feat: add bounded file inventory for media audits

This commit is contained in:
Mikei386 committed 2026-08-24 11:49:12 +02:00
1 parent d90874ed18
commit 4426969d63
12 files changed
+163 -12

No files matched your search

+9
View File
@@ -30,6 +30,14 @@ describe("secure tool configuration", () => {
expect(cfg.enabledTools).toContain("unraid_docker_update");
expect(cfg.enabledTools).toContain("unraid_docker_update_verified_batch");
});
test("an enabled read-only shell also exposes bounded file inventory", () => {
const cfg = parseConfig(
"MUA_API_KEY=test\nMUA_ENABLED_TOOLS=unraid_system_shell_readonly\n",
);
expect(cfg.enabledTools).toContain("unraid_files_inventory");
expect(cfg.enabledTools).not.toContain("unraid_system_shell");
});
});
describe("secret handling", () => {
@@ -53,6 +61,7 @@ describe("risk classification", () => {
expect(getToolRisk("unraid_network_lan_probe")).toBe("active");
expect(getToolRisk("unraid_docker_list")).toBe("read");
expect(getToolRisk("unraid_system_shell_readonly")).toBe("read");
expect(getToolRisk("unraid_files_inventory")).toBe("read");
expect(getToolRisk("unraid_system_health")).toBe("read");
expect(getToolRisk("unraid_ca_search")).toBe("active");
expect(getToolRisk("unraid_ca_install_preview")).toBe("active");