feat: add bounded file inventory for media audits
This commit is contained in:
1 parent
d90874ed18
commit
4426969d63
12 files changed
+163
-12
No files matched your search
@@ -30,6 +30,14 @@ describe("secure tool configuration", () => {
|
||||
expect(cfg.enabledTools).toContain("unraid_docker_update");
|
||||
expect(cfg.enabledTools).toContain("unraid_docker_update_verified_batch");
|
||||
});
|
||||
|
||||
test("an enabled read-only shell also exposes bounded file inventory", () => {
|
||||
const cfg = parseConfig(
|
||||
"MUA_API_KEY=test\nMUA_ENABLED_TOOLS=unraid_system_shell_readonly\n",
|
||||
);
|
||||
expect(cfg.enabledTools).toContain("unraid_files_inventory");
|
||||
expect(cfg.enabledTools).not.toContain("unraid_system_shell");
|
||||
});
|
||||
});
|
||||
|
||||
describe("secret handling", () => {
|
||||
@@ -53,6 +61,7 @@ describe("risk classification", () => {
|
||||
expect(getToolRisk("unraid_network_lan_probe")).toBe("active");
|
||||
expect(getToolRisk("unraid_docker_list")).toBe("read");
|
||||
expect(getToolRisk("unraid_system_shell_readonly")).toBe("read");
|
||||
expect(getToolRisk("unraid_files_inventory")).toBe("read");
|
||||
expect(getToolRisk("unraid_system_health")).toBe("read");
|
||||
expect(getToolRisk("unraid_ca_search")).toBe("active");
|
||||
expect(getToolRisk("unraid_ca_install_preview")).toBe("active");
|
||||
|
||||
Reference in new issue
Block a user