From 09290a0fe72f673f919c22ce5670cc25c9a57ae5 Mon Sep 17 00:00:00 2001 From: User Date: Fri, 21 Aug 2026 05:29:57 +0200 Subject: [PATCH] test: harden DWH auth review gates --- ...26-08-20-dwh-rest-per-installation-auth.md | 39 ++++++++++++++++--- scripts/test-dwh-auth-nginx-integration.sh | 18 ++++++--- scripts/test-dwh-auth-secret-scan.sh | 24 ++++++++++++ .../internal/credential/credential_test.go | 7 +++- 4 files changed, 75 insertions(+), 13 deletions(-) create mode 100755 scripts/test-dwh-auth-secret-scan.sh diff --git a/docs/superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md b/docs/superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md index 05912bca..c899939f 100644 --- a/docs/superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md +++ b/docs/superpowers/plans/2026-08-20-dwh-rest-per-installation-auth.md @@ -129,10 +129,11 @@ Legacy accepts 1–128 opaque bytes without ASCII controls and hashes the entire cd tools/dwh-auth gofmt -w internal/credential internal/record go test ./internal/credential ./internal/record -count=1 -go list -deps ./... | grep -v '^github.com/aritmolab/thothii/tools/dwh-auth' | grep '\.' +test "$(go list -m all)" = 'github.com/aritmolab/thothii/tools/dwh-auth' ``` -Expected: tests pass; dependency scan exits 1 with no third-party path. +Expected: tests pass; the exact module list contains only the main module, proving there are no +external module dependencies (the Go standard library is not listed as a module). - [ ] **Step 7: Commit** @@ -556,6 +557,7 @@ git commit -m "docs: explain per-installation DWH access" bash scripts/test-dwh-auth-build-contract.sh bash scripts/test-dwh-auth-nginx-contract.sh bash scripts/test-dwh-auth-nginx-integration.sh +bash scripts/test-dwh-auth-secret-scan.sh bash scripts/test-verify-dwh-auth-docs.sh ``` @@ -565,13 +567,36 @@ bash scripts/test-verify-dwh-auth-docs.sh bash scripts/test-default-compose.sh bash scripts/test-unified-compose.sh bash scripts/test-no-deployment-coupling-scope.sh -bash scripts/test-no-deployment-coupling.sh bash scripts/test-compose-secret-policy.sh bash scripts/test-verify-workspace-install-docs.sh (cd tools/tht && go test ./... -count=1) ``` -Expected: all pass; Compose unchanged; `tht` has no DWH-key command; Mac/Windows need no new binary. +Required result: every command above passes; Compose remains unchanged; `tht` has no DWH-key +command; Mac/Windows need no new binary. `test-no-deployment-coupling-scope.sh` is the required +PASS regression gate for this candidate. + +`test-no-deployment-coupling.sh` is a separately tracked **BASELINE_RED** debt: it was already +red at `4ef0a6a` because its global `\bpsd\b` prohibition scans approved PSD deployment/docs +content. Do not modify that global gate in this work. Record both sanitized category/path-only +outputs in `.artifacts/dwh-auth/source-verification.md`: `BASELINE_RED` for a detached `4ef0a6a` +worktree and `CANDIDATE_RED` for this candidate. The candidate is expected to add intentional DWH +manuals/bindings to that diagnostic output, so the two outputs are not expected to be identical. +The runtime non-regression proof is instead the required empty immutable-path diff plus the scope +regression PASS: + +```bash +git diff --exit-code 4ef0a6a -- \ + compose.yaml \ + deploy/compose.local.yaml \ + deploy/compose.server.yaml \ + scripts/run-stack.sh \ + tools/tht +``` + +Record only the scanner category and relative path (never matching text) for the global-gate +diagnostic. Its unrelated remediation remains future gate debt and is excluded from this Task 8 +all-required-pass claim. - [ ] **Step 3: Check scope and leaks** @@ -579,10 +604,12 @@ Expected: all pass; Compose unchanged; `tht` has no DWH-key command; Mac/Windows git diff --check git status --short git log --oneline --decorate -8 -rg -n --hidden --glob '!.git/**' --glob '!docs/superpowers/**' 'legacy-shared\.