package allowlist_test import ( "context" "testing" "git.d-ma.be/mathias/gitea-mcp/internal/allowlist" "git.d-ma.be/mathias/gitea-mcp/internal/gitea" "github.com/stretchr/testify/assert" ) func TestAllowlistCheck(t *testing.T) { a := allowlist.New([]string{"mathias", "acme"}) ctx := context.Background() assert.NoError(t, a.Check(ctx, "mathias")) assert.NoError(t, a.Check(ctx, "acme")) assert.Error(t, a.Check(ctx, "evil")) assert.Error(t, a.Check(ctx, "")) } // A caller authenticated with their own Gitea PAT (pass-through, gitea-mcp#59) // is gated by Gitea's own permission model, not the MCP's static owner list — // otherwise a legitimate second user could never touch their own repos. func TestAllowlistCheckTrustsPassthroughAuthenticatedCaller(t *testing.T) { a := allowlist.New([]string{"mathias"}) ctx := gitea.WithToken(context.Background(), "someone-elses-pat") assert.NoError(t, a.Check(ctx, "someone-else")) } // Empty owner is a structural input error, not an authz question — still // rejected even on the pass-through path. func TestAllowlistCheckStillRejectsEmptyOwnerOnPassthrough(t *testing.T) { a := allowlist.New([]string{"mathias"}) ctx := gitea.WithToken(context.Background(), "someone-elses-pat") assert.Error(t, a.Check(ctx, "")) }