fix(auth): close Windows remediation review findings
This commit is contained in:
@@ -10,6 +10,7 @@ import (
|
||||
"io"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
@@ -43,6 +44,7 @@ func TestPreflightReturnsValidatedMetadataAndCallsAllTargetChecksWithoutExtracti
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
defer result.CloseArchive()
|
||||
if result.Manifest.InstallationID != "local-dev" || result.Manifest.Entries[0].Path != "configuration/operator.env" {
|
||||
t.Fatalf("validated metadata = %#v", result)
|
||||
}
|
||||
@@ -197,10 +199,11 @@ func TestPreflightRequiresExplicitProtectionForExternalSecretPayloadsWithoutLeak
|
||||
if err == nil || strings.Contains(err.Error(), string(secret)) || !strings.Contains(err.Error(), "confirmation") {
|
||||
t.Fatalf("secret policy error = %v", err)
|
||||
}
|
||||
_, err = Preflight(context.Background(), installation, PreflightRequest{Archive: archive, Confirm: true, AllowExternalSecrets: true}, permissivePreflightDependencies())
|
||||
result, err := Preflight(context.Background(), installation, PreflightRequest{Archive: archive, Confirm: true, AllowExternalSecrets: true}, permissivePreflightDependencies())
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
defer result.CloseArchive()
|
||||
}
|
||||
|
||||
func TestPreflightRejectsInsufficientDiskAndEachTargetCompatibilityFailure(t *testing.T) {
|
||||
@@ -392,6 +395,17 @@ func TestPreflightRevalidationRefusesAnArchivePathThatWasReplaced(t *testing.T)
|
||||
writePreflightArchive(t, replacement, preflightArchiveSpec{
|
||||
entries: []preflightArchiveEntry{{path: "configuration/operator.env", body: []byte("unchecked")}},
|
||||
})
|
||||
if runtime.GOOS == "windows" {
|
||||
// The retained validated handle denies replacement on Windows; that is the
|
||||
// stronger invariant, so revalidation must still succeed for the unchanged path.
|
||||
if err := os.Rename(replacement, archive); err == nil {
|
||||
t.Fatal("Windows replaced a retained archive path")
|
||||
}
|
||||
if _, err := result.RevalidateArchive(); err != nil {
|
||||
t.Fatalf("RevalidateArchive() on retained Windows archive = %v", err)
|
||||
}
|
||||
return
|
||||
}
|
||||
if err := os.Rename(replacement, archive); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user