diff --git a/tests/test_app.py b/tests/test_app.py index 8c32eb7..b5db980 100644 --- a/tests/test_app.py +++ b/tests/test_app.py @@ -201,6 +201,45 @@ def test_host_forensics_rejects_unknown_host_and_invalid_window(monkeypatch): assert bad_window.status_code == 422 +def test_docker_residue_cleanup_defaults_to_dry_run(monkeypatch): + payload = {"dry_run": True, "before_rule_count": 25, "removed_rules": [], "removed_chains": [], "removed_links": [], "removed_paths": [], "errors": []} + calls = [] + monkeypatch.setattr(app, "_find_inventory_host", lambda name: {"name": name, "user": "root", "ip": "10.5.85.13"}) + monkeypatch.setattr(app, "_ssh", lambda host, command, timeout=600: (calls.append((host, command, timeout)) or (0, __import__("json").dumps(payload), ""))) + with TestClient(app.app) as client: + response = client.post("/system/cleanup/docker-residue/node3", headers={"Authorization": "Bearer test-token"}) + assert response.status_code == 200 + assert response.json()["dry_run"] is True + assert calls[0][0] == "root@10.5.85.13" + assert calls[0][2] == 90 + + +def test_docker_residue_cleanup_refuses_active_docker(monkeypatch): + payload = {"dry_run": False, "error": "Docker or containerd is still installed/active; refusing residue cleanup"} + monkeypatch.setattr(app, "_find_inventory_host", lambda name: {"name": name, "user": "root", "ip": "10.5.85.13"}) + monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (2, __import__("json").dumps(payload), "")) + with TestClient(app.app) as client: + response = client.post("/system/cleanup/docker-residue/node3?dry_run=false", headers={"Authorization": "Bearer test-token"}) + assert response.status_code == 409 + + +def test_iso_builder_restore_defaults_to_dry_run_and_has_no_free_target(monkeypatch): + payload = {"dry_run": True, "restored": [], "removed_outputs": [], "validation": {}} + calls = [] + monkeypatch.setattr(app, "_ssh", lambda host, command, timeout=600: (calls.append((host, command, timeout)) or (0, __import__("json").dumps(payload), ""))) + with TestClient(app.app) as client: + response = client.post("/system/restore/iso-builder", headers={"Authorization": "Bearer test-token"}) + assert response.status_code == 200 + assert response.json()["dry_run"] is True + assert calls[0][0] == app.AUTOMATION1 + assert calls[0][2] == 120 + command = app._iso_builder_restore_command(True) + encoded = command.split("base64.b64decode('", 1)[1].split("')", 1)[0] + decoded = __import__("base64").b64decode(encoded).decode() + assert "origin/master" in decoded + assert "/app-config/ansible" in decoded + + def test_invalid_log_target_is_rejected_before_ssh(): with TestClient(app.app) as client: response = client.get(