open-swe/tests/test_auth_error_leak.py
Adam Moussa 969b8e3882
fix: stop leaking upstream auth body in unexpected-result branch
The 2xx-but-missing-token/url branch echoed the parsed upstream response body
into the user-facing error. Return a generic message and log response_data
server-side only, mirroring the existing HTTPStatusError fix (Gap 4).
2026-06-29 12:10:54 -04:00

81 lines
2.4 KiB
Python

"""AUTH-RESP-LEAK-01: upstream auth-error bodies must not reach user-facing text."""
from __future__ import annotations
import asyncio
from typing import Any
import httpx
import pytest
from agent.utils import auth
_SECRET_BODY = "SENSITIVE-UPSTREAM-BODY-9999"
class _Resp:
def __init__(self, status_code: int, text: str) -> None:
self.status_code = status_code
self.text = text
def raise_for_status(self) -> None:
raise httpx.HTTPStatusError(
"boom",
request=httpx.Request("POST", "http://example.test"),
response=self, # type: ignore[arg-type]
)
def json(self) -> Any:
return {}
class _Client:
def __init__(self, resp: _Resp) -> None:
self._resp = resp
async def __aenter__(self) -> _Client:
return self
async def __aexit__(self, *_a: Any) -> None:
return None
async def post(self, *_a: Any, **_k: Any) -> _Resp:
return self._resp
class _OkResp:
"""A 2xx response whose JSON body lacks both a token and an auth url."""
def __init__(self, payload: Any) -> None:
self._payload = payload
def raise_for_status(self) -> None:
return None
def json(self) -> Any:
return self._payload
def test_http_error_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id")
monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret")
monkeypatch.setattr(httpx, "AsyncClient", lambda *a, **k: _Client(_Resp(500, _SECRET_BODY)))
result = asyncio.run(auth.get_github_token_for_user("ls-user", "tenant"))
assert "error" in result
assert _SECRET_BODY not in result["error"]
assert "500" in result["error"]
def test_unexpected_result_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None:
"""The 2xx-but-missing-token/url branch must not echo the upstream body."""
monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id")
monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret")
body = {"unexpected_field": _SECRET_BODY}
monkeypatch.setattr(httpx, "AsyncClient", lambda *a, **k: _Client(_OkResp(body)))
result = asyncio.run(auth.get_github_token_for_user("ls-user", "tenant"))
assert result == {"error": "GitHub auth returned an unexpected result"}
assert _SECRET_BODY not in result["error"]