release r007 security hardening and redesigned UI
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
import { describe, expect, test } from "bun:test";
|
||||
import { parseConfig, SAFE_DEFAULT_TOOLS } from "./auth";
|
||||
import { sanitizeLogOutput } from "./helpers";
|
||||
import { getToolRisk } from "./tools";
|
||||
|
||||
describe("secure tool configuration", () => {
|
||||
test("new and incomplete configs use the read-only baseline", () => {
|
||||
const cfg = parseConfig("MUA_API_KEY=test\n");
|
||||
expect(cfg.allToolsEnabled).toBe(false);
|
||||
expect(cfg.enabledTools).toEqual(SAFE_DEFAULT_TOOLS);
|
||||
expect(cfg.enabledTools).not.toContain("unraid_system_shell");
|
||||
});
|
||||
|
||||
test("none means no tools instead of all tools", () => {
|
||||
const cfg = parseConfig("MUA_API_KEY=test\nMUA_ENABLED_TOOLS=none\n");
|
||||
expect(cfg.allToolsEnabled).toBe(false);
|
||||
expect(cfg.enabledTools).toEqual([]);
|
||||
});
|
||||
|
||||
test("legacy all remains backwards compatible and explicit", () => {
|
||||
const cfg = parseConfig("MUA_API_KEY=test\nMUA_ENABLED_TOOLS=all\n");
|
||||
expect(cfg.allToolsEnabled).toBe(true);
|
||||
expect(cfg.enabledTools).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("secret handling", () => {
|
||||
test("redacts common key-value and JSON secrets", () => {
|
||||
const output = sanitizeLogOutput(
|
||||
'API_KEY=very-secret password:also-secret {"token":"third-secret"}',
|
||||
);
|
||||
expect(output).not.toContain("very-secret");
|
||||
expect(output).not.toContain("also-secret");
|
||||
expect(output).not.toContain("third-secret");
|
||||
expect(output).toContain("[REDACTED]");
|
||||
});
|
||||
});
|
||||
|
||||
describe("risk classification", () => {
|
||||
test("classifies root shell and container changes as critical", () => {
|
||||
expect(getToolRisk("unraid_system_shell")).toBe("critical");
|
||||
expect(getToolRisk("unraid_docker_modify")).toBe("critical");
|
||||
expect(getToolRisk("unraid_docker_restart")).toBe("write");
|
||||
expect(getToolRisk("unraid_network_lan_probe")).toBe("active");
|
||||
expect(getToolRisk("unraid_docker_list")).toBe("read");
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user