R-890: the test box (scratch 9202) may seed vaultwarden through its admin invite, inside the box
gates / gates (push) Successful in 7s
gates / gates (push) Successful in 7s
`09` §3 decision 149. box_admin_seed_allowed(): not the bench, FELHOM_BOX_ADMIN_SEED=1, demo-hp/9202 only, an app this run installed, the box on the drill catalog. The token is read inside the box and handed to curl on stdin; only HTTP codes come back. Tests: BoxAdminSeedGuard (red-proved). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -259,6 +259,97 @@ class BenchAdminSeedGuard(unittest.TestCase):
|
||||
self.assertFalse(any(ADMIN in s or "jwt.admin.session" in s for s in self.said), "a secret was printed")
|
||||
|
||||
|
||||
class FakeBoxWalk(FakeVenue):
|
||||
"""box_walk's interface on a test box: no VENUE, HP/GUEST, the run's installs, and guest() that answers like the
|
||||
in-box admin invite script would. Records every script sent into the box."""
|
||||
|
||||
def __init__(self, hp="demo-hp", guest="9202", deployed=("vaultwarden",), drill=True, invite="RESULT signin=200 session=yes invite=200"):
|
||||
FakeVenue.__init__(self, False)
|
||||
self.GENERATED = {}
|
||||
self.HP, self.GUEST, self.DEPLOYED_THIS_RUN = hp, guest, set(deployed)
|
||||
self.drill, self.invite, self.scripts = drill, invite, []
|
||||
|
||||
def guest(self, script, timeout=600):
|
||||
self.scripts.append(script)
|
||||
if "controller.yaml" in script:
|
||||
return ("git:\n repo_url: https://gitea.dooplex.hu/admin/%s.git\n"
|
||||
% ("app-catalog-drill" if self.drill else "app-catalog-felhom.eu"))
|
||||
if "/admin/invite" in script:
|
||||
m = __import__("re").search(r'"email":"([^"]+)"', script)
|
||||
if self.invite.endswith("invite=200"):
|
||||
self.invited.add(m.group(1))
|
||||
return "some noise\n" + self.invite + "\n"
|
||||
return ""
|
||||
|
||||
|
||||
class BoxAdminSeedGuard(unittest.TestCase):
|
||||
"""R-890 (`09` §3 decision 149): the admin seed on a TEST BOX — scratch 9202 on demo-hp, an app this run installed,
|
||||
the box on the drill catalog, the run opted in. RED-PROOF (REPORT): make box_admin_seed_allowed return (True, "") —
|
||||
test_each_condition_alone_refuses and test_a_household_shaped_box_is_never_seeded fail."""
|
||||
|
||||
ENV = {"FELHOM_BOX_ADMIN_SEED": "1"}
|
||||
|
||||
def allowed(self, w, env):
|
||||
with mock.patch.dict(os.environ, env, clear=False):
|
||||
if "FELHOM_BOX_ADMIN_SEED" not in env:
|
||||
os.environ.pop("FELHOM_BOX_ADMIN_SEED", None)
|
||||
return fxbox.box_admin_seed_allowed(w, "vaultwarden")
|
||||
|
||||
def test_all_conditions_allow(self):
|
||||
self.assertEqual(self.allowed(FakeBoxWalk(), self.ENV), (True, ""))
|
||||
|
||||
def test_each_condition_alone_refuses(self):
|
||||
cases = [(FakeVenue(True), self.ENV, "bench venue"),
|
||||
(FakeBoxWalk(), {}, "FELHOM_BOX_ADMIN_SEED"),
|
||||
(FakeBoxWalk(), {"FELHOM_BOX_ADMIN_SEED": "yes"}, "FELHOM_BOX_ADMIN_SEED"),
|
||||
(FakeBoxWalk(guest="9201"), self.ENV, "not a test box"),
|
||||
(FakeBoxWalk(hp="demo-felhom"), self.ENV, "not a test box"),
|
||||
(FakeBoxWalk(deployed=()), self.ENV, "did not install"),
|
||||
(FakeBoxWalk(drill=False), self.ENV, "drill catalog")]
|
||||
for w, env, want in cases:
|
||||
ok, why = self.allowed(w, env)
|
||||
self.assertFalse(ok, want)
|
||||
self.assertIn(want, why)
|
||||
|
||||
def seed(self, w, env):
|
||||
with mock.patch.dict(os.environ, env, clear=False):
|
||||
if "FELHOM_BOX_ADMIN_SEED" not in env:
|
||||
os.environ.pop("FELHOM_BOX_ADMIN_SEED", None)
|
||||
os.environ.pop("FELHOM_BENCH_ADMIN_SEED", None)
|
||||
fx_ = fxbox.Vaultwarden()
|
||||
return fx_, fx_.seed(w, "vault", lambda *a: None)
|
||||
|
||||
def test_the_test_box_seeds_through_the_invite_inside_the_box(self):
|
||||
w = FakeBoxWalk()
|
||||
_, got = self.seed(w, self.ENV)
|
||||
self.assertIsNotNone(got)
|
||||
self.assertEqual([c["path"] for c in w.calls], ["/identity/accounts/register", "/identity/accounts/register"])
|
||||
inv = [x for x in w.scripts if "/admin/invite" in x]
|
||||
self.assertEqual(len(inv), 1)
|
||||
# the token is read inside the box and handed to curl on stdin; the cookie file is shredded
|
||||
self.assertIn("printenv ADMIN_TOKEN", inv[0])
|
||||
self.assertIn("token@-", inv[0])
|
||||
self.assertIn('shred -u "$H"', inv[0])
|
||||
self.assertIn(got["email"], inv[0])
|
||||
|
||||
def test_a_household_shaped_box_is_never_seeded(self):
|
||||
for w in (FakeBoxWalk(guest="9201"), FakeBoxWalk(deployed=()), FakeBoxWalk(drill=False)):
|
||||
fx_, got = self.seed(w, self.ENV)
|
||||
self.assertIsNone(got)
|
||||
self.assertFalse([x for x in w.scripts if "/admin/invite" in x], "the admin route was tried")
|
||||
self.assertIn("NOT tried", fx_.tried)
|
||||
|
||||
def test_a_refused_invite_is_inconclusive(self):
|
||||
w = FakeBoxWalk(invite="RESULT signin=401 session=no")
|
||||
fx_, got = self.seed(w, self.ENV)
|
||||
self.assertIsNone(got)
|
||||
self.assertIn("test-box admin invite", fx_.tried)
|
||||
|
||||
def test_only_a_drill_address_is_invited(self):
|
||||
with self.assertRaises(ValueError):
|
||||
fxbox.box_admin_invite(FakeBoxWalk(), 'x"}; rm -rf /; {"@gate.invalid')
|
||||
|
||||
|
||||
class SecretHygiene(unittest.TestCase):
|
||||
"""The run's secrets: .env 0600 and shredded, every evidence file redacted. RED-PROOF (REPORT): make redact_tree
|
||||
return [] without rewriting — test_evidence_files_are_redacted fails."""
|
||||
|
||||
Reference in New Issue
Block a user