fix: avoid child paths in repositories (#111573)

* fix: avoid child paths in repositories

* add another unit test; fix linter

* Update pkg/registry/apis/provisioning/register.go

* skip itself

* fix: failing tests

---------

Co-authored-by: Stephanie Hingtgen <stephanie.hingtgen@grafana.com>
This commit is contained in:
Costa Alexoglou
2025-09-24 21:35:06 +00:00
committed by GitHub
co-authored by Stephanie Hingtgen
parent 020b87e91b
commit 0c0554da5e
3 changed files with 187 additions and 11 deletions
+69 -1
View File
@@ -3,12 +3,14 @@ package provisioning
import (
"context"
"encoding/json"
"errors"
"fmt"
"net/http"
"strings"
"testing"
"time"
provisioningAPIServer "github.com/grafana/grafana/pkg/registry/apis/provisioning"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
apierrors "k8s.io/apimachinery/pkg/api/errors"
@@ -213,6 +215,71 @@ func TestIntegrationProvisioning_RepositoryValidation(t *testing.T) {
}
})
}
// Test Git repository path validation - ensure child paths are rejected
t.Run("Git repository path validation", func(t *testing.T) {
baseURL := "https://github.com/grafana/test-repo-path-validation"
pathTests := []struct {
name string
path string
expectError error
}{
{
name: "first repo with path 'demo/nested' should succeed",
path: "demo/nested",
expectError: nil,
},
{
name: "second repo with child path 'demo/nested/again' should fail",
path: "demo/nested/again",
expectError: provisioningAPIServer.ErrRepositoryParentFolderConflict,
},
{
name: "third repo with parent path 'demo' should fail",
path: "demo",
expectError: provisioningAPIServer.ErrRepositoryParentFolderConflict,
},
{
name: "fourth repo with nested child path 'demo/nested/nested-second' should fail",
path: "demo/nested/again/two",
expectError: provisioningAPIServer.ErrRepositoryParentFolderConflict,
},
{
name: "fifth repo with duplicate path 'demo/nested' should fail",
path: "demo/nested",
expectError: provisioningAPIServer.ErrRepositoryDuplicatePath,
},
}
for i, test := range pathTests {
t.Run(test.name, func(t *testing.T) {
repoName := fmt.Sprintf("git-path-test-%d", i+1)
gitRepo := helper.RenderObject(t, "testdata/github-readonly.json.tmpl", map[string]any{
"Name": repoName,
"URL": baseURL,
"Path": test.path,
"SyncEnabled": false, // Disable sync to avoid external dependencies
"SyncTarget": "folder",
})
_, err := helper.Repositories.Resource.Create(ctx, gitRepo, metav1.CreateOptions{FieldValidation: "Strict"})
if test.expectError != nil {
require.Error(t, err, "Expected error for repository with path: %s", test.path)
require.ErrorContains(t, err, test.expectError.Error(), "Error should contain expected message for path: %s", test.path)
var statusError *apierrors.StatusError
if errors.As(err, &statusError) {
require.Equal(t, metav1.StatusReasonInvalid, statusError.ErrStatus.Reason, "Should be a validation error")
require.Equal(t, http.StatusUnprocessableEntity, int(statusError.ErrStatus.Code), "Should return 422 status code")
}
} else {
require.NoError(t, err, "Expected success for repository with path: %s", test.path)
}
})
}
})
}
func TestIntegrationProvisioning_FailInvalidSchema(t *testing.T) {
@@ -364,7 +431,8 @@ func TestIntegrationProvisioning_CreatingGitHubRepository(t *testing.T) {
"Name": test.name,
"URL": test.input,
"SyncTarget": "folder",
"SyncEnabled": false, // Disable sync since we're just testing URL cleanup
"SyncEnabled": false, // Disable sync since we're just testing URL cleanup,
"Path": fmt.Sprintf("grafana-%s/", test.name),
})
_, err := helper.Repositories.Resource.Create(ctx, input, metav1.CreateOptions{})