Files
felhom.eu/documentation/audits/r890-instructions-2026-10-06/tools/wgerwalk.py
T

63 lines
3.7 KiB
Python

"""wgerwalk.py — R-763 / R-764 / R-762 on scratch 9202 (drill catalog = live + wger un-hidden, DRILL only).
Install wger through the product, then, STRAIGHT AT THE APP inside the box (a stranger who got past the box's own gate —
the strictest case; the family gate would stop him first): the sign-up page and form, two anonymous dashboard visits,
the user count before and after (wger's own ORM). The settings wger read (its own process). The static and media read
(R-762). Removed through the product at the end. Evidence: ../C/wger.txt."""
import os, sys
sys.path.insert(0, "/mnt/5_hdd/felhom.eu/git/app-catalog-felhom.eu/scripts")
import box_walk as w
HERE = os.path.dirname(os.path.abspath(__file__))
log = open(os.path.join(HERE, "..", "C", "wger.txt"), "a", buffering=1)
def say(*a):
w.say(*a); log.write(" ".join(map(str, a)) + "\n")
ORM = ("cd /home/wger/src && DJANGO_SETTINGS_MODULE=settings.main python3 -c "
"\"import django; django.setup(); from django.contrib.auth.models import User; print('USERS', User.objects.count())\"")
SETTINGS = ("cd /home/wger/src && DJANGO_SETTINGS_MODULE=settings.main python3 -c "
"\"import django; django.setup(); from django.conf import settings as s; "
"print('ALLOW_REGISTRATION', s.WGER_SETTINGS.get('ALLOW_REGISTRATION'), 'ALLOW_GUEST_USERS', s.WGER_SETTINGS.get('ALLOW_GUEST_USERS'), "
"'EMAIL_BACKEND', s.EMAIL_BACKEND, 'DEBUG', s.DEBUG)\"")
def users():
out = w.guest(f"docker exec wger sh -c '{ORM}' 2>&1 | tail -1")
return out.strip()
STRANGER = r"""set -u
ip=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}} {{end}}' wger | awk '{print $1}')
H="Host: fitness.enkisfelhom.hu"; P="X-Forwarded-Proto: https"
J=$(mktemp)
echo "GET registration: $(curl -s -o /dev/null -c $J -b $J -H "$H" -H "$P" -w '%{http_code} %{redirect_url}' http://$ip:8000/en/user/registration)"
tok=$(grep csrftoken $J | awk '{print $7}')
echo "POST registration: $(curl -s -o /dev/null -c $J -b $J -H "$H" -H "$P" -H "Referer: https://fitness.enkisfelhom.hu/en/user/registration" -w '%{http_code} %{redirect_url}' --data "csrfmiddlewaretoken=$tok&username=stranger1&email=stranger1@gate.invalid&password1=Str4nger-Pass-991&password2=Str4nger-Pass-991" http://$ip:8000/en/user/registration)"
rm -f $J
for i in 1 2; do echo "anonymous GET dashboard $i: $(curl -s -o /dev/null -H "$H" -H "$P" -w '%{http_code} %{redirect_url}' http://$ip:8000/en/dashboard)"; done
echo "static css: $(curl -s -o /dev/null -H "$H" -H "$P" -w '%{http_code}' http://$ip:8000/static/css/workout-manager.css)"
echo "static root size: $(docker exec wger du -sh /home/wger/static 2>&1 | tail -1)"
"""
w.login()
w.sync_rescan("wger")
st = w.stack("wger")
say(f"lifecycle on the box: {(st.get('metadata') or {}).get('lifecycle')} deployed={st.get('deployed')}")
if not w.deploy("wger", "fitness"):
sys.exit(say("RESULT install did not complete") or 1)
w.wait_app("fitness", "/", tries=60)
say("settings read by wger's own process:", w.guest(f"docker exec wger sh -c \"{SETTINGS}\" 2>&1 | tail -1").strip())
say("before:", users())
for line in w.guest(STRANGER).strip().splitlines():
say(" stranger, straight at the app:", line)
say("after:", users())
say("stranger account exists:", w.guest("docker exec wger sh -c \"cd /home/wger/src && DJANGO_SETTINGS_MODULE=settings.main python3 -c "
"\\\"import django; django.setup(); from django.contrib.auth.models import User; "
"print('STRANGER', User.objects.filter(username='stranger1').exists())\\\"\" 2>&1 | tail -1").strip())
say("restarts:", w.guest("docker inspect -f '{{.RestartCount}} {{.State.Health.Status}}' wger").strip())
if not os.environ.get("KEEP"):
say(f"remove -> {w.remove('wger')}")