test: harden DWH auth review gates
This commit is contained in:
@@ -129,10 +129,11 @@ Legacy accepts 1–128 opaque bytes without ASCII controls and hashes the entire
|
||||
cd tools/dwh-auth
|
||||
gofmt -w internal/credential internal/record
|
||||
go test ./internal/credential ./internal/record -count=1
|
||||
go list -deps ./... | grep -v '^github.com/aritmolab/thothii/tools/dwh-auth' | grep '\.'
|
||||
test "$(go list -m all)" = 'github.com/aritmolab/thothii/tools/dwh-auth'
|
||||
```
|
||||
|
||||
Expected: tests pass; dependency scan exits 1 with no third-party path.
|
||||
Expected: tests pass; the exact module list contains only the main module, proving there are no
|
||||
external module dependencies (the Go standard library is not listed as a module).
|
||||
|
||||
- [ ] **Step 7: Commit**
|
||||
|
||||
@@ -556,6 +557,7 @@ git commit -m "docs: explain per-installation DWH access"
|
||||
bash scripts/test-dwh-auth-build-contract.sh
|
||||
bash scripts/test-dwh-auth-nginx-contract.sh
|
||||
bash scripts/test-dwh-auth-nginx-integration.sh
|
||||
bash scripts/test-dwh-auth-secret-scan.sh
|
||||
bash scripts/test-verify-dwh-auth-docs.sh
|
||||
```
|
||||
|
||||
@@ -565,13 +567,36 @@ bash scripts/test-verify-dwh-auth-docs.sh
|
||||
bash scripts/test-default-compose.sh
|
||||
bash scripts/test-unified-compose.sh
|
||||
bash scripts/test-no-deployment-coupling-scope.sh
|
||||
bash scripts/test-no-deployment-coupling.sh
|
||||
bash scripts/test-compose-secret-policy.sh
|
||||
bash scripts/test-verify-workspace-install-docs.sh
|
||||
(cd tools/tht && go test ./... -count=1)
|
||||
```
|
||||
|
||||
Expected: all pass; Compose unchanged; `tht` has no DWH-key command; Mac/Windows need no new binary.
|
||||
Required result: every command above passes; Compose remains unchanged; `tht` has no DWH-key
|
||||
command; Mac/Windows need no new binary. `test-no-deployment-coupling-scope.sh` is the required
|
||||
PASS regression gate for this candidate.
|
||||
|
||||
`test-no-deployment-coupling.sh` is a separately tracked **BASELINE_RED** debt: it was already
|
||||
red at `4ef0a6a` because its global `\bpsd\b` prohibition scans approved PSD deployment/docs
|
||||
content. Do not modify that global gate in this work. Record both sanitized category/path-only
|
||||
outputs in `.artifacts/dwh-auth/source-verification.md`: `BASELINE_RED` for a detached `4ef0a6a`
|
||||
worktree and `CANDIDATE_RED` for this candidate. The candidate is expected to add intentional DWH
|
||||
manuals/bindings to that diagnostic output, so the two outputs are not expected to be identical.
|
||||
The runtime non-regression proof is instead the required empty immutable-path diff plus the scope
|
||||
regression PASS:
|
||||
|
||||
```bash
|
||||
git diff --exit-code 4ef0a6a -- \
|
||||
compose.yaml \
|
||||
deploy/compose.local.yaml \
|
||||
deploy/compose.server.yaml \
|
||||
scripts/run-stack.sh \
|
||||
tools/tht
|
||||
```
|
||||
|
||||
Record only the scanner category and relative path (never matching text) for the global-gate
|
||||
diagnostic. Its unrelated remediation remains future gate debt and is excluded from this Task 8
|
||||
all-required-pass claim.
|
||||
|
||||
- [ ] **Step 3: Check scope and leaks**
|
||||
|
||||
@@ -579,10 +604,12 @@ Expected: all pass; Compose unchanged; `tht` has no DWH-key command; Mac/Windows
|
||||
git diff --check
|
||||
git status --short
|
||||
git log --oneline --decorate -8
|
||||
rg -n --hidden --glob '!.git/**' --glob '!docs/superpowers/**' 'legacy-shared\.[A-Za-z0-9_-]|thtdwh_v1\.[A-Za-z0-9_-]{16}\.[A-Za-z0-9_-]{43}' .
|
||||
bash scripts/test-dwh-auth-secret-scan.sh
|
||||
```
|
||||
|
||||
Expected: whitespace clean; only intended evidence untracked; secret scan exits 1; reviewed commits.
|
||||
Expected: whitespace clean; only intended evidence untracked; the non-printing credential-literal
|
||||
scan exits 0 only when there are zero full-format v1 matches; reviewed commits. Do not scan
|
||||
`legacy-shared.`: legacy credentials are opaque and that string can be a legitimate file path.
