Skip to content

Commit 9736a2b

Browse files
authored
build(deps): bump basic-auth from 2.0.1 to 3.0.0 (#690)
1 parent edee9d5 commit 9736a2b

4 files changed

Lines changed: 56 additions & 19 deletions

File tree

‎lib/auth-middleware.js‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,12 +5,12 @@
55
* in the follow format: "username:password"
66
*/
77

8-
import auth from 'basic-auth'
8+
import { parse } from 'basic-auth'
99

1010
const [username, password] = (process.env.LOGIN_CREDENTIALS || '').split(':')
1111

1212
export default function authMiddleware (req, res, next) {
13-
const user = auth(req)
13+
const user = parse(req.headers.authorization || '')
1414

1515
if (user === undefined || user.name !== username || user.pass !== password) {
1616
res.statusCode = 401

‎package-lock.json‎

Lines changed: 6 additions & 15 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,14 +9,14 @@
99
"test:watch": "nodemon -q -x 'npm test'"
1010
},
1111
"engines": {
12-
"node": ">= 20.11.0"
12+
"node": ">= 22.0.0"
1313
},
1414
"private": true,
1515
"license": "MIT",
1616
"dependencies": {
1717
"@octokit/rest": "^22.0.1",
1818
"aigle": "^1.14.1",
19-
"basic-auth": "^2.0.1",
19+
"basic-auth": "^3.0.0",
2020
"body-parser": "^2.3.0",
2121
"bunyan": "^1.8.1",
2222
"codeowners-utils": "^1.0.2",

‎test/unit/auth-middleware.test.js‎

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
import assert from 'node:assert/strict'
2+
import test from 'node:test'
3+
4+
process.env.LOGIN_CREDENTIALS = 'admin:secret'
5+
const { default: authMiddleware } = await import('../../lib/auth-middleware.js')
6+
7+
function request (authorization) {
8+
return { headers: { authorization } }
9+
}
10+
11+
function response () {
12+
return {
13+
headers: {},
14+
setHeader (name, value) {
15+
this.headers[name] = value
16+
},
17+
end (body) {
18+
this.body = body
19+
}
20+
}
21+
}
22+
23+
test('accepts the configured credentials', () => {
24+
const req = request('Basic ' + Buffer.from('admin:secret').toString('base64'))
25+
const res = response()
26+
let nextCalled = false
27+
28+
authMiddleware(req, res, () => { nextCalled = true })
29+
30+
assert.equal(nextCalled, true)
31+
assert.equal(res.statusCode, undefined)
32+
})
33+
34+
test('rejects missing or incorrect credentials', () => {
35+
for (const authorization of [undefined, 'Basic invalid', 'Bearer token']) {
36+
const res = response()
37+
let nextCalled = false
38+
39+
authMiddleware(request(authorization), res, () => { nextCalled = true })
40+
41+
assert.equal(nextCalled, false)
42+
assert.equal(res.statusCode, 401)
43+
assert.equal(res.headers['WWW-Authenticate'], 'Basic realm="nodejs-github-bot"')
44+
assert.equal(res.body, 'Unauthorized')
45+
}
46+
})

0 commit comments

Comments
 (0)