mapbox / mapbox/node-pre-gyp

Chaining publish and unpublish Commands Changes Their Default Behavior

Open
#653 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
1.2k
Forks
271
Avg merge
23h 40m
Merged PRs (30d)
2

Description

## Describe the bug

Chaining `publish` and `unpublish` commands changes their default behavior in relation to staging/production hosts.

## Expected Behavior
Commands `publish` and `unpublish` should **always** default to staging when `production_host` and `staging_host` are defined under `binary` in package.json.

## Actual Behavior

When the commands `publish` and `unpublish` are executed by themselves they default to staging. However, if the command being executed is chained after another command (for example `package publish` or `info unpublish`) then the default reverts to `binary.production_host`. As a result - **accidental publishing/unpublishing is possible**.

## Steps to Reproduce

### 1) Prep package.json
Replace "host" with `staging_host` and `production_host` in package.json

Example:
```
"staging_host": "https://apm-appoptics-bindings-node-dev-staging.s3.us-east-1.amazonaws.com",
"production_host": "https://apm-appoptics-bindings-node-dev-production.s3.us-east-1.amazonaws.com",
```

### 2) Run Commands one after the other
`node-pre-gyp package`
`node-pre-gyp publish`

Results in: ✅
```
[node-pre-gyp-test-app1] published to https://apm-appoptics-bindings-node-dev-staging.s3.us-east-1.amazonaws.com/node-pre-gyp/node-pre-gyp-test-app1/v0.1.0/Release/
```

`node-pre-gyp info`
`node-pre-gyp unpublish`

Results in: ✅
```
[node-pre-gyp-test-app1] Success: removed https://apm-appoptics-bindings-node-dev-staging.s3.amazonaws.com/node-pre-gyp/node-pre-gyp-test-app1/v0.1.0/Release/node-v83-darwin-x64.tar.gz
```

### 3) Run Chained Commands
`node-pre-gyp package publish`

Results in: ❌
```
[node-pre-gyp-test-app1] published to https://apm-appoptics-bindings-node-dev-production.s3.us-east-1.amazonaws.com/node-pre-gyp/node-pre-gyp-test-app1/v0.1.0/Release/
```

`node-pre-gyp info unpublish`

Results in: ❌
```
[node-pre-gyp-test-app1] Success: removed https://apm-appoptics-bindings-node-dev-production.s3.amazonaws.com/node-pre-gyp/node-pre-gyp-test-app1/v0.1.0/Release/node-v83-darwin-x64.tar.gz
```
## Root Cause
When chained commands are executed, the first command in the chain will [raise the `binaryHostSet` flag](https://github.com/mapbox/node-pre-gyp/blob/master/lib/node-pre-gyp.js#L275). Subsequent `publish` or `unpublish` [will trigger the early return](https://github.com/mapbox/node-pre-gyp/blob/master/lib/node-pre-gyp.js#L247). Due to the early return, the host will not be configured correctly resulting in the bug described above.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in lib/node-pre-gyp.js at the binaryHostSet handling around lines 247 and 275, then reproduce the issue with the package.json staging_host and production_host values shown. Verify the fix with both standalone and chained publish/unpublish commands; chained commands should default to staging rather than production.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
cli
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.