59 lines
2.4 KiB
Bash
Executable File
59 lines
2.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
|
|
scanner="$repo_root/scripts/test-dwh-auth-secret-scan.sh"
|
|
tmp_parent=${TMPDIR:-/tmp}
|
|
fixture_parent=$(mktemp -d "$tmp_parent/thothii-dwh-auth-secret-scan-contract.XXXXXX")
|
|
fixture_root="$fixture_parent/root"
|
|
outside_root="$fixture_parent/outside"
|
|
|
|
cleanup() {
|
|
case "$fixture_parent" in
|
|
"$tmp_parent"/thothii-dwh-auth-secret-scan-contract.*) rm -rf -- "$fixture_parent" ;;
|
|
*) printf '%s\n' 'secret scan contract cleanup refused' >&2; return 1 ;;
|
|
esac
|
|
}
|
|
trap cleanup EXIT HUP INT TERM
|
|
|
|
fail() {
|
|
printf 'case=%s status=FAIL\n' "$1" >&2
|
|
exit 1
|
|
}
|
|
|
|
run_scanner() {
|
|
local root=$1 stdout=$2 stderr=$3
|
|
set +e
|
|
"$scanner" --root "$root" >"$stdout" 2>"$stderr"
|
|
scan_status=$?
|
|
set -e
|
|
}
|
|
|
|
mkdir -p "$fixture_root" "$outside_root" || fail fixture_directories
|
|
chmod 0700 "$fixture_parent" "$fixture_root" "$outside_root" || fail fixture_directories
|
|
|
|
credential="$(printf 'thtdwh_v1.%s.%s' "$(printf 'A%.0s' {1..16})" "$(printf 'B%.0s' {1..43})")"
|
|
printf '%s\n' "$credential" >"$fixture_root/full-format-fixture.txt"
|
|
printf '%s\n' "$credential" >"$outside_root/outside-fixture.txt"
|
|
|
|
run_scanner "$fixture_root" "$fixture_root/negative.stdout" "$fixture_root/negative.stderr"
|
|
[[ "$scan_status" -eq 1 ]] || fail detects_full_format
|
|
[[ ! -s "$fixture_root/negative.stdout" ]] || fail detects_full_format
|
|
[[ "$(<"$fixture_root/negative.stderr")" == 'dwh-auth credential literal scan failed' ]] || fail detects_full_format
|
|
! grep -Fq -- "$credential" "$fixture_root/negative.stdout" "$fixture_root/negative.stderr" || fail detects_full_format
|
|
printf 'case=detects_full_format status=PASS\n'
|
|
|
|
rm -f -- "$fixture_root/full-format-fixture.txt"
|
|
run_scanner "$fixture_root" "$fixture_root/clean.stdout" "$fixture_root/clean.stderr"
|
|
[[ "$scan_status" -eq 0 ]] || fail clean_fixture
|
|
[[ "$(<"$fixture_root/clean.stdout")" == 'dwh-auth credential literal scan passed' ]] || fail clean_fixture
|
|
[[ ! -s "$fixture_root/clean.stderr" ]] || fail clean_fixture
|
|
printf 'case=clean_fixture status=PASS\n'
|
|
|
|
run_scanner "$fixture_parent/missing" "$fixture_root/error.stdout" "$fixture_root/error.stderr"
|
|
[[ "$scan_status" -ne 0 ]] || fail invalid_root
|
|
! grep -Fq -- "$credential" "$fixture_root/error.stdout" "$fixture_root/error.stderr" || fail invalid_root
|
|
printf 'case=invalid_root status=PASS\n'
|
|
|
|
printf 'case=summary status=PASS\n'
|