#!/usr/bin/env bash

export MISE_LOCKFILE=1

detect_platform
PLATFORM="$MISE_PLATFORM"

echo "=== Testing unconfigured SLSA is omitted from locks ==="
# sops declares SLSA provenance but the Aqua registry has no signer identity.
cat <<EOF >mise.toml
[tools]
sops = "3.12.1"
EOF

mise lock --platform "$PLATFORM"
assert "test -f mise.lock"
assert_not_contains "cat mise.lock" 'provenance.slsa'

echo "=== Testing configured SLSA signer locks and installs ==="
rm -f mise.lock mise.toml
case "$PLATFORM" in
  linux-x64) SOPS_ASSET=sops-v3.12.1.linux.amd64 ;;
  macos-arm64) SOPS_ASSET=sops-v3.12.1.darwin.arm64 ;;
  *) SOPS_ASSET= ;;
esac
if [[ -n $SOPS_ASSET ]]; then
  cat <<EOF >mise.toml
[tools]
"github:getsops/sops" = { version = "3.12.1", asset_pattern = "$SOPS_ASSET", github_attestations = false, slsa_signer_identity = "https://github.com/slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@refs/tags/v2.1.0", slsa_signer_issuer = "https://token.actions.githubusercontent.com" }
EOF

  mise lock --platform "$PLATFORM"
  assert_contains "cat mise.lock" 'provenance.slsa]'
  mise install --locked
  assert "mise where github:getsops/sops@3.12.1"

  # A lock that records a checksum and SLSA provenance is trusted: installing from it
  # verifies nothing, so neither a different signer nor a missing one matters.
  SOPS_INSTALL=$(mise where github:getsops/sops@3.12.1)
  rm -rf "$SOPS_INSTALL"
  cat <<EOF >mise.toml
[tools]
"github:getsops/sops" = { version = "3.12.1", asset_pattern = "$SOPS_ASSET", github_attestations = false }
EOF
  mise install --locked
  assert "mise where github:getsops/sops@3.12.1"

  # locked_verify_provenance opts back in to verifying against the current signer.
  rm -rf "$SOPS_INSTALL"
  assert_fail_contains "MISE_LOCKED_VERIFY_PROVENANCE=1 mise install --locked 2>&1" "no expected signer"
  cat <<EOF >mise.toml
[tools]
"github:getsops/sops" = { version = "3.12.1", asset_pattern = "$SOPS_ASSET", github_attestations = false, slsa_signer_identity = "https://github.com/example/other/.github/workflows/release.yml@refs/tags/v3.12.1", slsa_signer_issuer = "https://token.actions.githubusercontent.com" }
EOF
  assert_fail_contains "MISE_LOCKED_VERIFY_PROVENANCE=1 mise install --locked 2>&1" "signer identity"
fi

echo "=== Testing provenance downgrade attack detection ==="
rm -f mise.lock mise.toml

# Set up a tool via aqua backend
cat <<EOF >mise.toml
[tools]
"aqua:jqlang/jq" = "1.7.1"
EOF

# Generate lockfile with real checksums/URLs for the current platform only
mise lock --platform "$PLATFORM"
assert "test -f mise.lock"
assert_contains "cat mise.lock" "\"platforms.$PLATFORM\""

# Inject provenance into the lockfile (simulating a previously-verified install)
# Use awk for portable sed-like editing (works on both macOS and Linux)
awk -v platform="$PLATFORM" '
    # Remove existing provenance lines in the target platform section
    /^provenance/ && in_section { next }
    # Detect entering the target platform section and add provenance after the header
    { print }
    index($0, "platforms." platform) > 0 { in_section=1; print "provenance = \"github-attestations\"" }
    /^\[/ { in_section=0 }
' mise.lock >mise.lock.tmp && mv mise.lock.tmp mise.lock
assert_contains "cat mise.lock" 'provenance = "github-attestations"'

# Attempt install with provenance verification disabled.
# The lockfile says provenance was verified, but settings are off,
# so mise should refuse to install (downgrade/stripping attack).
rm -rf "$MISE_DATA_DIR/installs/aqua-jqlang-jq"
export MISE_GITHUB_ATTESTATIONS=0
export MISE_AQUA__GITHUB_ATTESTATIONS=0
assert_fail_contains "mise install 2>&1" "downgrade attack"

echo "=== Cleanup ==="
rm -f mise.lock mise.toml

echo "mise lockfile provenance tests passed!"
