Files
windmill/cli/test/local_encryption_unit.test.ts
Ruben Fiszel a2cefdf0a2 refactor(cli): migrate CLI from Deno to Bun/Node.js (#8041)
* fix: only enable EE features in test backend when license key is available

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: skip EE tests without license key and exclude test-skills from test discovery

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: unskip passing tests and add duplicate (remote, workspaceId) check in addWorkspace

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(cli): migrate from Deno APIs to Node.js/Bun-compatible APIs

Replace Deno-specific APIs with Node.js equivalents across the entire CLI
codebase to enable running on Node.js/Bun. Switch build system from dnt
to bun, update imports from jsr:/npm: prefixed to bare specifiers, and
add package.json/tsconfig.json for the Node.js ecosystem.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* all

* test(cli): expand test coverage with new integration and unit tests

Add standalone_commands.test.ts covering folder list, schedule list,
resource-type list/push/update, script show/run/bootstrap, and user
commands. Add unit tests for filePathExtensionFromContentType and
removeExtensionToPath. Add git_unit, local_encryption_unit,
resource_folders_unit, and settings_unit test files. Fix schedule
cron expressions (6-field format), add includeSchedules flag, improve
test setup with pre-build and auto-cleanup, and support TEST_CLI_RUNTIME=node.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): replace Deno.readFile with node:fs in WASM loaders and add schema parsing tests

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* refactor(cli): switch WASM parsers from local files to npm packages

Use published windmill-parser-wasm-* npm packages instead of local
wasm/ files. A loadParser() helper uses createRequire to resolve the
.wasm binary from node_modules and passes it to init() via
readFileSync, avoiding fetch() and Deno.readFile() patches.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* test(cli): add coverage for --locks-required lint feature

Add 15 tests covering the lock-checking functionality merged from main:
- checkMissingLocks: standalone scripts (python, bun, bash), inline
  lock file resolution (valid, empty, missing), flow inline rawscripts
  (with/without locks, nested forloopflow), app inline scripts, raw
  apps without backend folder
- runLint --locks-required integration: reports issues when locks
  missing, skips checks when flag absent, passes when locks exist

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* ci(cli): replace Deno with Bun in CI workflows

- cli-tests.yml: remove Deno setup, use `bun test` instead of
  `deno test`, add `bun install` step for dependency installation
- npm_on_release.yml: replace Deno setup with Bun setup for CLI
  publishing
- build.sh: add `bun install` before building so CI has dependencies

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): pre-start backend in test preload and remove Deno test leftovers

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): normalize path separators for Windows compatibility

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* more tests + windows

* ci(cli): use Blacksmith runner for Windows tests

Switch test-windows job from windows-latest to blacksmith-16vcpu-windows-2025
for faster CI execution.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): fix Windows path separator expectations in unit tests

buildMetadataPath and extractResourceName normalize to forward slashes
internally, so tests should not expect platform-specific separators in
their output.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): fix Windows CI test failures for dev_server and script_run

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): set BUN_PATH and NODE_BIN_PATH for backend worker on Windows

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* ci(cli): add SSH debug step on Windows test failure

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): use native path separators for ignore check in dev mode on Windows

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-21 21:19:04 +00:00

95 lines
3.2 KiB
TypeScript

/**
* Unit tests for local_encryption.ts encrypt/decrypt functions.
* Tests round-trip encryption, different key lengths, and error handling.
*/
import { expect, test, describe } from "bun:test";
import { encrypt, decrypt } from "../src/utils/local_encryption.ts";
// =============================================================================
// encrypt / decrypt round-trip
// =============================================================================
describe("encrypt and decrypt", () => {
test("round-trip with a simple message", async () => {
const key = "my-secret-key";
const message = "Hello, World!";
const encrypted = await encrypt(message, key);
const decrypted = await decrypt(encrypted, key);
expect(decrypted).toBe(message);
});
test("round-trip with empty string", async () => {
const key = "key";
const encrypted = await encrypt("", key);
const decrypted = await decrypt(encrypted, key);
expect(decrypted).toBe("");
});
test("round-trip with long message", async () => {
const key = "test-key-123";
const message = "A".repeat(10000);
const encrypted = await encrypt(message, key);
const decrypted = await decrypt(encrypted, key);
expect(decrypted).toBe(message);
});
test("round-trip with unicode characters", async () => {
const key = "unicode-key";
const message = "Hello 🌍 世界 مرحبا";
const encrypted = await encrypt(message, key);
const decrypted = await decrypt(encrypted, key);
expect(decrypted).toBe(message);
});
test("round-trip with very short key", async () => {
const key = "k";
const message = "short key test";
const encrypted = await encrypt(message, key);
const decrypted = await decrypt(encrypted, key);
expect(decrypted).toBe(message);
});
test("round-trip with very long key", async () => {
const key = "x".repeat(1000);
const message = "long key test";
const encrypted = await encrypt(message, key);
const decrypted = await decrypt(encrypted, key);
expect(decrypted).toBe(message);
});
test("encrypted output is base64", async () => {
const encrypted = await encrypt("test", "key");
// base64 characters: A-Z, a-z, 0-9, +, /, =
expect(encrypted).toMatch(/^[A-Za-z0-9+/=]+$/);
});
test("same message encrypted twice produces different ciphertexts (random IV)", async () => {
const key = "determinism-test";
const message = "same input";
const enc1 = await encrypt(message, key);
const enc2 = await encrypt(message, key);
expect(enc1).not.toBe(enc2);
});
test("decrypting with wrong key throws", async () => {
const encrypted = await encrypt("secret", "correct-key");
await expect(decrypt(encrypted, "wrong-key")).rejects.toThrow();
});
test("decrypting corrupted ciphertext throws", async () => {
await expect(decrypt("not-valid-ciphertext-at-all!!", "key")).rejects.toThrow();
});
test("round-trip with JSON content", async () => {
const key = "json-key";
const message = JSON.stringify({ license_key: "abc-123", secret: true });
const encrypted = await encrypt(message, key);
const decrypted = await decrypt(encrypted, key);
expect(JSON.parse(decrypted)).toEqual({
license_key: "abc-123",
secret: true,
});
});
});