Sichere Entfernung stillgelegter Uptime-Monitore #36
1 changed files with 20 additions and 2 deletions
|
|
@ -1,5 +1,6 @@
|
||||||
import os
|
import os
|
||||||
import asyncio
|
import asyncio
|
||||||
|
import json
|
||||||
import time
|
import time
|
||||||
from datetime import datetime, timedelta, timezone
|
from datetime import datetime, timedelta, timezone
|
||||||
|
|
||||||
|
|
@ -278,10 +279,27 @@ def test_dns_rrset_dry_run_returns_only_selected_records(monkeypatch):
|
||||||
|
|
||||||
|
|
||||||
def test_hetzner_dns_token_accepts_single_sanitized_vault_alias(monkeypatch):
|
def test_hetzner_dns_token_accepts_single_sanitized_vault_alias(monkeypatch):
|
||||||
monkeypatch.setattr(app, "_vault_cache", {"hetzner-dns-api": "secret-value", "other": "ignored"})
|
token = "a" * 48
|
||||||
|
monkeypatch.setattr(app, "_vault_cache", {"hetzner-dns-api": f"Hetzner DNS API Token: {token}\nFür sascha-lutz.de", "other": "ignored"})
|
||||||
monkeypatch.setattr(app, "_read", lambda _name: None)
|
monkeypatch.setattr(app, "_read", lambda _name: None)
|
||||||
monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (_ for _ in ()).throw(AssertionError("must not sync vault")))
|
monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (_ for _ in ()).throw(AssertionError("must not sync vault")))
|
||||||
assert app._get_hetzner_dns_token() == "secret-value"
|
assert app._get_hetzner_dns_token() == token
|
||||||
|
|
||||||
|
|
||||||
|
def test_uptime_monitor_remove_defaults_to_dry_run(monkeypatch):
|
||||||
|
payload = {"monitor_id": 71, "expected_name": "Outline Wiki", "dry_run": True, "found": {"id": 71, "name": "Outline Wiki"}}
|
||||||
|
monkeypatch.setattr(app, "_ssh", lambda target, command, timeout=120: (0, json.dumps(payload), ""))
|
||||||
|
with TestClient(app.app) as client:
|
||||||
|
response = client.delete("/uptime/monitor/71", params={"expected_name": "Outline Wiki"}, headers={"Authorization": "Bearer test-token"})
|
||||||
|
assert response.status_code == 200
|
||||||
|
assert response.json()["dry_run"] is True
|
||||||
|
|
||||||
|
|
||||||
|
def test_uptime_monitor_remove_rejects_invalid_expected_name_before_ssh(monkeypatch):
|
||||||
|
monkeypatch.setattr(app, "_ssh", lambda *_args, **_kwargs: (_ for _ in ()).throw(AssertionError("must not SSH")))
|
||||||
|
with TestClient(app.app) as client:
|
||||||
|
response = client.delete("/uptime/monitor/71", params={"expected_name": "Outline; rm -rf /"}, headers={"Authorization": "Bearer test-token"})
|
||||||
|
assert response.status_code == 400
|
||||||
|
|
||||||
|
|
||||||
def test_invalid_log_target_is_rejected_before_ssh():
|
def test_invalid_log_target_is_rejected_before_ssh():
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue