fix: harden stelloauth oauth worker

This commit is contained in:
Dennis Juhler Aagaard
2026-09-24 17:00:07 +02:00
parent adb5aecfdc
commit ca34ff1dc6
3 changed files with 411 additions and 0 deletions
+56
View File
@@ -0,0 +1,56 @@
from __future__ import annotations
import subprocess
from pathlib import Path
import pytest
ROOT = Path(__file__).parents[1]
STELLOAUTH_COMMIT = "367d4f8c02a3b072c59142c49dffc129edc8548b"
CLOAK_COMMIT = "f04c23da285b3b3d3cf10c8f9d282e7adc1d52ce"
def run(*args: str, cwd: Path):
return subprocess.run(args, cwd=cwd, text=True, capture_output=True, check=True)
def fetch_exact(tmp_path: Path, name: str, url: str, commit: str) -> Path:
target = tmp_path / name
run("git", "init", str(target), cwd=tmp_path)
run("git", "remote", "add", "origin", url, cwd=target)
run("git", "fetch", "--depth=1", "origin", commit, cwd=target)
run("git", "checkout", "--detach", "FETCH_HEAD", cwd=target)
assert run("git", "rev-parse", "HEAD", cwd=target).stdout.strip() == commit
return target
@pytest.mark.upstream
def test_stelloauth_patch_applies_and_tests_pass(tmp_path: Path) -> None:
source = fetch_exact(
tmp_path,
"stelloauth",
"https://github.com/tamcore/stelloauth.git",
STELLOAUTH_COMMIT,
)
patch = ROOT / "stelloauth/patches/stelloauth-security.patch"
run("git", "apply", "--check", str(patch), cwd=source)
run("git", "apply", str(patch), cwd=source)
run("go", "test", "./...", cwd=source)
@pytest.mark.upstream
def test_cloak_patch_binds_only_loopback(tmp_path: Path) -> None:
source = fetch_exact(
tmp_path,
"cloakbrowser",
"https://github.com/CloakHQ/CloakBrowser.git",
CLOAK_COMMIT,
)
patch = ROOT / "stelloauth/patches/cloakserve-loopback.patch"
run("git", "apply", "--check", str(patch), cwd=source)
run("git", "apply", str(patch), cwd=source)
wrapper = (source / "bin/cloakserve").read_text(encoding="utf-8")
assert 'host = "127.0.0.1"' in wrapper
assert 'host = "0.0.0.0" if in_container' not in wrapper
run("python3", "-m", "py_compile", "bin/cloakserve", cwd=source)