Add live capabilities and safety map (#40)
This commit is contained in:
parent
f2c5fa7051
commit
c7dd2ea972
2 changed files with 103 additions and 0 deletions
|
|
@ -46,6 +46,33 @@ def test_health_exposes_current_version():
|
|||
assert response.json()["version"] == app.VERSION == "2.3.5"
|
||||
|
||||
|
||||
def test_capabilities_is_live_machine_readable_safety_map():
|
||||
with TestClient(app.app) as client:
|
||||
response = client.get(
|
||||
"/capabilities",
|
||||
headers={"Authorization": "Bearer test-token"},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
payload = response.json()
|
||||
by_operation = {(item["method"], item["path"]): item for item in payload["operations"]}
|
||||
assert ("GET", "/network/wireguard/{host}") in by_operation
|
||||
assert by_operation[("GET", "/network/wireguard/{host}")]["mode"] == "read_only"
|
||||
removal = by_operation[("DELETE", "/network/wireguard/{host}/peer")]
|
||||
assert removal["mode"] == "mutation"
|
||||
assert removal["dry_run"] is True
|
||||
assert removal["critical"] is True
|
||||
assert by_operation[("DELETE", "/vm/destroy/{vmid}")]["dry_run"] is True
|
||||
assert all(item["path"] != "/{service}/{path}" for item in payload["operations"])
|
||||
assert payload["model_contract"]["instruction"].startswith("Prefer read_only")
|
||||
|
||||
|
||||
def test_info_advertises_capabilities_endpoint():
|
||||
with TestClient(app.app) as client:
|
||||
response = client.get("/info", headers={"Authorization": "Bearer test-token"})
|
||||
assert response.status_code == 200
|
||||
assert response.json()["endpoints"]["capabilities"] == "/capabilities"
|
||||
|
||||
|
||||
def test_wireguard_status_returns_redacted_live_state(monkeypatch):
|
||||
payload = {
|
||||
"interface": "wg0",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue