Files
netris-nestri/apps/api/test/presign.test.ts
T
Wanjohi 065af689b3 feat(api): serve the host installer and its downloads
GET /install.sh serves a POSIX script, embedded in the API at build time
so the script and the routes that redeem its token ship together. It
checks the platform, asks where box images should live, downloads the
host agent at a pinned version, verifies it against SHA256SUMS, installs
it for the calling user and hands over with the token in the environment
rather than argv.

GET /install/:component/:version/:asset redirects to a one-minute signed
URL on a private S3-compatible bucket, so every download passes through a
route that can be logged or switched off. The SigV4 signer is written
against Web Crypto and checked against AWS's published example.
2026-09-28 09:12:23 +03:00

45 lines
1.3 KiB
TypeScript

import { describe, expect, test } from 'bun:test';
import { presignGet } from '../app/utils/presign';
describe('presignGet', () => {
// The example in AWS's SigV4 query-string documentation, which publishes the
// signature it must produce. If this passes, every other signature is the
// same arithmetic with different inputs.
test('matches the published AWS example', async () => {
const url = await presignGet(
{
endpoint: 'https://s3.amazonaws.com',
bucket: 'examplebucket',
region: 'us-east-1',
accessKeyId: 'AKIAIOSFODNN7EXAMPLE',
secretAccessKey: 'wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY',
virtualHost: true
},
'test.txt',
86400,
new Date('2013-05-24T00:00:00Z')
);
expect(url).toContain('https://examplebucket.s3.amazonaws.com/test.txt?');
expect(url).toEndWith(
'X-Amz-Signature=aeeed9bbccd4d02ee5c0109b86d86835f995330da4c265957d157751f604d404'
);
});
test('path style puts the bucket in the path', async () => {
const url = await presignGet(
{
endpoint: 'https://objects.example.net',
bucket: 'releases',
region: 'europe-1',
accessKeyId: 'k',
secretAccessKey: 's'
},
'host/0.1.0/SHA256SUMS',
60
);
expect(url).toStartWith('https://objects.example.net/releases/host/0.1.0/SHA256SUMS?');
expect(url).toContain('X-Amz-Expires=60');
});
});