test: harden DWH auth review gates

This commit is contained in:
User
2026-08-21 05:29:57 +02:00
parent 7fe53164ba
commit 09290a0fe7
4 changed files with 75 additions and 13 deletions
+12 -6
View File
@@ -3,6 +3,8 @@ set -euo pipefail
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
go_image='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651'
http_template=${DWH_AUTH_NGINX_HTTP:-"$repo_root/deploy/dwh-auth/nginx-http.conf.example"}
location_template=${DWH_AUTH_NGINX_LOCATION:-"$repo_root/deploy/dwh-auth/nginx-dwh-location.conf.example"}
temp_root=
current_case=setup
failure_reported=false
@@ -294,6 +296,7 @@ sleep 3
v1_key=$(<"$v1_file")
legacy_key=$(<"$legacy_file")
expired_key=$(<"$expired_file")
invalid_v1_key="$(printf 'thtdwh_v1.%s.%s' "$(printf 'A%.0s' {1..16})" "$(printf 'A%.0s' {1..43})")"
report_pass registry_setup
current_case=verifier_start
@@ -438,11 +441,11 @@ marker_port=$(<"$marker_port_file")
report_pass synthetic_upstreams
current_case=render_nginx
cp -- "$repo_root/deploy/dwh-auth/nginx-http.conf.example" "$runtime_http"
cp -- "$http_template" "$runtime_http"
sed \
-e "s|http://unix:/run/dwh-auth/verify.sock:/verify|http://unix:$auth_proxy_socket:/verify|" \
-e "s|http://127.0.0.1:3001|http://127.0.0.1:$marker_port|" \
"$repo_root/deploy/dwh-auth/nginx-dwh-location.conf.example" >"$runtime_location"
"$location_template" >"$runtime_location"
cat >"$nginx_config" <<EOF
worker_processes 1;
pid $nginx_prefix/nginx.pid;
@@ -500,8 +503,11 @@ expect_status valid_legacy 200 "$probe_body" -H "X-API-Key: $legacy_key" 'http:/
[[ $(<"$probe_body") == 'postgrest-marker' ]] || fail_case valid_legacy
report_pass valid_legacy
expect_status missing_key 401 "$probe_body" 'http://synthetic/dwh/?missing=one'
report_pass missing_key
expect_status invalid_key 401 "$probe_body" \
-H 'X-API-Key: thtdwh_v1.AAAAAAAAAAAAAAAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA' \
-H "X-API-Key: $invalid_v1_key" \
'http://synthetic/dwh/?invalid=one'
report_pass invalid_key
@@ -541,11 +547,11 @@ def load(path):
auth = load(os.environ["AUTH_OBSERVATIONS"])
marker = load(os.environ["MARKER_OBSERVATIONS"])
assert len(auth) == 8
for request in auth:
assert len(auth) == 9
for index, request in enumerate(auth):
assert request["method"] == "GET"
assert request["path"] == "/verify"
assert request["client_header_names"] == ["x-api-key"]
assert request["client_header_names"] == ([] if index == 2 else ["x-api-key"])
assert not request["has_authorization"]
assert not request["has_cookie"]
assert not request["has_dwh_key_id"]
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env bash
set -euo pipefail
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
pattern='thtdwh_v1\.[A-Za-z0-9_-]{16}\.[A-Za-z0-9_-]{43}'
set +e
rg --quiet --hidden --glob '!.git/**' -P -- "$pattern" "$repo_root"
scan_status=$?
set -e
case "$scan_status" in
0)
printf '%s\n' 'dwh-auth credential literal scan failed' >&2
exit 1
;;
1)
printf '%s\n' 'dwh-auth credential literal scan passed'
;;
*)
printf '%s\n' "dwh-auth credential literal scan failed (rg status $scan_status)" >&2
exit "$scan_status"
;;
esac