mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 13:53:15 +00:00
Applies the plan's C5 step: git mv every test per the domain-reorg
move-map (movemap-m50.txt) into tests/{agent,analyzer,auth,dashboard,
github,middleware,models,reviewer,sandbox,slack,tools,webhooks}/, plus
the 13 fork-only placements from the scoping report §2c (Atlassian
webhook tests -> tests/webhooks/, test_atlassian_connect.py and
test_auth_error_leak.py -> tests/auth/, jira/confluence util tests ->
tests/tools/, test_repo_binding_isolation.py -> tests/sandbox/,
bot-identity/autofix tests -> tests/github/).
Path-only move: the only content edits are parents[1] -> parents[2]
fixes in test_e2b_integration.py and test_daytona_integration.py,
required because their __file__-relative ROOT path gained one more
directory level in the move.
Monkeypatch retargets for these files were already completed in C4;
none remained outstanding here.
81 lines
2.4 KiB
Python
81 lines
2.4 KiB
Python
"""AUTH-RESP-LEAK-01: upstream auth-error bodies must not reach user-facing text."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import asyncio
|
|
from typing import Any
|
|
|
|
import httpx
|
|
import pytest
|
|
|
|
from agent.utils import auth
|
|
|
|
_SECRET_BODY = "SENSITIVE-UPSTREAM-BODY-9999"
|
|
|
|
|
|
class _Resp:
|
|
def __init__(self, status_code: int, text: str) -> None:
|
|
self.status_code = status_code
|
|
self.text = text
|
|
|
|
def raise_for_status(self) -> None:
|
|
raise httpx.HTTPStatusError(
|
|
"boom",
|
|
request=httpx.Request("POST", "http://example.test"),
|
|
response=self, # type: ignore[arg-type]
|
|
)
|
|
|
|
def json(self) -> Any:
|
|
return {}
|
|
|
|
|
|
class _Client:
|
|
def __init__(self, resp: _Resp) -> None:
|
|
self._resp = resp
|
|
|
|
async def __aenter__(self) -> _Client:
|
|
return self
|
|
|
|
async def __aexit__(self, *_a: Any) -> None:
|
|
return None
|
|
|
|
async def post(self, *_a: Any, **_k: Any) -> _Resp:
|
|
return self._resp
|
|
|
|
|
|
class _OkResp:
|
|
"""A 2xx response whose JSON body lacks both a token and an auth url."""
|
|
|
|
def __init__(self, payload: Any) -> None:
|
|
self._payload = payload
|
|
|
|
def raise_for_status(self) -> None:
|
|
return None
|
|
|
|
def json(self) -> Any:
|
|
return self._payload
|
|
|
|
|
|
def test_http_error_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None:
|
|
monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id")
|
|
monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret")
|
|
monkeypatch.setattr(httpx, "AsyncClient", lambda *a, **k: _Client(_Resp(500, _SECRET_BODY)))
|
|
|
|
result = asyncio.run(auth.get_github_token_for_user("ls-user", "tenant"))
|
|
|
|
assert "error" in result
|
|
assert _SECRET_BODY not in result["error"]
|
|
assert "500" in result["error"]
|
|
|
|
|
|
def test_unexpected_result_returns_generic_message(monkeypatch: pytest.MonkeyPatch) -> None:
|
|
"""The 2xx-but-missing-token/url branch must not echo the upstream body."""
|
|
monkeypatch.setattr(auth, "GITHUB_OAUTH_PROVIDER_ID", "provider-id")
|
|
monkeypatch.setattr(auth, "X_SERVICE_AUTH_JWT_SECRET", "jwt-secret")
|
|
body = {"unexpected_field": _SECRET_BODY}
|
|
monkeypatch.setattr(httpx, "AsyncClient", lambda *a, **k: _Client(_OkResp(body)))
|
|
|
|
result = asyncio.run(auth.get_github_token_for_user("ls-user", "tenant"))
|
|
|
|
assert result == {"error": "GitHub auth returned an unexpected result"}
|
|
assert _SECRET_BODY not in result["error"]
|