fix: require signed evidence provenance
This commit is contained in:
@@ -128,6 +128,18 @@ def test_signed_http_file_requires_explicit_provenance_urls(tmp_path):
|
|||||||
assert_no_canaries(caught.value)
|
assert_no_canaries(caught.value)
|
||||||
|
|
||||||
|
|
||||||
|
def test_signed_http_file_rejects_explicit_null_provenance(tmp_path):
|
||||||
|
secret_file = tmp_path / "signed-urls.json"
|
||||||
|
secret_file.write_text(json.dumps(["https://evidence.example.test/guide.md"]))
|
||||||
|
path = write_config(tmp_path, {
|
||||||
|
"type": "http", "provenance_urls": None, "signed_urls_file": str(secret_file),
|
||||||
|
})
|
||||||
|
|
||||||
|
with pytest.raises(ConfigError) as caught:
|
||||||
|
load_config(path)
|
||||||
|
assert "provenance" in str(caught.value).lower()
|
||||||
|
|
||||||
|
|
||||||
def test_public_http_rejects_inline_query_bearing_transport_urls(tmp_path):
|
def test_public_http_rejects_inline_query_bearing_transport_urls(tmp_path):
|
||||||
path = write_config(tmp_path, {
|
path = write_config(tmp_path, {
|
||||||
"type": "http",
|
"type": "http",
|
||||||
|
|||||||
@@ -60,7 +60,12 @@ def _resolve_http_signed_url_files(value: Any) -> Any:
|
|||||||
return resolved
|
return resolved
|
||||||
if "urls" in resolved:
|
if "urls" in resolved:
|
||||||
raise ConfigError("HTTP signed URL file cannot be combined with urls")
|
raise ConfigError("HTTP signed URL file cannot be combined with urls")
|
||||||
if "provenance_urls" not in resolved:
|
provenance_urls = resolved.get("provenance_urls")
|
||||||
|
if (
|
||||||
|
not isinstance(provenance_urls, list)
|
||||||
|
or not provenance_urls
|
||||||
|
or any(not isinstance(item, str) or not item for item in provenance_urls)
|
||||||
|
):
|
||||||
raise ConfigError("HTTP signed URL file requires provenance_urls")
|
raise ConfigError("HTTP signed URL file requires provenance_urls")
|
||||||
path_value = resolved.pop("signed_urls_file")
|
path_value = resolved.pop("signed_urls_file")
|
||||||
if not isinstance(path_value, str):
|
if not isinstance(path_value, str):
|
||||||
|
|||||||
Reference in New Issue
Block a user