Skip to content

Commit 9a5b080

Browse files
refactor(ENG-13681): move the unused domain-selection API to its caller
This branch shipped an API surface nothing in it calls. Every consumer is in the Maven helper (#339), which is stacked on top of this branch, so the code and its tests move there, where the first caller lives and where a reviewer can see what they are for. Moved: select_custom_domain and CustomDomain.serves_repository; the single-host resolvers default_host, default_host_for_type, builtin_host and builtin_host_for_type with their two private helpers; and domain_scope. With them go the twelve select_custom_domain tests, the six host-resolver tests and the persisted-scope test. Staying: _precedence_key and the CustomDomain.scope / is_bound_to pair it reads, because get_format_domains sorts by it and the Docker installer and runtime helper both call that. The DomainScope enum stays with them; only its string parser moves. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 59c9b1a commit 9a5b080

5 files changed

Lines changed: 10 additions & 403 deletions

File tree

‎cloudsmith_cli/cli/tests/commands/test_credential_helper.py‎

Lines changed: 1 addition & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@
2626
read_cache,
2727
write_cache,
2828
)
29-
from ....credential_helpers.default_domains import DomainScope, domain_scope
29+
from ....credential_helpers.default_domains import DomainScope
3030
from ....credential_helpers.docker.runtime import (
3131
_REFUSAL_MESSAGE,
3232
execute,
@@ -839,21 +839,6 @@ def test_custom_domain_scope(repository, expected):
839839
assert domain.scope is expected
840840

841841

842-
@pytest.mark.parametrize(
843-
"value,expected",
844-
[
845-
("repository", DomainScope.REPOSITORY),
846-
("organization", DomainScope.ORGANIZATION),
847-
("nonsense", DomainScope.ORGANIZATION),
848-
(None, DomainScope.ORGANIZATION),
849-
("", DomainScope.ORGANIZATION),
850-
],
851-
)
852-
def test_domain_scope_resolves_persisted_values(value, expected):
853-
"""A persisted scope string resolves, degrading to organisation."""
854-
assert domain_scope(value) is expected
855-
856-
857842
@httpretty.activate(allow_net_connect=False)
858843
def test_get_custom_domains_parses_repository_scope(tmp_path, monkeypatch):
859844
"""The nested repository payload binds the record to its repository."""

‎cloudsmith_cli/cli/tests/commands/test_custom_domain_precedence.py‎

Lines changed: 3 additions & 159 deletions
Original file line numberDiff line numberDiff line change
@@ -1,24 +1,18 @@
11
# Copyright 2026 Cloudsmith Ltd
2-
"""Tests for choosing between overlapping custom domains.
2+
"""Tests for the record fields custom-domain precedence ranks on.
33
4-
Repository-scoped beats organisation-wide, primary beats non-primary, and an
5-
older domain beats a newer one.
6-
7-
Also covers the record fields the chain reads, which have to survive the
8-
on-disk cache: a run served from the cache must rank domains identically to
9-
the run that populated it.
4+
They have to survive the on-disk cache: a run served from the cache must rank
5+
domains identically to the run that populated it.
106
"""
117

128
from datetime import datetime, timezone
139

1410
import pytest
1511

16-
from ....credential_helpers.backends import BackendKind
1712
from ....credential_helpers.custom_domains import (
1813
CustomDomain,
1914
_record_from_payload,
2015
read_cache,
21-
select_custom_domain,
2216
write_cache,
2317
)
2418
from ....credential_helpers.default_domains import DomainType
@@ -50,156 +44,6 @@ def _domain(
5044
)
5145

