mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-10-05 22:22:08 +00:00
fix(ci): hash the served index.html byte stream in CloudFront verify (SH-300) (#186)
Some checks failed
Frontend checks / Build and test (push) Has been cancelled
Frontend checks / governance (push) Has been cancelled
Frontend checks / Visual regression (push) Has been cancelled
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
Some checks failed
Frontend checks / Build and test (push) Has been cancelled
Frontend checks / governance (push) Has been cancelled
Frontend checks / Visual regression (push) Has been cancelled
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
Capturing the curl body in "$(...)" strips the trailing newline, so the served sha256 never matched dist/index.html and every release and rollback verify polled to the budget and failed. Hash the response stream directly and give the test fixture a trailing newline so the suite covers it.
This commit is contained in:
parent
c30e8aa74b
commit
29aecff2bb
2 changed files with 11 additions and 8 deletions
|
|
@ -8,7 +8,9 @@ CURRENT="bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb-2-1"
|
||||||
PREVIOUS="aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa-1-1"
|
PREVIOUS="aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa-1-1"
|
||||||
NEW_HASH="1111111111111111111111111111111111111111111111111111111111111111"
|
NEW_HASH="1111111111111111111111111111111111111111111111111111111111111111"
|
||||||
OLD_HASH="0000000000000000000000000000000000000000000000000000000000000000"
|
OLD_HASH="0000000000000000000000000000000000000000000000000000000000000000"
|
||||||
INDEX_HTML='<!doctype html><html><head><script type="module" src="/assets/app.js"></script></head><body></body></html>'
|
# Vite writes index.html with a trailing newline. Keep it in the fixture so
|
||||||
|
# the expected hash covers every served byte, exactly like dist/index.html.
|
||||||
|
INDEX_HTML=$'<!doctype html><html><head><script type="module" src="/assets/app.js"></script></head><body></body></html>\n'
|
||||||
INDEX_HASH="$(printf '%s' "${INDEX_HTML}" | python3 -c 'import hashlib,sys; print(hashlib.sha256(sys.stdin.buffer.read()).hexdigest())')"
|
INDEX_HASH="$(printf '%s' "${INDEX_HTML}" | python3 -c 'import hashlib,sys; print(hashlib.sha256(sys.stdin.buffer.read()).hexdigest())')"
|
||||||
|
|
||||||
failures=0
|
failures=0
|
||||||
|
|
@ -75,12 +77,12 @@ if [[ "${url}" == *"/assets/"* ]]; then
|
||||||
[[ -z "${output}" ]] && printf '%s' "${body}"
|
[[ -z "${output}" ]] && printf '%s' "${body}"
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
body="$(cat "${state_dir}/index.html")"
|
# Serve index.html byte-for-byte, trailing newline included, like real curl.
|
||||||
[[ -n "${dump}" ]] && printf 'HTTP/1.1 200 OK\nCache-Control: no-cache,no-store,must-revalidate\n\n' > "${dump}"
|
[[ -n "${dump}" ]] && printf 'HTTP/1.1 200 OK\nCache-Control: no-cache,no-store,must-revalidate\n\n' > "${dump}"
|
||||||
if [[ -n "${output}" ]]; then
|
if [[ -n "${output}" ]]; then
|
||||||
printf '%s' "${body}" > "${output}"
|
cat "${state_dir}/index.html" > "${output}"
|
||||||
else
|
else
|
||||||
printf '%s' "${body}"
|
cat "${state_dir}/index.html"
|
||||||
fi
|
fi
|
||||||
exit 0
|
exit 0
|
||||||
CURL
|
CURL
|
||||||
|
|
|
||||||
|
|
@ -80,10 +80,11 @@ observe() {
|
||||||
last_status="$(printf '%s\n' "${parsed}" | sed -n '1p')"
|
last_status="$(printf '%s\n' "${parsed}" | sed -n '1p')"
|
||||||
last_paths="$(printf '%s\n' "${parsed}" | sed -n '2p' | tr '\037' ' ')"
|
last_paths="$(printf '%s\n' "${parsed}" | sed -n '2p' | tr '\037' ' ')"
|
||||||
last_path_ok="$(printf '%s\n' "${parsed}" | sed -n '3p')"
|
last_path_ok="$(printf '%s\n' "${parsed}" | sed -n '3p')"
|
||||||
local body
|
# Hash the response stream directly. Capturing the body in "$(...)" strips
|
||||||
body="$(curl -fsS --max-time 30 "${SITE_URL}/" || true)"
|
# trailing newlines, so the hash never matched dist/index.html.
|
||||||
if [[ -n "${body}" ]]; then
|
local hash
|
||||||
last_hash="$(printf '%s' "${body}" | sha256_of)"
|
if hash="$(curl -fsS --max-time 30 "${SITE_URL}/" | sha256_of)" && [[ -n "${hash}" ]]; then
|
||||||
|
last_hash="${hash}"
|
||||||
else
|
else
|
||||||
last_hash="unreachable"
|
last_hash="unreachable"
|
||||||
fi
|
fi
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue