release r010 add Unraid health and Community Apps tools
This commit is contained in:
1 parent
e586b22b13
commit
771b8c43a1
14 files changed
+831
-33
No files matched your search
+13
-1
@@ -1,6 +1,6 @@
|
||||
import { describe, expect, test } from "bun:test";
|
||||
import { parseConfig, SAFE_DEFAULT_TOOLS } from "./auth";
|
||||
import { runReadOnlyCommand, sanitizeLogOutput } from "./helpers";
|
||||
import { installCommunityApp, runReadOnlyCommand, sanitizeLogOutput } from "./helpers";
|
||||
import { getToolRisk } from "./tools";
|
||||
|
||||
describe("secure tool configuration", () => {
|
||||
@@ -44,6 +44,10 @@ describe("risk classification", () => {
|
||||
expect(getToolRisk("unraid_network_lan_probe")).toBe("active");
|
||||
expect(getToolRisk("unraid_docker_list")).toBe("read");
|
||||
expect(getToolRisk("unraid_system_shell_readonly")).toBe("read");
|
||||
expect(getToolRisk("unraid_system_health")).toBe("read");
|
||||
expect(getToolRisk("unraid_ca_search")).toBe("active");
|
||||
expect(getToolRisk("unraid_ca_install_preview")).toBe("active");
|
||||
expect(getToolRisk("unraid_ca_install")).toBe("critical");
|
||||
});
|
||||
});
|
||||
|
||||
@@ -61,3 +65,11 @@ describe("read-only shell", () => {
|
||||
await expect(runReadOnlyCommand("ss", ["-K", "dst", "127.0.0.1"], 5)).rejects.toThrow();
|
||||
});
|
||||
});
|
||||
|
||||
describe("Community Applications approval", () => {
|
||||
test("rejects an install without a matching preview ticket before any write", async () => {
|
||||
await expect(
|
||||
installCommunityApp("aaaaaaaaaaaaaaaa", "mua-test", {}, false, true, "missing"),
|
||||
).rejects.toThrow("Approval ticket missing");
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user