fix: corrige 6 bugs mineurs (BUG-035 a BUG-040)
This commit is contained in:
@@ -44,6 +44,22 @@ class TestPasswordHashing:
|
||||
result = hash_password("ab")
|
||||
assert result is not None
|
||||
|
||||
def test_argon2_memory_recalibrated(self):
|
||||
"""BUG-038: memory cost must stay at the OWASP 19 MiB recommendation."""
|
||||
from backend.auth.password import (
|
||||
ARGON2_MEMORY_COST_KIB,
|
||||
ARGON2_PARALLELISM,
|
||||
ARGON2_TIME_COST,
|
||||
ph,
|
||||
)
|
||||
|
||||
assert ARGON2_MEMORY_COST_KIB == 19456
|
||||
assert ARGON2_TIME_COST == 2
|
||||
assert ARGON2_PARALLELISM == 1
|
||||
assert ph.memory_cost == 19456
|
||||
assert ph.time_cost == 2
|
||||
assert ph.parallelism == 1
|
||||
|
||||
|
||||
# ═══════════════════════════════════════════════════════════════════
|
||||
# JWT Handler
|
||||
@@ -279,3 +295,61 @@ class TestMiddleware:
|
||||
assert check_vault_access("Vault1", user) is True
|
||||
assert check_vault_access("Vault3", user) is False
|
||||
assert check_vault_access("Vault1", nobody) is False
|
||||
|
||||
|
||||
# ═══════════════════════════════════════════════════════════════════
|
||||
# Insecure (auth-disabled) deployment guard — BUG-037
|
||||
# ═══════════════════════════════════════════════════════════════════
|
||||
|
||||
class TestInsecureAuthGuard:
|
||||
def test_is_loopback_host(self):
|
||||
from backend.auth.middleware import is_loopback_host
|
||||
|
||||
assert is_loopback_host(None) is True
|
||||
assert is_loopback_host("127.0.0.1") is True
|
||||
assert is_loopback_host("::1") is True
|
||||
assert is_loopback_host("[::1]") is True
|
||||
assert is_loopback_host("localhost") is True
|
||||
assert is_loopback_host("0.0.0.0") is False
|
||||
assert is_loopback_host("192.168.1.10") is False
|
||||
|
||||
def test_bind_host_from_argv(self):
|
||||
from backend.auth.middleware import bind_host_from_argv
|
||||
|
||||
assert bind_host_from_argv(
|
||||
["uvicorn", "backend.main:app", "--host", "0.0.0.0", "--port", "8080"]
|
||||
) == "0.0.0.0"
|
||||
assert bind_host_from_argv(["uvicorn", "app", "--host=127.0.0.1"]) == "127.0.0.1"
|
||||
assert bind_host_from_argv(["uvicorn", "app"]) is None
|
||||
|
||||
def test_guard_refuses_public_bind_without_optin(self, monkeypatch):
|
||||
from backend import main
|
||||
|
||||
monkeypatch.setenv("OBSIGATE_AUTH_ENABLED", "false")
|
||||
monkeypatch.delenv("OBSIGATE_ALLOW_INSECURE", raising=False)
|
||||
monkeypatch.setattr("sys.argv", ["uvicorn", "backend.main:app", "--host", "0.0.0.0"])
|
||||
with pytest.raises(RuntimeError):
|
||||
main._guard_insecure_auth()
|
||||
|
||||
def test_guard_allows_loopback(self, monkeypatch):
|
||||
from backend import main
|
||||
|
||||
monkeypatch.setenv("OBSIGATE_AUTH_ENABLED", "false")
|
||||
monkeypatch.delenv("OBSIGATE_ALLOW_INSECURE", raising=False)
|
||||
monkeypatch.setattr("sys.argv", ["uvicorn", "backend.main:app", "--host", "127.0.0.1"])
|
||||
main._guard_insecure_auth() # must not raise
|
||||
|
||||
def test_guard_allows_explicit_optin(self, monkeypatch):
|
||||
from backend import main
|
||||
|
||||
monkeypatch.setenv("OBSIGATE_AUTH_ENABLED", "false")
|
||||
monkeypatch.setenv("OBSIGATE_ALLOW_INSECURE", "true")
|
||||
monkeypatch.setattr("sys.argv", ["uvicorn", "backend.main:app", "--host", "0.0.0.0"])
|
||||
main._guard_insecure_auth() # must not raise
|
||||
|
||||
def test_guard_noop_when_auth_enabled(self, monkeypatch):
|
||||
from backend import main
|
||||
|
||||
monkeypatch.setenv("OBSIGATE_AUTH_ENABLED", "true")
|
||||
monkeypatch.setattr("sys.argv", ["uvicorn", "backend.main:app", "--host", "0.0.0.0"])
|
||||
main._guard_insecure_auth() # must not raise
|
||||
|
||||
Reference in New Issue
Block a user