open-swe/tests/test_jira_webhook_replay.py
Adam Moussa b3fc62da80
refactor: split webapp.py into api/ + per-source webhook routes
Plan step C4 (docs/upstream-sync/domain-reorg/reorg-build-plan.md, approved
decisions 1-2): split the 2,590-line agent/webapp.py monolith into
agent/webhooks/common.py (shared verify/dispatch helpers), agent/api/app.py
(composition), agent/api/health.py (/health + /webhooks/run-complete), and
per-source {github,linear,slack,jira,confluence}_routes.py. Atlassian
Connect lifecycle + descriptor routes (/connect/*) fold into
confluence_routes.py; webapp.py becomes the upstream-shaped compatibility
shim (from .api.app import app). langgraph.json http.app stays
agent.webapp:app via the shim.

Fork content, upstream layout: linear/slack route files verified
content-identical to upstream 8356eb34 and taken verbatim; github_routes is
upstream + the fork's CI auto-fix trigger wiring; jira/confluence routes are
fork-only, transformed to the same common.X / service.X module-attribute
style. All signature verification (GitHub HMAC, Slack, Linear
timestamp-freshness, verify_jira_secret + opt-in HMAC/timestamp/IP
allowlist, Connect JWT/qsh), token-attribution gating, TID-COLLIDE-01 repo
binding, _is_repo_auto_review_enabled gates, and public-repo org gate move
unchanged.

Handlers rewired from webapp.X to common.X; test monkeypatch sites across
26 files + conftest.py + e2e/harness.py retargeted to
webhook_common/handler/route modules per upstream's pattern. Residual
agent.webapp importers: only the shim, langgraph.json http.app, Makefile
uvicorn target, and docs (doc-path updates land in C7).

Gates: ruff check + format, pytest --co, full unit (1637 passed), full
Playwright E2E vs real langgraph dev (9/9), residual-importer sweep.
2026-07-17 14:30:05 -04:00

133 lines
5.7 KiB
Python

"""Shared-secret verification for the Jira Automation webhook (AUTHZ)."""
from __future__ import annotations
import hashlib
import hmac
import json
from datetime import UTC, datetime
from types import SimpleNamespace
import pytest
from agent.webhooks import common as webhook_common
_SECRET = "jira-automation-secret"
def _signed_body(secret: str, *, fresh: bool = True) -> tuple[bytes, str]:
ts_ms = datetime.now(UTC).timestamp() * 1000
if not fresh:
ts_ms -= (webhook_common.JIRA_WEBHOOK_MAX_AGE_SECONDS + 60) * 1000
body = json.dumps({"issue_key": "PROJ-1", "timestamp": ts_ms}).encode()
sig = hmac.new(secret.encode(), body, hashlib.sha256).hexdigest()
return body, sig
def test_valid_secret_accepted(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
headers = {"X-Automation-Webhook-Token": _SECRET}
assert webhook_common.verify_jira_secret(headers) is True
def test_wrong_secret_rejected(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
headers = {"X-Automation-Webhook-Token": "wrong-token"}
assert webhook_common.verify_jira_secret(headers) is False
def test_missing_header_rejected(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
assert webhook_common.verify_jira_secret({}) is False
def test_empty_header_rejected(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
assert webhook_common.verify_jira_secret({"X-Automation-Webhook-Token": ""}) is False
def test_unset_env_fails_closed(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", "")
headers = {"X-Automation-Webhook-Token": _SECRET}
assert webhook_common.verify_jira_secret(headers) is False
# --- Opt-in HMAC body signature + timestamp (JIRA_WEBHOOK_REQUIRE_SIGNATURE) ---
def test_signature_check_is_noop_when_disabled(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_REQUIRE_SIGNATURE", False)
assert webhook_common.verify_jira_signature(b"{}", {}) is True
def test_valid_signature_and_fresh_timestamp_accepted(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_REQUIRE_SIGNATURE", True)
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
body, sig = _signed_body(_SECRET)
assert webhook_common.verify_jira_signature(body, {"X-Openswe-Signature": sig}) is True
def test_missing_signature_rejected_when_required(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_REQUIRE_SIGNATURE", True)
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
body, _sig = _signed_body(_SECRET)
assert webhook_common.verify_jira_signature(body, {}) is False
def test_wrong_signature_rejected(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_REQUIRE_SIGNATURE", True)
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
body, _sig = _signed_body(_SECRET)
assert webhook_common.verify_jira_signature(body, {"X-Openswe-Signature": "deadbeef"}) is False
def test_stale_timestamp_rejected(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_REQUIRE_SIGNATURE", True)
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_SECRET", _SECRET)
body, sig = _signed_body(_SECRET, fresh=False)
assert webhook_common.verify_jira_signature(body, {"X-Openswe-Signature": sig}) is False
# --- Opt-in source-IP allowlist (JIRA_WEBHOOK_IP_ALLOWLIST) ---
def _req(host: str | None) -> object:
client = None if host is None else SimpleNamespace(host=host)
return SimpleNamespace(client=client)
def test_ip_check_is_noop_when_disabled(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_IP_ALLOWLIST", ())
assert webhook_common.verify_jira_source_ip(_req("9.9.9.9")) is True
def test_ip_in_allowlist_accepted(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_IP_ALLOWLIST", ("10.0.0.0/24",))
assert webhook_common.verify_jira_source_ip(_req("10.0.0.5")) is True
def test_ip_not_in_allowlist_rejected(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_IP_ALLOWLIST", ("10.0.0.0/24",))
assert webhook_common.verify_jira_source_ip(_req("192.168.1.1")) is False
def test_ip_missing_client_rejected(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "JIRA_WEBHOOK_IP_ALLOWLIST", ("10.0.0.0/24",))
assert webhook_common.verify_jira_source_ip(_req(None)) is False
# --- Fail-closed repo allowlist (REQUIRE_REPO_ALLOWLIST) ---
def test_empty_allowlist_allows_all_by_default(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "ALLOWED_GITHUB_ORGS", frozenset())
monkeypatch.setattr(webhook_common, "ALLOWED_GITHUB_REPOS", frozenset())
monkeypatch.setattr(webhook_common, "REQUIRE_REPO_ALLOWLIST", False)
assert webhook_common._is_repo_allowed({"owner": "anyone", "name": "anything"}) is True
def test_empty_allowlist_fails_closed_when_required(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setattr(webhook_common, "ALLOWED_GITHUB_ORGS", frozenset())
monkeypatch.setattr(webhook_common, "ALLOWED_GITHUB_REPOS", frozenset())
monkeypatch.setattr(webhook_common, "REQUIRE_REPO_ALLOWLIST", True)
assert webhook_common._is_repo_allowed({"owner": "anyone", "name": "anything"}) is False