Simplify Athena operator maintenance workflow
This commit is contained in:
@@ -136,14 +136,23 @@ class OperatorTests(unittest.TestCase):
|
||||
return {"argv": argv, "exit_code": 0, "output": " compose.yaml | 2 +-"}
|
||||
return {"argv": argv, "exit_code": 0, "output": "ok"}
|
||||
self.module.run = fake_run
|
||||
payload, preview = self.module.normalise_operation("git_publish", {"message": "Update Athena platform"})
|
||||
payload, preview = self.module.normalise_operation("git_publish", {"message": "Update Athena platform", "paths": ["compose.yaml"]})
|
||||
self.assertEqual(payload["reviewed_status"], "M compose.yaml")
|
||||
self.assertEqual(payload["paths"], ["compose.yaml"])
|
||||
self.assertIn("compose.yaml | 2 +-", preview)
|
||||
|
||||
def test_git_publish_rejects_empty_repository(self):
|
||||
self.module.run = lambda argv, **kwargs: {"argv": argv, "exit_code": 0, "output": ""}
|
||||
with self.assertRaises(RuntimeError):
|
||||
self.module.normalise_operation("git_publish", {"message": "Update Athena platform", "paths": ["compose.yaml"]})
|
||||
|
||||
def test_git_publish_requires_explicit_safe_paths(self):
|
||||
with self.assertRaises(ValueError):
|
||||
self.module.normalise_operation("git_publish", {"message": "Update Athena platform"})
|
||||
with self.assertRaises(ValueError):
|
||||
self.module.normalise_operation("git_publish", {"message": "Update Athena platform", "paths": ["compose.yaml", "compose.yaml"]})
|
||||
with self.assertRaises((ValueError, PermissionError)):
|
||||
self.module.normalise_operation("git_publish", {"message": "Update Athena platform", "paths": [".git/config"]})
|
||||
|
||||
def test_path_traversal_and_protected_paths_are_rejected(self):
|
||||
for path in ("../etc/passwd", ".git/config", "/etc/passwd", "secrets/key"):
|
||||
|
||||
Reference in New Issue
Block a user