e9e6300cfc
gates / gates (push) Successful in 4m35s
Read phase passes (Page 1360018983863273, CREATE_CONTENT/MODERATE/ANALYZE, page token PAGE expires_at 0, three insights metrics alive on v26.0). Write test: removal check accepts Meta's code-10 'Object does not exist' (fixed without a row, 4 tests); run 1 evidence kept. R-914 READY, R-915 narrowed to Live mode.
86 lines
2.9 KiB
Python
86 lines
2.9 KiB
Python
#!/usr/bin/env python3
|
|
# -*- coding: utf-8 -*-
|
|
"""Tests for fb_probe.py's two secret-handling seams: the key loader (R-453) and redact()."""
|
|
import os
|
|
import sys
|
|
import tempfile
|
|
import unittest
|
|
|
|
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
|
import fb_probe # noqa: E402
|
|
from read_credential import CredentialError # noqa: E402
|
|
|
|
FAKE = "EAAfakeprobe0123456789abcdef"
|
|
|
|
|
|
def creds(text):
|
|
fd, p = tempfile.mkstemp()
|
|
with os.fdopen(fd, "w") as fh:
|
|
fh.write(text)
|
|
return p
|
|
|
|
|
|
class LoadKey(unittest.TestCase):
|
|
def load(self, text):
|
|
p = creds(text)
|
|
try:
|
|
return fb_probe.load_key(p)
|
|
finally:
|
|
os.unlink(p)
|
|
|
|
def test_single_quotes(self):
|
|
self.assertEqual(self.load("OTHER='x'\nFACEBOOK_API='%s'\n" % FAKE), FAKE)
|
|
|
|
def test_double_quotes_and_export(self):
|
|
self.assertEqual(self.load('export FACEBOOK_API="%s"\n' % FAKE), FAKE)
|
|
|
|
def test_trailing_whitespace_stripped(self):
|
|
self.assertEqual(self.load("FACEBOOK_API='%s' \n" % FAKE), FAKE)
|
|
|
|
def test_mismatched_quote_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_API='%s\"\n" % FAKE)
|
|
|
|
def test_inner_whitespace_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_API='EAA abc'\n")
|
|
|
|
def test_not_a_meta_token_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_API='xyz123'\n")
|
|
|
|
def test_missing_key_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_APIX='%s'\n" % FAKE)
|
|
|
|
|
|
class Redact(unittest.TestCase):
|
|
def test_access_token_key_dropped_everywhere(self):
|
|
out = fb_probe.redact({"data": [{"id": "1", "access_token": "zzz"}], "access_token": "y"}, secrets=[])
|
|
self.assertEqual(out, {"data": [{"id": "1"}]})
|
|
|
|
def test_held_secret_and_token_shape_replaced(self):
|
|
out = fb_probe.redact({"a": "pre-sekret-post", "b": "x " + FAKE, "c": "fine"}, secrets=["sekret"])
|
|
self.assertEqual(out, {"a": "[REDACTED]", "b": "[REDACTED]", "c": "fine"})
|
|
|
|
def test_hungarian_text_survives(self):
|
|
self.assertEqual(fb_probe.redact(fb_probe.TEST_TEXT, secrets=[]), fb_probe.TEST_TEXT)
|
|
|
|
|
|
class GoneError(unittest.TestCase):
|
|
def test_measured_code_10_does_not_exist(self):
|
|
self.assertTrue(fb_probe.gone_error({"code": 10, "message": "(#10) Object does not exist, cannot be loaded due to missing permission"}))
|
|
|
|
def test_code_100(self):
|
|
self.assertTrue(fb_probe.gone_error({"code": 100, "message": "Unsupported get request"}))
|
|
|
|
def test_other_code_10_is_not_removal(self):
|
|
self.assertFalse(fb_probe.gone_error({"code": 10, "message": "(#10) Application does not have permission"}))
|
|
|
|
def test_success_body_is_not_removal(self):
|
|
self.assertFalse(fb_probe.gone_error(None))
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|