Sichere Entfernung stillgelegter Uptime-Monitore #36

Merged
sascha merged 2 commits from feat/safe-uptime-monitor-removal-20260814 into main 2026-08-14 10:49:04 +02:00
Showing only changes of commit c40e869ef8 - Show all commits

View file

@ -1,5 +1,6 @@
import os
import asyncio
import json
import time
from datetime import datetime, timedelta, timezone
@ -278,10 +279,27 @@ def test_dns_rrset_dry_run_returns_only_selected_records(monkeypatch):
def test_hetzner_dns_token_accepts_single_sanitized_vault_alias(monkeypatch):
monkeypatch.setattr(app, "_vault_cache", {"hetzner-dns-api": "secret-value", "other": "ignored"})
token = "a" * 48
monkeypatch.setattr(app, "_vault_cache", {"hetzner-dns-api": f"Hetzner DNS API Token: {token}\nFür sascha-lutz.de", "other": "ignored"})
monkeypatch.setattr(app, "_read", lambda _name: None)
monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (_ for _ in ()).throw(AssertionError("must not sync vault")))
assert app._get_hetzner_dns_token() == "secret-value"
assert app._get_hetzner_dns_token() == token
def test_uptime_monitor_remove_defaults_to_dry_run(monkeypatch):
payload = {"monitor_id": 71, "expected_name": "Outline Wiki", "dry_run": True, "found": {"id": 71, "name": "Outline Wiki"}}
monkeypatch.setattr(app, "_ssh", lambda target, command, timeout=120: (0, json.dumps(payload), ""))
with TestClient(app.app) as client:
response = client.delete("/uptime/monitor/71", params={"expected_name": "Outline Wiki"}, headers={"Authorization": "Bearer test-token"})
assert response.status_code == 200
assert response.json()["dry_run"] is True
def test_uptime_monitor_remove_rejects_invalid_expected_name_before_ssh(monkeypatch):
monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (_ for _ in ()).throw(AssertionError("must not SSH")))
with TestClient(app.app) as client:
response = client.delete("/uptime/monitor/71", params={"expected_name": "Outline; rm -rf /"}, headers={"Authorization": "Bearer test-token"})
assert response.status_code == 400
def test_invalid_log_target_is_rejected_before_ssh():