Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 50 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
name: CI

# Consolidates the ci.yml that used to live in packages/xapi/.github. GitHub
# Actions only reads .github/workflows from the repository ROOT, so it never
# ran: typecheck, tests and builds were not validated by CI at all.

on:
push:
branches: [main]
pull_request:

concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true

jobs:
ci:
name: Typecheck, test & build (Node ${{ matrix.node-version }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
node-version: [20, 22]

steps:
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}
cache: npm

- run: npm ci

- name: Typecheck (library)
run: npm run typecheck --workspace=packages/xapi

- name: Test (library)
run: npm run test:run --workspace=packages/xapi

- name: Build (library)
run: npm run build --workspace=packages/xapi

- name: Lint (example)
run: npm run lint --workspace=example

# After the library build: the example resolves @studiolxd/xapi through
# the workspace, whose `exports` point at dist/.
- name: Build (example)
run: npm run build --workspace=example
32 changes: 0 additions & 32 deletions packages/xapi/.github/workflows/ci.yml

This file was deleted.

11 changes: 8 additions & 3 deletions packages/xapi/tests/server/jws.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -37,9 +37,14 @@ describe('verifySignedStatement', () => {

it('rejects a tampered signature', async () => {
const { jws, publicKey } = await signJws('RS256', {}, { hello: 'world' });
const lastChar = jws.slice(-1);
const swapped = lastChar === 'A' ? 'B' : 'A';
const tampered = jws.slice(0, -1) + swapped;
const [headerB64, payloadB64, signatureB64] = jws.split('.');
// Tamper with the FIRST signature character, which always carries six
// significant bits. The last character of a 256-byte (RS256) base64url
// signature carries only two significant bits plus discarded padding, so
// flipping it decodes to the same bytes ~25% of the time, leaving the
// signature intact and the assertion flaky.
const swapped = signatureB64[0] === 'A' ? 'B' : 'A';
const tampered = `${headerB64}.${payloadB64}.${swapped}${signatureB64.slice(1)}`;
const result = await verifySignedStatement(tampered, {
allowedAlgorithms: ['RS256'],
resolveKey: async () => publicKey,
Expand Down
Loading