fix: harden workspace diagnostic protocols
This commit is contained in:
@@ -366,6 +366,31 @@ test("does not substitute the reader credential for a declared vector writer", a
|
||||
expect(adapters.writeDiagnosticRecord).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test("rejects a writer credential that aliases the reader credential", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const readerKey = join(directory, "reader-key");
|
||||
const writerAlias = join(directory, "writer-key");
|
||||
await writeFile(readerKey, "same-secret\n", { mode: 0o600 });
|
||||
await (await import("node:fs/promises")).symlink(readerKey, writerAlias);
|
||||
const adapters = successfulAdapters();
|
||||
const aliasedBindings: RuntimeBindings = {
|
||||
...writerBindings,
|
||||
vector: { ...writerBindings.vector, values: {
|
||||
...writerBindings.vector.values,
|
||||
THT_WS_PSD_CLINICAL_VECTOR_API_KEY_FILE: readerKey,
|
||||
THT_WS_PSD_CLINICAL_VECTOR_WRITER_API_KEY_FILE: writerAlias,
|
||||
} },
|
||||
};
|
||||
|
||||
try {
|
||||
const result = await diagnose(adapters)(writerWorkspace, aliasedBindings, { writeProbe: true });
|
||||
expect(result.activatable).toBe(false);
|
||||
expect(adapters.writeDiagnosticRecord).not.toHaveBeenCalled();
|
||||
} finally {
|
||||
await rm(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("uses the declared POST DWH ping endpoint without exposing its local credential", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const credentialFile = join(directory, "dwh-api-key");
|
||||
@@ -403,6 +428,50 @@ test("uses the declared POST DWH ping endpoint without exposing its local creden
|
||||
}
|
||||
});
|
||||
|
||||
test("requires an authenticated TLS database query before direct diagnostics succeed", async () => {
|
||||
const directory = await mkdtemp(join(tmpdir(), "thothii-diagnostic-"));
|
||||
const passwordFile = join(directory, "password");
|
||||
const caFile = join(directory, "ca.pem");
|
||||
await Promise.all([writeFile(passwordFile, "password\n", { mode: 0o600 }), writeFile(caFile, "test-ca\n")]);
|
||||
const query = vi.fn(async () => ({ rows: [{ database: "warehouse", schema: "datawarehouse" }] }));
|
||||
const end = vi.fn(async () => undefined);
|
||||
const connect = vi.fn(async () => ({ query, end }));
|
||||
|
||||
try {
|
||||
const result = await createConcreteDiagnosticAdapters({ databaseClient: { connect } } as any).probeConnector({
|
||||
role: "dwh", transport: "postgres_direct", host: "127.0.0.1", port: 5432, user: "reader",
|
||||
credentialFile: passwordFile, tlsCaFile: caFile,
|
||||
resource: { database: "warehouse", schema: "datawarehouse" }, timeoutMs: 5000,
|
||||
signal: new AbortController().signal,
|
||||
});
|
||||
|
||||
expect(connect).toHaveBeenCalledWith(expect.objectContaining({ database: "warehouse", tlsCaFile: caFile }));
|
||||
expect(query).toHaveBeenCalledWith(expect.stringContaining("current_database"), []);
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
expect(result).toMatchObject({ authenticated: true, tlsVerified: true });
|
||||
} finally {
|
||||
await rm(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("honors a declared unauthenticated REST diagnostic without reading a credential", async () => {
|
||||
const fetchSpy = vi.fn(async () => new Response(JSON.stringify({ database: "warehouse", schema: "datawarehouse" }), {
|
||||
status: 200, headers: { "content-type": "application/json" },
|
||||
}));
|
||||
vi.stubGlobal("fetch", fetchSpy);
|
||||
try {
|
||||
await expect(createConcreteDiagnosticAdapters().probeConnector({
|
||||
role: "dwh", transport: "rest_api", baseUrl: "https://dwh.example.test",
|
||||
resource: { database: "warehouse", schema: "datawarehouse" }, timeoutMs: 5000,
|
||||
signal: new AbortController().signal,
|
||||
diagnostic: { method: "POST", path: "/rpc/ping", auth: "none", response: { database: "database", schema: "schema" } } as any,
|
||||
})).resolves.toMatchObject({ authenticated: true });
|
||||
expect(fetchSpy.mock.calls[0]?.[1]).not.toMatchObject({ headers: expect.objectContaining({ authorization: expect.anything() }) });
|
||||
} finally {
|
||||
vi.unstubAllGlobals();
|
||||
}
|
||||
});
|
||||
|
||||
test("constructs the production diagnoser with the configured timeout and injected adapters", async () => {
|
||||
const adapters = successfulAdapters();
|
||||
|
||||
@@ -430,3 +499,16 @@ test("retries bounded cleanup after a write-probe removal times out", async () =
|
||||
expect(result).toMatchObject({ activatable: false });
|
||||
expect(JSON.stringify(result)).not.toContain("timeout");
|
||||
});
|
||||
|
||||
test("attempts bounded cleanup when a timed-out write may already have created the record", async () => {
|
||||
const adapters = successfulAdapters({
|
||||
writeDiagnosticRecord: vi.fn(() => new Promise<void>(() => undefined)),
|
||||
});
|
||||
const diagnoseWithShortTimeout = createWorkspaceDiagnoser(adapters, { timeoutMs: 10 });
|
||||
|
||||
const result = await diagnoseWithShortTimeout(writerWorkspace, writerBindings, { writeProbe: true });
|
||||
|
||||
expect(adapters.writeDiagnosticRecord).toHaveBeenCalledOnce();
|
||||
expect(adapters.removeDiagnosticRecord).toHaveBeenCalledOnce();
|
||||
expect(result.activatable).toBe(false);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user