5246

53-
def _repo_domain(host, repository="prod", **kwargs):
54-
"""Build a record bound to a single repository."""
55-
return _domain(host, repository=repository, **kwargs)
56-
57-
58-
def test_repository_scoped_beats_organisation_wide():
59-
"""A domain bound to the repository in hand is the most specific match."""
60-
org_wide = _domain("dl.acme.com")
61-
repo_bound = _repo_domain("dl-prod.acme.com")
62-
63-
chosen = select_custom_domain(
64-
[org_wide, repo_bound], domain_type=DomainType.DOWNLOAD, repository="prod"
65-
)
66-
67-
assert chosen is repo_bound
68-
69-
70-
def test_repository_scoping_outranks_primary():
71-
"""Scope is a stronger signal than the primary flag."""
72-
org_wide_primary = _domain("dl.acme.com", primary=True)
73-
repo_bound_secondary = _repo_domain("dl-prod.acme.com", primary=False)
74-
75-
chosen = select_custom_domain(
76-
[org_wide_primary, repo_bound_secondary],
77-
domain_type=DomainType.DOWNLOAD,
78-
repository="prod",
79-
)
80-
81-
assert chosen is repo_bound_secondary
82-
83-
84-
def test_primary_beats_secondary_at_the_same_scope():
85-
"""Within one scope the primary domain wins, whatever its age."""
86-
secondary = _domain(
87-
"old.acme.com", primary=False, created_at="2024-01-01T00:00:00Z"
88-
)
89-
primary = _domain("new.acme.com", primary=True, created_at="2026-01-01T00:00:00Z")
90-
91-
chosen = select_custom_domain([secondary, primary], domain_type=DomainType.DOWNLOAD)
92-
93-
assert chosen is primary
94-
95-
96-
def test_oldest_wins_when_scope_and_primary_tie():
97-
"""Age is the final tie-break, oldest first."""
98-
newer = _domain("new.acme.com", created_at="2026-06-01T00:00:00Z")
99-
older = _domain("old.acme.com", created_at="2024-02-01T00:00:00Z")
100-
101-
chosen = select_custom_domain([newer, older], domain_type=DomainType.DOWNLOAD)
102-
103-
assert chosen is older
104-
105-
106-
def test_undated_domain_sorts_after_a_dated_one():
107-
"""A record with no timestamp must not out-rank a known-older one."""
108-
undated = _domain("undated.acme.com", created_at=None)
109-
dated = _domain("dated.acme.com", created_at="2025-05-01T00:00:00Z")
110-
111-
chosen = select_custom_domain([undated, dated], domain_type=DomainType.DOWNLOAD)
112-
113-
assert chosen is dated
114-
115-
116-
@pytest.mark.parametrize("enabled,validated", [(False, True), (True, False)])
117-
def test_inactive_domains_are_never_chosen(enabled, validated):
118-
"""A disabled or unvalidated domain cannot serve traffic."""
119-
inactive = _domain("broken.acme.com", enabled=enabled, validated=validated)
120-
121-
assert select_custom_domain([inactive], domain_type=DomainType.DOWNLOAD) is None
122-
123-
124-
def test_a_domain_bound_to_another_repository_is_never_used():
125-
"""A repository-scoped host serves only the repository it belongs to."""
126-
other = _repo_domain("dl-staging.acme.com", repository="staging")
127-
128-
assert (
129-
select_custom_domain(
130-
[other], domain_type=DomainType.DOWNLOAD, repository="prod"
131-
)
132-
is None
133-
)
134-
135-
136-
def test_a_repository_scoped_domain_is_skipped_without_a_repository():
137-
"""With no repository in hand, only organisation-wide domains apply."""
138-
repo_bound = _repo_domain("dl-prod.acme.com")
139-
140-
assert select_custom_domain([repo_bound], domain_type=DomainType.DOWNLOAD) is None
141-
142-
143-
def test_domain_types_do_not_cross_over():
144-
"""An upload host must never be offered as the download host."""
145-
upload = _domain("up.acme.com", domain_type=DomainType.UPLOAD)
146-
download = _domain("dl.acme.com", domain_type=DomainType.DOWNLOAD)
147-
148-
assert (
149-
select_custom_domain([upload, download], domain_type=DomainType.UPLOAD)
150-
is upload
151-
)
152-
assert (
153-
select_custom_domain([upload, download], domain_type=DomainType.DOWNLOAD)
154-
is download
155-
)
156-
157-
158-
def test_native_api_domains_are_matched_on_backend_kind():
159-
"""Native API hosts speak one format each, so the kind has to match."""
160-
maven = _domain(
161-
"mvn.acme.com",
162-
domain_type=DomainType.NATIVE_API,
163-
backend_kind=BackendKind.MAVEN,
164-
)
165-
python = _domain(
166-
"pypi.acme.com",
167-
domain_type=DomainType.NATIVE_API,
168-
backend_kind=BackendKind.PYTHON,
169-
)
170-
171-
chosen = select_custom_domain(
172-
[maven, python],
173-
domain_type=DomainType.NATIVE_API,
174-
backend_kind=BackendKind.MAVEN,
175-
)
176-
177-
assert chosen is maven
178-
179-
180-
def test_selection_is_independent_of_input_order():
181-
"""Two otherwise-equal domains must resolve the same way every run.
182-
183-
The listing API guarantees no ordering, and `read_all_cached_domains`
184-
merges several organisations' cache files, so arrival order is not stable
185-
even between two runs on one machine. Without a final tie-break, two
186-
installs of the same repository could bind different hosts.
187-
"""
188-
first = _domain("zzz.acme.com", created_at=None)
189-
second = _domain("aaa.acme.com", created_at=None)
190-
191-
forwards = select_custom_domain([first, second], domain_type=DomainType.DOWNLOAD)
192-
backwards = select_custom_domain([second, first], domain_type=DomainType.DOWNLOAD)
193-
194-
assert forwards is backwards
195-
assert forwards.host == "aaa.acme.com"
196-
197-
198-
def test_no_candidates_returns_none():
199-
"""An empty listing resolves to nothing, not an error."""
200-
assert select_custom_domain([], domain_type=DomainType.DOWNLOAD) is None
201-
202-
20347
def test_precedence_fields_round_trip_the_cache(tmp_path):
20448
"""A cached run must rank domains the same way the fetching run did.
20549

