78 lines
2.9 KiB
Bash
Executable File
78 lines
2.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
root=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)
|
|
verify="$root/scripts/verify-dwh-auth-docs.sh"
|
|
temp_root=
|
|
|
|
report_pass() {
|
|
printf 'case=%s status=PASS\n' "$1"
|
|
}
|
|
|
|
report_fail() {
|
|
printf 'case=%s status=FAIL\n' "$1" >&2
|
|
exit 1
|
|
}
|
|
|
|
cleanup() {
|
|
if [[ "$temp_root" == /tmp/thothii-dwh-auth-docs.* && -d "$temp_root" ]]; then
|
|
rm -rf -- "$temp_root"
|
|
fi
|
|
}
|
|
trap cleanup EXIT
|
|
|
|
[[ -x "$verify" ]] || report_fail verifier_missing
|
|
|
|
temp_root=$(mktemp -d /tmp/thothii-dwh-auth-docs.XXXXXXXX) || report_fail fixture_root
|
|
fixture_root="$temp_root/fixture"
|
|
mkdir -p "$fixture_root/docs/install" "$fixture_root/docs/operations" \
|
|
"$fixture_root/docs/testing/evidence" "$fixture_root/scripts"
|
|
|
|
for relative in \
|
|
docs/install/dwh-auth-server.md \
|
|
docs/install/dwh-auth-client-enrollment.md \
|
|
docs/install/dwh-auth-tls.md \
|
|
docs/operations/psd-dwh-auth-rollout.md \
|
|
docs/testing/dwh-auth-manual-acceptance.md \
|
|
docs/testing/evidence/psd-dwh-auth-rollout-report-template.md \
|
|
docs/install/local-workspace-registry.md \
|
|
docs/install/server-workspace-registry.md \
|
|
docs/install/psd-workspace-setup.md \
|
|
docs/guida-utente.md \
|
|
docs/index.md \
|
|
mkdocs.yml; do
|
|
mkdir -p "$fixture_root/$(dirname "$relative")"
|
|
cp "$root/$relative" "$fixture_root/$relative"
|
|
done
|
|
cp -a "$root/docs/." "$fixture_root/docs/"
|
|
|
|
"$verify" --root "$fixture_root" || report_fail positive_source
|
|
report_pass positive_source
|
|
|
|
expect_rejected() {
|
|
local name=$1 target=$2 addition=$3
|
|
local case_root="$temp_root/$name"
|
|
cp -a "$fixture_root" "$case_root"
|
|
printf '\n%s\n' "$addition" >>"$case_root/$target"
|
|
if "$verify" --root "$case_root" >/dev/null 2>&1; then
|
|
report_fail "$name"
|
|
fi
|
|
report_pass "$name"
|
|
}
|
|
|
|
# Build synthetic only-in-fixture text at runtime: it is never a provisioned credential.
|
|
fake_key="thtdwh_v1.$(printf 'A%.0s' {1..16}).$(printf 'A%.0s' {1..43})"
|
|
fake_digest="$(printf 'A%.0s' {1..43})"
|
|
|
|
expect_rejected credential_literal docs/install/dwh-auth-client-enrollment.md "$fake_key"
|
|
expect_rejected credential_digest_literal docs/testing/evidence/psd-dwh-auth-rollout-report-template.md "secret_sha256: $fake_digest"
|
|
expect_rejected curl_insecure docs/install/dwh-auth-tls.md 'curl -k https://example.invalid/dwh/rpc/ping'
|
|
expect_rejected tls_disabled docs/install/dwh-auth-tls.md 'verify_tls=false'
|
|
expect_rejected secret_in_environment docs/install/dwh-auth-client-enrollment.md "DWH_API_KEY=$fake_key"
|
|
expect_rejected secret_in_argv docs/install/dwh-auth-client-enrollment.md "curl -H 'X-API-Key: $fake_key' https://example.invalid/dwh/rpc/ping"
|
|
expect_rejected world_readable_secret docs/install/dwh-auth-server.md 'chmod 0644 /root/dwh-auth-provision/client.key'
|
|
expect_rejected raw_nginx_capture docs/operations/psd-dwh-auth-rollout.md 'nginx -T > /tmp/nginx-full.conf'
|
|
expect_rejected compose_coupling docs/install/dwh-auth-server.md 'docker compose up dwh-auth'
|
|
|
|
report_pass summary
|