68 lines
2.9 KiB
Python
68 lines
2.9 KiB
Python
#!/usr/bin/env python3
|
|
"""Mutation fixtures for current auth/DWH documentation; never contacts services."""
|
|
import importlib.util
|
|
import shutil
|
|
import subprocess
|
|
import sys
|
|
import tempfile
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parent.parent
|
|
SCRIPT = ROOT / "scripts/verify-auth-docs.py"
|
|
spec = importlib.util.spec_from_file_location("authdocs", SCRIPT)
|
|
module = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(module)
|
|
mode = sys.argv[1] if len(sys.argv) > 1 else "auth"
|
|
assert mode in ("auth", "dwh")
|
|
relative = next(iter(module.AUTH if mode == "auth" else module.DWH))
|
|
|
|
with tempfile.TemporaryDirectory(prefix="thoth-auth-docs-") as tmp:
|
|
fixture = Path(tmp)
|
|
shutil.copytree(ROOT / "docs", fixture / "docs")
|
|
for item in ROOT.glob("*.md"):
|
|
shutil.copy2(item, fixture / item.name)
|
|
target = fixture / relative
|
|
original = target.read_text()
|
|
|
|
def check(expected=None):
|
|
result = subprocess.run([sys.executable, str(SCRIPT), mode, "--root", tmp], capture_output=True, text=True)
|
|
if expected is None:
|
|
assert result.returncode == 0, result.stderr
|
|
else:
|
|
assert result.returncode != 0 and expected in result.stderr, result.stderr
|
|
|
|
check()
|
|
mutations = [
|
|
("curl -k https://example.invalid", "TLS bypass"),
|
|
("curl --insecure https://example.invalid", "TLS bypass"),
|
|
("verify_tls=false", "TLS bypass"),
|
|
("DWH_API_KEY=synthetic", "raw environment secret"),
|
|
('curl -H "X-API-Key: synthetic" https://example.invalid', "raw key header"),
|
|
("tht auth user add demo --password synthetic", "secret argument"),
|
|
("password: synthetic", "plaintext password"),
|
|
("chmod 644 /protected/demo.key", "world-readable secret"),
|
|
("sudo nginx -T", "raw nginx capture"),
|
|
("git diff /protected/secret", "raw diff capture"),
|
|
("docker compose up dwh-auth", "Compose coupling"),
|
|
("thtdwh_v1." + "a" * 16 + "." + "b" * 43, "credential literal"),
|
|
("secret_sha256: " + "a" * 64, "credential digest"),
|
|
("auth-canonical:/run/thothii-auth:ro", "canonical auth root"),
|
|
("useradd --uid 10001 core", "host runtime identity"),
|
|
("nano /protected/generations/one/auth.yaml", "direct auth projection edit"),
|
|
]
|
|
for snippet, error in mutations:
|
|
target.write_text(original + "\n```sh\n" + snippet + "\n```\n")
|
|
check(error)
|
|
target.write_text(original + '\nDo not use `curl -k`.\n```sh\nDWH_API_KEY_FILE=/protected/demo.key\n```\n')
|
|
check()
|
|
if mode == "auth":
|
|
target.write_text(original.replace("`memory.manage`, ", ""))
|
|
check("role-to-permission")
|
|
target.write_text(original.replace("auth_ready\n", "auth_unknown\n"))
|
|
check("diagnostic code")
|
|
target.write_text(original + "\n[broken](missing-file.md)\n")
|
|
check("broken local link")
|
|
target.unlink()
|
|
check("missing")
|
|
print(f"{mode} documentation mutation fixtures passed")
|