Files
gita/tests/integration/api_repo_hook_test.go
admin e4afba3416
giteabot backport / giteabot (push) Canceled after 0s
giteabot / giteabot (push) Canceled after 0s
release-nightly / nightly-binary (push) Canceled after 0s
release-nightly / nightly-container (push) Canceled after 0s
cache-seeder / gobuild (push) Canceled after 0s
cache-seeder / lint (bindata, lint-backend) (push) Canceled after 0s
release-nightly-snapcraft / build-and-publish (push) Canceled after 0s
chore: initialize Gitea v1.27.2 fork
Includes direct password setup links in registration emails.

Assisted-by: Codex:GPT-5
2026-08-15 22:56:18 +08:00

99 lines
3.6 KiB
Go

// Copyright 2022 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package integration
import (
"fmt"
"net/http"
"testing"
auth_model "gitea.dev/models/auth"
repo_model "gitea.dev/models/repo"
"gitea.dev/models/unittest"
user_model "gitea.dev/models/user"
api "gitea.dev/modules/structs"
"gitea.dev/tests"
"github.com/stretchr/testify/assert"
)
func TestAPICreateHook(t *testing.T) {
defer tests.PrepareTestEnv(t)()
repo := unittest.AssertExistsAndLoadBean(t, &repo_model.Repository{ID: 37})
owner := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: repo.OwnerID})
// user1 is an admin user
session := loginUser(t, "user1")
token := getTokenForLoggedInUser(t, session, auth_model.AccessTokenScopeWriteRepository)
req := NewRequestWithJSON(t, "POST", fmt.Sprintf("/api/v1/repos/%s/%s/%s", owner.Name, repo.Name, "hooks"), api.CreateHookOption{
Type: "gitea",
Config: api.CreateHookOptionConfig{
"content_type": "json",
"url": "http://example.com/",
},
AuthorizationHeader: "Bearer s3cr3t",
Name: " CI notifications ",
}).AddTokenAuth(token)
resp := MakeRequest(t, req, http.StatusCreated)
apiHook := DecodeJSON(t, resp, &api.Hook{})
assert.Equal(t, "http://example.com/", apiHook.Config["url"])
// the stored authorization header is a secret and must never be returned by the API
assert.Empty(t, apiHook.AuthorizationHeader)
assert.Equal(t, "CI notifications", apiHook.Name)
// a read-scoped token must not be able to read back the authorization header
readToken := getTokenForLoggedInUser(t, session, auth_model.AccessTokenScopeReadRepository)
getReq := NewRequest(t, "GET", fmt.Sprintf("/api/v1/repos/%s/%s/hooks/%d", owner.Name, repo.Name, apiHook.ID)).
AddTokenAuth(readToken)
getResp := MakeRequest(t, getReq, http.StatusOK)
assert.NotContains(t, getResp.Body.String(), "s3cr3t")
newName := "Deploy hook"
patchReq := NewRequestWithJSON(t, "PATCH", fmt.Sprintf("/api/v1/repos/%s/%s/hooks/%d", owner.Name, repo.Name, apiHook.ID), api.EditHookOption{
Name: &newName,
}).AddTokenAuth(token)
patchResp := MakeRequest(t, patchReq, http.StatusOK)
patched := DecodeJSON(t, patchResp, &api.Hook{})
assert.Equal(t, newName, patched.Name)
hooksURL := fmt.Sprintf("/api/v1/repos/%s/%s/hooks", owner.Name, repo.Name)
// Create with Name field omitted: Name should be ""
req2 := NewRequestWithJSON(t, "POST", hooksURL, api.CreateHookOption{
Type: "gitea",
Config: api.CreateHookOptionConfig{
"content_type": "json",
"url": "http://example.com/",
},
}).AddTokenAuth(token)
resp2 := MakeRequest(t, req2, http.StatusCreated)
created := DecodeJSON(t, resp2, &api.Hook{})
assert.Empty(t, created.Name)
hookURL := fmt.Sprintf("/api/v1/repos/%s/%s/hooks/%d", owner.Name, repo.Name, created.ID)
// PATCH with Name set: existing Name must be updated
setName := "original"
setReq := NewRequestWithJSON(t, "PATCH", hookURL, api.EditHookOption{
Name: &setName,
}).AddTokenAuth(token)
MakeRequest(t, setReq, http.StatusOK)
// PATCH without Name field: name must remain "original"
patchReq2 := NewRequestWithJSON(t, "PATCH", hookURL, api.EditHookOption{}).AddTokenAuth(token)
patchResp2 := MakeRequest(t, patchReq2, http.StatusOK)
notCleared := DecodeJSON(t, patchResp2, &api.Hook{})
assert.Equal(t, "original", notCleared.Name)
// PATCH with Name: "" explicitly: Name should be cleared to ""
clearReq := NewRequestWithJSON(t, "PATCH", hookURL, api.EditHookOption{
Name: new(""),
}).AddTokenAuth(token)
clearResp := MakeRequest(t, clearReq, http.StatusOK)
cleared := DecodeJSON(t, clearResp, &api.Hook{})
assert.Empty(t, cleared.Name)
}