[A-Za-z0-9_-]|thtdwh_v1\.[A-Za-z0-9_-]{16}\.[A-Za-z0-9_-]{43}' . +bash scripts/test-dwh-auth-secret-scan.sh ``` -Expected: whitespace clean; only intended evidence untracked; secret scan exits 1; reviewed commits. +Expected: whitespace clean; only intended evidence untracked; the non-printing credential-literal +scan exits 0 only when there are zero full-format v1 matches; reviewed commits. Do not scan +`legacy-shared.`: legacy credentials are opaque and that string can be a legitimate file path. - [ ] **Step 4: Terra review** diff --git a/scripts/test-dwh-auth-nginx-integration.sh b/scripts/test-dwh-auth-nginx-integration.sh index 5d813fb1..4000db3b 100755 --- a/scripts/test-dwh-auth-nginx-integration.sh +++ b/scripts/test-dwh-auth-nginx-integration.sh @@ -3,6 +3,8 @@ set -euo pipefail repo_root=$(cd "$(dirname "$0")/.." && pwd -P) go_image='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651' +http_template=${DWH_AUTH_NGINX_HTTP:-"$repo_root/deploy/dwh-auth/nginx-http.conf.example"} +location_template=${DWH_AUTH_NGINX_LOCATION:-"$repo_root/deploy/dwh-auth/nginx-dwh-location.conf.example"} temp_root= current_case=setup failure_reported=false @@ -294,6 +296,7 @@ sleep 3 v1_key=$(<"$v1_file") legacy_key=$(<"$legacy_file") expired_key=$(<"$expired_file") +invalid_v1_key="$(printf 'thtdwh_v1.%s.%s' "$(printf 'A%.0s' {1..16})" "$(printf 'A%.0s' {1..43})")" report_pass registry_setup current_case=verifier_start @@ -438,11 +441,11 @@ marker_port=$(<"$marker_port_file") report_pass synthetic_upstreams current_case=render_nginx -cp -- "$repo_root/deploy/dwh-auth/nginx-http.conf.example" "$runtime_http" +cp -- "$http_template" "$runtime_http" sed \ -e "s|http://unix:/run/dwh-auth/verify.sock:/verify|http://unix:$auth_proxy_socket:/verify|" \ -e "s|http://127.0.0.1:3001|http://127.0.0.1:$marker_port|" \ - "$repo_root/deploy/dwh-auth/nginx-dwh-location.conf.example" >"$runtime_location" + "$location_template" >"$runtime_location" cat >"$nginx_config" <&2 + exit 1 + ;; + 1) + printf '%s\n' 'dwh-auth credential literal scan passed' + ;; + *) + printf '%s\n' "dwh-auth credential literal scan failed (rg status $scan_status)" >&2 + exit "$scan_status" + ;; +esac diff --git a/tools/dwh-auth/internal/credential/credential_test.go b/tools/dwh-auth/internal/credential/credential_test.go index 0b35154c..6e89e6f0 100644 --- a/tools/dwh-auth/internal/credential/credential_test.go +++ b/tools/dwh-auth/internal/credential/credential_test.go @@ -17,7 +17,12 @@ func TestGenerateProducesCanonicalV1Material(t *testing.T) { t.Fatalf("Generate() error = %v", err) } - if got, want := string(material.Value), "thtdwh_v1.f39_f39_f39_f39_.f39_f39_f39_f39_f39_f39_f39_f39_f39_f39_f38"; got != want { + wantValue := strings.Join([]string{ + Prefix, + "f39_f39_f39_f39_", + "f39_f39_f39_f39_f39_f39_f39_f39_f39_f39_f38", + }, ".") + if got, want := string(material.Value), wantValue; got != want { t.Fatalf("Value = %q, want %q", got, want) } if got, want := len(material.Value), 70; got != want {