‎cloudsmith_cli/cli/tests/commands/test_default_domains.py‎

Lines changed: 6 additions & 81 deletions
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,6 @@
1111
BUILTIN_DOMAINS,
1212
DefaultDomain,
1313
DomainType,
14-
builtin_host,
15-
builtin_host_for_type,
16-
default_host,
17-
default_host_for_type,
1814
domain_type_for_backend_kind,
1915
format_for_backend_kind,
2016
load_default_domains,
@@ -215,60 +211,6 @@ def test_trusted_lookup_skips_a_config_without_a_domains_section(tmp_path, monke
215211
]
216212

217213

218-
def test_default_hosts_honour_a_config_override(tmp_path, monkeypatch):
219-
"""default_host/_for_type resolve against the override, not the builtins."""
220-
(tmp_path / "config.ini").write_text(
221-
"[domains]\ncdn.internal.example.com =\nmvn.internal.example.com = maven\n",
222-
encoding="utf-8",
223-
)
224-
monkeypatch.setattr(cli_config.ConfigReader, "config_files", ["config.ini"])
225-
monkeypatch.setattr(cli_config.ConfigReader, "config_searchpath", [str(tmp_path)])
226-
227-
assert default_host_for_type(DomainType.DOWNLOAD) == "cdn.internal.example.com"
228-
assert default_host(BackendKind.MAVEN) == "mvn.internal.example.com"
229-
230-
231-
def test_default_host_rejects_a_kind_the_declared_table_omits(tmp_path, monkeypatch):
232-
"""A declared table is authoritative - it never falls back to a built-in.
233-
234-
The section decides which hosts may receive a Cloudsmith credential, so
235-
resolving to a public *.cloudsmith.io host the operator never listed would
236-
contradict the very statement the table makes. An on-premise deployment
237-
would also be handed a host it cannot reach.
238-
"""
239-
(tmp_path / "config.ini").write_text(
240-
"[domains]\ncdn.internal.example.com =\n", encoding="utf-8"
241-
)
242-
monkeypatch.setattr(cli_config.ConfigReader, "config_files", ["config.ini"])
243-
monkeypatch.setattr(cli_config.ConfigReader, "config_searchpath", [str(tmp_path)])
244-
245-
with pytest.raises(ValueError, match="maven"):
246-
default_host(BackendKind.MAVEN)
247-
248-
249-
def test_default_host_for_type_rejects_a_type_the_declared_table_omits(
250-
tmp_path, monkeypatch
251-
):
252-
"""The format-less endpoints get the same treatment as a package format."""
253-
(tmp_path / "config.ini").write_text(
254-
"[domains]\ncdn.internal.example.com =\n", encoding="utf-8"
255-
)
256-
monkeypatch.setattr(cli_config.ConfigReader, "config_files", ["config.ini"])
257-
monkeypatch.setattr(cli_config.ConfigReader, "config_searchpath", [str(tmp_path)])
258-
259-
with pytest.raises(ValueError, match="upload"):
260-
default_host_for_type(DomainType.UPLOAD)
261-
262-
263-
def test_default_hosts_use_builtins_when_no_table_is_declared(tmp_path, monkeypatch):
264-
"""Declaring no table at all still resolves to the built-in hosts."""
265-
monkeypatch.setattr(cli_config.ConfigReader, "config_files", ["config.ini"])
266-
monkeypatch.setattr(cli_config.ConfigReader, "config_searchpath", [str(tmp_path)])
267-
268-
assert default_host(BackendKind.MAVEN) == "maven.cloudsmith.io"
269-
assert default_host_for_type(DomainType.UPLOAD) == "upload.cloudsmith.io"
270-
271-
272214
@pytest.mark.parametrize(
273215
"label,domain_type",
274216
[
@@ -299,14 +241,15 @@ def test_config_reserved_labels_declare_formatless_hosts(tmp_path, label, domain
299241

