diff --git a/tests/test_app.py b/tests/test_app.py index 0b30b71..eb3be0d 100644 --- a/tests/test_app.py +++ b/tests/test_app.py @@ -46,6 +46,52 @@ def test_health_exposes_current_version(): assert response.json()["version"] == app.VERSION == "2.3.5" +def test_wireguard_status_returns_redacted_live_state(monkeypatch): + payload = { + "interface": "wg0", + "addresses": ["10.11.12.1/32"], + "listen_port": 37888, + "service_active": True, + "service_enabled": True, + "routes": [{"dst": "10.11.12.3", "prefsrc": "10.11.12.1"}], + "peers": [{ + "public_key": "peer-public-key", + "endpoint": "203.0.113.9:51820", + "allowed_ips": ["10.11.12.3/32"], + "latest_handshake": 123, + "rx_bytes": 456, + "tx_bytes": 789, + "persistent_keepalive": 25, + }], + } + monkeypatch.setattr(app, "_find_inventory_host", lambda host: {"user": "debian", "ip": "141.94.237.199"}) + monkeypatch.setattr(app, "_ssh", lambda host, command, timeout=30: (0, json.dumps(payload), "")) + + with TestClient(app.app) as client: + response = client.get( + "/network/wireguard/guck-vps", + headers={"Authorization": "Bearer test-token"}, + ) + + assert response.status_code == 200 + assert response.json()["host"] == "guck-vps" + assert response.json()["peers"][0]["allowed_ips"] == ["10.11.12.3/32"] + assert "private" not in response.text.lower() + + +def test_wireguard_status_rejects_unknown_host_without_ssh(monkeypatch): + monkeypatch.setattr(app, "_find_inventory_host", lambda host: None) + monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (_ for _ in ()).throw(AssertionError("SSH must not run"))) + + with TestClient(app.app) as client: + response = client.get( + "/network/wireguard/does-not-exist", + headers={"Authorization": "Bearer test-token"}, + ) + + assert response.status_code == 404 + + def test_tts_generate_returns_cloned_wav(monkeypatch): captured = {}