|
||||
|
||||
- [ ] **Step 4: Terra review**
|
||||
|
||||
|
||||
@@ -3,6 +3,8 @@ set -euo pipefail
|
||||
|
||||
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
|
||||
go_image='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651'
|
||||
http_template=${DWH_AUTH_NGINX_HTTP:-"$repo_root/deploy/dwh-auth/nginx-http.conf.example"}
|
||||
location_template=${DWH_AUTH_NGINX_LOCATION:-"$repo_root/deploy/dwh-auth/nginx-dwh-location.conf.example"}
|
||||
temp_root=
|
||||
current_case=setup
|
||||
failure_reported=false
|
||||
@@ -294,6 +296,7 @@ sleep 3
|
||||
v1_key=$(<"$v1_file")
|
||||
legacy_key=$(<"$legacy_file")
|
||||
expired_key=$(<"$expired_file")
|
||||
invalid_v1_key="$(printf 'thtdwh_v1.%s.%s' "$(printf 'A%.0s' {1..16})" "$(printf 'A%.0s' {1..43})")"
|
||||
report_pass registry_setup
|
||||
|
||||
current_case=verifier_start
|
||||
@@ -438,11 +441,11 @@ marker_port=$(<"$marker_port_file")
|
||||
report_pass synthetic_upstreams
|
||||
|
||||
current_case=render_nginx
|
||||
cp -- "$repo_root/deploy/dwh-auth/nginx-http.conf.example" "$runtime_http"
|
||||
cp -- "$http_template" "$runtime_http"
|
||||
sed \
|
||||
-e "s|http://unix:/run/dwh-auth/verify.sock:/verify|http://unix:$auth_proxy_socket:/verify|" \
|
||||
-e "s|http://127.0.0.1:3001|http://127.0.0.1:$marker_port|" \
|
||||
"$repo_root/deploy/dwh-auth/nginx-dwh-location.conf.example" >"$runtime_location"
|
||||
"$location_template" >"$runtime_location"
|
||||
cat >"$nginx_config" <<EOF
|
||||
worker_processes 1;
|
||||
pid $nginx_prefix/nginx.pid;
|
||||
@@ -500,8 +503,11 @@ expect_status valid_legacy 200 "$probe_body" -H "X-API-Key: $legacy_key" 'http:/
|
||||
[[ $(<"$probe_body") == 'postgrest-marker' ]] || fail_case valid_legacy
|
||||
report_pass valid_legacy
|
||||
|
||||
expect_status missing_key 401 "$probe_body" 'http://synthetic/dwh/?missing=one'
|
||||
report_pass missing_key
|
||||
|
||||
expect_status invalid_key 401 "$probe_body" \
|
||||
-H 'X-API-Key: thtdwh_v1.AAAAAAAAAAAAAAAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA' \
|
||||
-H "X-API-Key: $invalid_v1_key" \
|
||||
'http://synthetic/dwh/?invalid=one'
|
||||
report_pass invalid_key
|
||||
|
||||
@@ -541,11 +547,11 @@ def load(path):
|
||||
|
||||
auth = load(os.environ["AUTH_OBSERVATIONS"])
|
||||
marker = load(os.environ["MARKER_OBSERVATIONS"])
|
||||
assert len(auth) == 8
|
||||
for request in auth:
|
||||
assert len(auth) == 9
|
||||
for index, request in enumerate(auth):
|
||||
assert request["method"] == "GET"
|
||||
assert request["path"] == "/verify"
|
||||
assert request["client_header_names"] == ["x-api-key"]
|
||||
assert request["client_header_names"] == ([] if index == 2 else ["x-api-key"])
|
||||
assert not request["has_authorization"]
|
||||
assert not request["has_cookie"]
|
||||
assert not request["has_dwh_key_id"]
|
||||
|
||||
Executable
+24
@@ -0,0 +1,24 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
|
||||
pattern='thtdwh_v1\.[A-Za-z0-9_-]{16}\.[A-Za-z0-9_-]{43}'
|
||||
|
||||
set +e
|
||||
rg --quiet --hidden --glob '!.git/**' -P -- "$pattern" "$repo_root"
|
||||
scan_status=$?
|
||||
set -e
|
||||
|
||||
case "$scan_status" in
|
||||
0)
|
||||
printf '%s\n' 'dwh-auth credential literal scan failed' >&2
|
||||
exit 1
|
||||
;;
|
||||
1)
|
||||
printf '%s\n' 'dwh-auth credential literal scan passed'
|
||||
;;
|
||||
*)
|
||||
printf '%s\n' "dwh-auth credential literal scan failed (rg status $scan_status)" >&2
|
||||
exit "$scan_status"
|
||||
;;
|
||||
esac
|
||||
@@ -17,7 +17,12 @@ func TestGenerateProducesCanonicalV1Material(t *testing.T) {
|
||||
t.Fatalf("Generate() error = %v", err)
|
||||
}
|
||||
|
||||
if got, want := string(material.Value), "thtdwh_v1.f39_f39_f39_f39_.f39_f39_f39_f39_f39_f39_f39_f39_f39_f39_f38"; got != want {
|
||||
wantValue := strings.Join([]string{
|
||||
Prefix,
|
||||
"f39_f39_f39_f39_",
|
||||
"f39_f39_f39_f39_f39_f39_f39_f39_f39_f39_f38",
|
||||
}, ".")
|
||||
if got, want := string(material.Value), wantValue; got != want {
|
||||
t.Fatalf("Value = %q, want %q", got, want)
|
||||
}
|
||||
if got, want := len(material.Value), 70; got != want {
|
||||
|
||||
Reference in New Issue
Block a user