Hetzner-DNS-Vaultalias sicher auflösen: tests/test_app.py

This commit is contained in:
sascha 2026-08-14 10:34:29 +02:00
parent 5d68ff90a8
commit 90021b5a48

View file

@ -277,6 +277,13 @@ def test_dns_rrset_dry_run_returns_only_selected_records(monkeypatch):
assert body["deleted"] == [] assert body["deleted"] == []
def test_hetzner_dns_token_accepts_single_sanitized_vault_alias(monkeypatch):
monkeypatch.setattr(app, "_vault_cache", {"hetzner-dns-api": "secret-value", "other": "ignored"})
monkeypatch.setattr(app, "_read", lambda _name: None)
monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (_ for _ in ()).throw(AssertionError("must not sync vault")))
assert app._get_hetzner_dns_token() == "secret-value"
def test_invalid_log_target_is_rejected_before_ssh(): def test_invalid_log_target_is_rejected_before_ssh():
with TestClient(app.app) as client: with TestClient(app.app) as client:
response = client.get( response = client.get(