Skip to content

test: keep verdaccio users alive across createTestDir() calls - #40219

Open
robobun wants to merge 1 commit into
mainfrom
farm/dd1a17e9/verdaccio-createtestdir-keeps-users
Open

robobun wants to merge 1 commit into
mainfrom
farm/dd1a17e9/verdaccio-createtestdir-keeps-users

Conversation

@robobun

@robobun robobun commented Aug 23, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Fix

  • createTestDir() no longer touches htpasswd or the user map. start() still begins each file with a fresh htpasswd (and now an empty user map), and stop() still removes the file.
  • Correct because the reset was not needed: no test file creates the same verdaccio user twice, so the duplicate guard in generateUser() never fires. Users now accumulate in htpasswd for the life of one registry process, which is one test file.
  • Verified: bun bd test test/cli/install/npmrc.test.ts test/cli/install/config-precedence.test.ts (91 pass) and bun bd test test/cli/install/bun-install-registry.test.ts (246 pass, 5 skip). These are the files that create verdaccio users. test: run bun-publish.test.ts concurrently and assert the exact requests and output #40198 is rebased on this change.

Background

  • VerdaccioRegistry forks one verdaccio process per test file. Its users live in test/cli/install/registry/htpasswd. generateUser() creates a user through the registry's API and returns a token. authBunfig() wraps that token in a bunfig.toml.
  • Verdaccio's default API tokens are legacy AES tokens. The registry decrypts the token on every request and verifies the user against htpasswd. A missing file makes every request anonymous, and a publish with a token then fails with 401.

no test proof · iteration 0 · no src or test change; test-proof not applicable

VerdaccioRegistry.createTestDir() deleted the htpasswd file and forgot the users the file had
generated. Verdaccio checks every authenticated request against that file, so a call from
one test logged out every other test that was running at the same time. The registry
already starts with a fresh htpasswd in start() and removes it in stop(), and no test file
creates the same user twice, so the per-call reset is not needed.
@coderabbitai

coderabbitai Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 64f5021d-cac4-4693-bdbf-b3f96f822e6a

📥 Commits

Reviewing files that changed from the base of the PR and between 3e347b3 and 3f3861d.

📒 Files selected for processing (1)
  • test/harness.ts

Included review availability: Your plan provides up to 5 included reviews per hour; 0 remain after this review.


Walkthrough

The test harness now clears tracked registry users during VerdaccioRegistry.start() after removing the authentication file. createTestDir() only handles fixture cleanup and test directory configuration.

Changes

Registry test harness reset

Layer / File(s) Summary
Reset users during registry startup
test/harness.ts
VerdaccioRegistry.start() clears the in-memory users map after deleting htpasswd. createTestDir() no longer performs authentication cleanup or user resets. It continues private-package cleanup and test configuration setup.

Suggested reviewers: jarred-sumner, dylan-conway, cirospaciari

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the main change: preserving Verdaccio users across createTestDir() calls.
Description check ✅ Passed The description explains the problem, fix, background, and verification steps, covering the required template information.

Comment @coderabbitai help to get the list of available commands.

@robobun

robobun commented Aug 23, 2026

Copy link
Copy Markdown
Collaborator Author

Status: ready for review. This is the prerequisite for #40198, which is rebased on it.

Verified with the debug build: bun bd test test/cli/install/npmrc.test.ts test/cli/install/config-precedence.test.ts (91 pass) and bun bd test test/cli/install/bun-install-registry.test.ts (246 pass, 5 skip). Those are the test files that create verdaccio users.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — test-harness-only change that stops createTestDir() from wiping the shared htpasswd mid-file.

What was reviewed:

  • Verified every generateUser/authBunfig caller (bun-publish, bun-install-registry, npmrc, config-precedence) uses a unique username within its file, so the duplicate guard in generateUser() still cannot fire now that this.users accumulates.
  • start() still deletes htpasswd and now also clears this.users, so per-file state remains fresh; stop() unchanged.
  • bun-install-registry.test.ts's own beforeEach rm targets import.meta.dir/htpasswd (a different path), but that file only creates one user (whoami) so it is unaffected either way.
Extended reasoning...

Overview

This PR moves two lines inside VerdaccioRegistry in test/harness.ts: the htpasswd delete and this.users = {} reset move out of createTestDir() (called per-test) and the map reset is added to start() (called once per file). Net effect: authenticated users created earlier in a test file are no longer invalidated when a later test in the same file calls createTestDir(). No production code is touched.

Security risks

None. This is test infrastructure controlling a local verdaccio registry's user file. No auth, crypto, or runtime code paths are involved.

Level of scrutiny

Low. Three-line net change to a test helper, with clear rationale (unblocking concurrent auth-bearing verdaccio tests). The only correctness question is whether any test file relied on the per-test reset — i.e., whether any file creates the same username twice.

Other factors

I grepped every generateUser/authBunfig call site. All usernames are unique within each file (bun-publish.test.ts, bun-install-registry.test.ts, npmrc.test.ts, config-precedence.test.ts), so the if (this.users[username]) throw guard cannot newly fire. The pre-existing cross-file htpasswd sharing (which config-precedence.test.ts already works around with its own config dir) is untouched by this change — start()/stop() still delete the file. The PR description's claim about bun-install-registry.test.ts's own beforeEach deleting htpasswd is slightly off (it targets test/cli/install/htpasswd, not test/cli/install/registry/htpasswd), but that file only creates a single whoami user so the reset was never load-bearing there anyway. The author reports the affected test files pass; the change is strictly less destructive than before.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant