Parent directory

anon-access-env.txtar

1826 bytes
 1# vi: set ft=conf
 2
 3# Proves the zero-touch dev/local bootstrap: SOFT_SERVE_ANON_ACCESS and
 4# SOFT_SERVE_ALLOW_KEYLESS grant a fully anonymous, keyless connection
 5# admin-level access from the moment the server starts -- no `settings`
 6# command, and no admin SSH key at all. This is the whole point of the
 7# feature: standing up a throwaway, fully open server from zero for local
 8# dev tooling, scriptably.
 9
10# Override away the admin key the test harness normally provisions, and set
11# the two bootstrap overrides under test.
12env SOFT_SERVE_INITIAL_ADMIN_KEYS=
13env SOFT_SERVE_ANON_ACCESS=admin-access
14env SOFT_SERVE_ALLOW_KEYLESS=true
15
16# start soft serve
17exec soft serve &
18ensureserverrunning SSH_PORT
19ensureserverrunning HTTP_PORT
20
21# --- SSH, with zero credentials: no key offered at all ---
22# ksoft authenticates via keyboard-interactive with no public key at all --
23# the exact "no key at all" path that allow-keyless gates. This is distinct
24# from offering an unregistered key, which anon-access alone already
25# governs regardless of allow-keyless -- see anon-access.txtar.
26ksoft repo create keyless-repo
27stderr 'Created repository keyless-repo'
28
29# --- HTTP, with zero credentials: no Authorization header at all ---
30mkdir httprepo
31git -c init.defaultBranch=main -C httprepo init
32mkfile ./httprepo/README.md '# hello'
33git -C httprepo remote add origin http://localhost:$HTTP_PORT/httprepo
34git -C httprepo add -A
35git -C httprepo commit -m 'first'
36git -C httprepo push origin HEAD
37
38git clone http://localhost:$HTTP_PORT/httprepo httprepo_clone
39cmp httprepo_clone/README.md httprepo/README.md
40
41# both repos -- the one created via keyless SSH and the one auto-created by
42# a keyless HTTP push -- are visible with zero credentials.
43ksoft repo list
44stdout 'keyless-repo'
45stdout 'httprepo'
46
47# stop the server
48[windows] stopserver