fix: harden stelloauth oauth worker
This commit is contained in:
@@ -0,0 +1,56 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import subprocess
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
|
||||
ROOT = Path(__file__).parents[1]
|
||||
STELLOAUTH_COMMIT = "367d4f8c02a3b072c59142c49dffc129edc8548b"
|
||||
CLOAK_COMMIT = "f04c23da285b3b3d3cf10c8f9d282e7adc1d52ce"
|
||||
|
||||
|
||||
def run(*args: str, cwd: Path):
|
||||
return subprocess.run(args, cwd=cwd, text=True, capture_output=True, check=True)
|
||||
|
||||
|
||||
def fetch_exact(tmp_path: Path, name: str, url: str, commit: str) -> Path:
|
||||
target = tmp_path / name
|
||||
run("git", "init", str(target), cwd=tmp_path)
|
||||
run("git", "remote", "add", "origin", url, cwd=target)
|
||||
run("git", "fetch", "--depth=1", "origin", commit, cwd=target)
|
||||
run("git", "checkout", "--detach", "FETCH_HEAD", cwd=target)
|
||||
assert run("git", "rev-parse", "HEAD", cwd=target).stdout.strip() == commit
|
||||
return target
|
||||
|
||||
|
||||
@pytest.mark.upstream
|
||||
def test_stelloauth_patch_applies_and_tests_pass(tmp_path: Path) -> None:
|
||||
source = fetch_exact(
|
||||
tmp_path,
|
||||
"stelloauth",
|
||||
"https://github.com/tamcore/stelloauth.git",
|
||||
STELLOAUTH_COMMIT,
|
||||
)
|
||||
patch = ROOT / "stelloauth/patches/stelloauth-security.patch"
|
||||
run("git", "apply", "--check", str(patch), cwd=source)
|
||||
run("git", "apply", str(patch), cwd=source)
|
||||
run("go", "test", "./...", cwd=source)
|
||||
|
||||
|
||||
@pytest.mark.upstream
|
||||
def test_cloak_patch_binds_only_loopback(tmp_path: Path) -> None:
|
||||
source = fetch_exact(
|
||||
tmp_path,
|
||||
"cloakbrowser",
|
||||
"https://github.com/CloakHQ/CloakBrowser.git",
|
||||
CLOAK_COMMIT,
|
||||
)
|
||||
patch = ROOT / "stelloauth/patches/cloakserve-loopback.patch"
|
||||
run("git", "apply", "--check", str(patch), cwd=source)
|
||||
run("git", "apply", str(patch), cwd=source)
|
||||
wrapper = (source / "bin/cloakserve").read_text(encoding="utf-8")
|
||||
assert 'host = "127.0.0.1"' in wrapper
|
||||
assert 'host = "0.0.0.0" if in_container' not in wrapper
|
||||
run("python3", "-m", "py_compile", "bin/cloakserve", cwd=source)
|
||||
Reference in New Issue
Block a user