mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
173 lines
6 KiB
Python
173 lines
6 KiB
Python
#!/usr/bin/env python3
|
|
"""Tests for check_hcp_workspace_triggers.py (stdlib unittest, no live HCP)."""
|
|
from __future__ import annotations
|
|
|
|
import sys
|
|
import tempfile
|
|
import unittest
|
|
from pathlib import Path
|
|
from unittest import mock
|
|
|
|
SCRIPTS = Path(__file__).resolve().parent
|
|
sys.path.insert(0, str(SCRIPTS))
|
|
import check_hcp_workspace_triggers as chk # noqa: E402
|
|
|
|
|
|
def _ws(
|
|
name: str,
|
|
project_id: str,
|
|
*,
|
|
file_triggers: bool = True,
|
|
prefixes: list[str] | None = None,
|
|
patterns: list[str] | None = None,
|
|
wd: str = "terraform",
|
|
identifier: str | None = "Sea-Haven-Industries/sample",
|
|
) -> dict:
|
|
vcs = {"identifier": identifier} if identifier else None
|
|
return {
|
|
"attributes": {
|
|
"name": name,
|
|
"file-triggers-enabled": file_triggers,
|
|
"trigger-prefixes": prefixes or [],
|
|
"trigger-patterns": patterns or [],
|
|
"working-directory": wd,
|
|
"vcs-repo": vcs,
|
|
},
|
|
"relationships": {"project": {"data": {"id": project_id}}},
|
|
}
|
|
|
|
|
|
class WorkingDirScanTests(unittest.TestCase):
|
|
def test_detects_relative_src_in_tf(self) -> None:
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
repo = Path(tmp)
|
|
tf = repo / "terraform"
|
|
tf.mkdir()
|
|
(tf / "lambda.tf").write_text(
|
|
'source_dir = "${path.module}/../src/shared"\n'
|
|
)
|
|
hits = chk.working_dir_reads_outside(repo, "terraform")
|
|
self.assertEqual(hits, ["terraform/lambda.tf"])
|
|
|
|
def test_detects_repo_src_in_build_script(self) -> None:
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
repo = Path(tmp)
|
|
tf = repo / "terraform"
|
|
tf.mkdir()
|
|
(tf / "build_packages.sh").write_text(
|
|
'SRC="$(cd "${ROOT}/../src" && pwd)"\n'
|
|
)
|
|
hits = chk.working_dir_reads_outside(repo, "terraform")
|
|
self.assertEqual(hits, ["terraform/build_packages.sh"])
|
|
|
|
def test_ignores_terraform_only_tree(self) -> None:
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
repo = Path(tmp)
|
|
tf = repo / "terraform"
|
|
tf.mkdir()
|
|
(tf / "s3.tf").write_text('resource "aws_s3_bucket" "x" {}\n')
|
|
self.assertEqual(chk.working_dir_reads_outside(repo, "terraform"), [])
|
|
|
|
|
|
class ClassifyTests(unittest.TestCase):
|
|
def test_empty_triggers_with_outside_refs_is_defect(self) -> None:
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
root = Path(tmp)
|
|
repo = root / "sample"
|
|
(repo / "terraform").mkdir(parents=True)
|
|
(repo / "terraform" / "lambda.tf").write_text(
|
|
'source_dir = "${path.module}/../src/app"\n'
|
|
)
|
|
row = chk.classify_workspace(
|
|
_ws("sample-prod", "p1")["attributes"],
|
|
"seahaven-prod",
|
|
root,
|
|
)
|
|
self.assertTrue(row["defect"])
|
|
|
|
def test_empty_triggers_without_outside_refs_is_ok(self) -> None:
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
root = Path(tmp)
|
|
repo = root / "sample"
|
|
(repo / "terraform").mkdir(parents=True)
|
|
(repo / "terraform" / "s3.tf").write_text("resource aws_s3_bucket x {}\n")
|
|
row = chk.classify_workspace(
|
|
_ws("sample-prod", "p1")["attributes"],
|
|
"seahaven-prod",
|
|
root,
|
|
)
|
|
self.assertFalse(row["defect"])
|
|
|
|
def test_prefixes_cover_outside_refs(self) -> None:
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
root = Path(tmp)
|
|
repo = root / "sample"
|
|
(repo / "terraform").mkdir(parents=True)
|
|
(repo / "terraform" / "lambda.tf").write_text(
|
|
'source_dir = "${path.module}/../src/app"\n'
|
|
)
|
|
row = chk.classify_workspace(
|
|
_ws("sample-prod", "p1", prefixes=["terraform", "src"])["attributes"],
|
|
"seahaven-prod",
|
|
root,
|
|
)
|
|
self.assertFalse(row["defect"])
|
|
self.assertTrue(row["outside_refs"])
|
|
|
|
def test_missing_clone_does_not_fail(self) -> None:
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
row = chk.classify_workspace(
|
|
_ws("sample-prod", "p1")["attributes"],
|
|
"seahaven-prod",
|
|
Path(tmp),
|
|
)
|
|
self.assertEqual(row["inspect"], "missing-clone")
|
|
self.assertFalse(row["defect"])
|
|
|
|
|
|
class CheckFilterTests(unittest.TestCase):
|
|
def test_skips_disabled_file_triggers_and_other_projects(self) -> None:
|
|
payload = {
|
|
"data": [
|
|
_ws("cli-only", "prod", file_triggers=False),
|
|
_ws("shoc-dev", "ext"),
|
|
_ws("app-prod", "prod", patterns=["terraform/**/*", "src/**/*"]),
|
|
],
|
|
"included": [
|
|
{"id": "prod", "type": "projects", "attributes": {"name": "seahaven-prod"}},
|
|
{
|
|
"id": "ext",
|
|
"type": "projects",
|
|
"attributes": {"name": "seahaven-external-dev"},
|
|
},
|
|
],
|
|
"links": {"next": None},
|
|
}
|
|
with mock.patch.object(chk, "api_get", return_value=payload):
|
|
with tempfile.TemporaryDirectory() as tmp:
|
|
rows = chk.check("token", Path(tmp))
|
|
names = [row["name"] for row in rows]
|
|
self.assertEqual(names, ["app-prod"])
|
|
|
|
|
|
class ReportTests(unittest.TestCase):
|
|
def test_format_includes_defect_count(self) -> None:
|
|
text = chk.format_report(
|
|
[
|
|
{
|
|
"name": "bad-prod",
|
|
"project": "seahaven-prod",
|
|
"trigger_prefixes": [],
|
|
"trigger_patterns": [],
|
|
"outside_refs": ["terraform/lambda.tf"],
|
|
"inspect": "ok",
|
|
"defect": True,
|
|
}
|
|
]
|
|
)
|
|
self.assertIn("defects: 1", text)
|
|
self.assertIn("bad-prod", text)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|