from pathlib import Path import pytest from tools import publish_registry_release def test_publish_stops_before_registry_when_manager_gate_fails(monkeypatch, tmp_path): calls = [] def fail_gate(source): raise RuntimeError("public clone failed") monkeypatch.setattr(publish_registry_release, "verify_manager_install", fail_gate) monkeypatch.setattr( publish_registry_release.subprocess, "run", lambda *args, **kwargs: calls.append((args, kwargs)), ) with pytest.raises(RuntimeError, match="public clone failed"): publish_registry_release.publish_release( tmp_path, comfy="comfy", token="private-token", changelog="release", ) assert calls == [] def test_publish_keeps_token_out_of_arguments_and_environment(monkeypatch, tmp_path): calls = [] monkeypatch.setattr( publish_registry_release, "verify_manager_install", lambda source: ("1.0.3", "https://example.test/owner/repo", "abc123"), ) def record_run(command, **kwargs): calls.append((command, kwargs)) monkeypatch.setattr(publish_registry_release.subprocess, "run", record_run) publish_registry_release.publish_release( Path(tmp_path), comfy="comfy", token="private-token", changelog="release notes", ) assert [command for command, _ in calls] == [ ["comfy", "node", "validate"], ["comfy", "node", "publish"], ] publish_kwargs = calls[1][1] assert publish_kwargs["input"] == "private-token\n" assert "private-token" not in repr(calls[1][0]) assert "private-token" not in repr(publish_kwargs["env"]) assert publish_kwargs["env"]["COMFY_NODE_CHANGELOG"] == "release notes"