300242

301243
def test_declared_upload_host_resolves(tmp_path, monkeypatch):
302-
"""A declared upload endpoint is what default_host_for_type returns."""
244+
"""A declared upload endpoint lands in the table as the upload host."""
303245
(tmp_path / "config.ini").write_text(
304246
"[domains]\nuploads.internal.example.com = upload\n", encoding="utf-8"
305247
)
306248
monkeypatch.setattr(cli_config.ConfigReader, "config_files", ["config.ini"])
307249
monkeypatch.setattr(cli_config.ConfigReader, "config_searchpath", [str(tmp_path)])
308250

309-
assert default_host_for_type(DomainType.UPLOAD) == "uploads.internal.example.com"
251+
domain = _by_host(load_default_domains())["uploads.internal.example.com"]
252+
assert domain.domain_type is DomainType.UPLOAD
310253

311254

312255
def test_unrecognised_config_label_is_warned_about(tmp_path, caplog):
@@ -396,8 +339,9 @@ def test_explicit_config_file_is_honoured_as_trusted(tmp_path, monkeypatch):
396339
)
397340
monkeypatch.setattr(cli_config.ConfigReader, "config_searchpath", ["."])
398341

399-
assert default_host_for_type(DomainType.DOWNLOAD) == "cdn.internal.example.com"
400-
assert default_host(BackendKind.MAVEN) == "mvn.internal.example.com"
342+
indexed = _by_host(load_default_domains())
343+
assert indexed["cdn.internal.example.com"].domain_type is DomainType.DOWNLOAD
344+
assert indexed["mvn.internal.example.com"].backend_kind == BackendKind.MAVEN
401345
assert untrusted_config_declares_domains() is False
402346

403347

@@ -459,17 +403,6 @@ def test_builtin_domains_with_a_backend_kind_are_native_api():
459403
assert domain.domain_type is DomainType.NATIVE_API, domain.host
460404

461405

462-
def test_builtin_host_for_type_resolves_the_format_less_hosts():
463-
"""The download and upload hosts are looked up by type, not by constant.
464-
465-
NATIVE_API covers many hosts, so there is no single one to return.
466-
"""
467-
assert builtin_host_for_type(DomainType.DOWNLOAD) == "dl.cloudsmith.io"
468-
assert builtin_host_for_type(DomainType.UPLOAD) == "upload.cloudsmith.io"
469-
with pytest.raises(ValueError):
470-
builtin_host_for_type(DomainType.NATIVE_API)
471-
472-
473406
@pytest.mark.parametrize(
474407
"backend_kind,expected",
475408
[
@@ -484,14 +417,6 @@ def test_domain_type_for_backend_kind(backend_kind, expected):
484417
assert domain_type_for_backend_kind(backend_kind) is expected
485418

486419

487-
def test_builtin_host_resolves_a_backend_kind_to_its_own_host():
488-
"""Formats served only via the CDN have no dedicated built-in host."""
489-
assert builtin_host(BackendKind.MAVEN) == "maven.cloudsmith.io"
490-
assert builtin_host(BackendKind.PYTHON) == "python.cloudsmith.io"
491-
with pytest.raises(ValueError):
492-
builtin_host(BackendKind.DEB)
493-
494-
495420
def test_default_domain_is_frozen():
496421
"""Records are immutable so callers cannot mutate the shared table."""
497422
domain = DefaultDomain(host="a.cloudsmith.io", backend_kind=BackendKind.PYTHON)

0 commit comments

Comments
 (0)