeSafe }); assert.deepEqual(b.load(), ["a.com", "b.com"]); }); test("without an OS keystore nothing is stored", () => { const file = tmpFile(); const noSafe = { isEncryptionAvailable: () => false }; const s = createSigninSites({ file, safeStorage: noSafe }); assert.equal(s.save(["a.com"]), false); assert.equal(fs.existsSync(file), false); assert.deepEqual(createSigninSites({ file, safeStorage: noSafe }).load(), []); });