Harden package paths and storage writes
This commit is contained in:
@@ -0,0 +1,50 @@
|
||||
import json
|
||||
import tempfile
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
|
||||
from beeos.core.package_manifest import ManifestError, load_manifest
|
||||
|
||||
|
||||
BASE_MANIFEST = {
|
||||
"id": "local.test.app",
|
||||
"name": "Test App",
|
||||
"type": "app",
|
||||
"version": "1.0.0",
|
||||
"author": "BeeOS",
|
||||
"description": "Manifest validation test package",
|
||||
"entry": "app.py",
|
||||
}
|
||||
|
||||
|
||||
class PackageManifestTests(unittest.TestCase):
|
||||
def load_with_entry(self, entry: str):
|
||||
data = {**BASE_MANIFEST, "entry": entry}
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
path = Path(temp_dir) / "manifest.json"
|
||||
path.write_text(json.dumps(data), encoding="utf-8")
|
||||
return load_manifest(path)
|
||||
|
||||
def test_accepts_relative_entry(self):
|
||||
manifest = self.load_with_entry("src/app.py")
|
||||
self.assertEqual(manifest.entry, "src/app.py")
|
||||
|
||||
def test_rejects_parent_directory_entry(self):
|
||||
with self.assertRaisesRegex(ManifestError, "relative path"):
|
||||
self.load_with_entry("../outside.py")
|
||||
|
||||
def test_rejects_windows_absolute_entry(self):
|
||||
with self.assertRaisesRegex(ManifestError, "relative path"):
|
||||
self.load_with_entry(r"C:\\outside.py")
|
||||
|
||||
def test_rejects_windows_parent_directory_entry(self):
|
||||
with self.assertRaisesRegex(ManifestError, "relative path"):
|
||||
self.load_with_entry(r"..\outside.py")
|
||||
|
||||
def test_rejects_empty_entry(self):
|
||||
with self.assertRaisesRegex(ManifestError, "non-empty"):
|
||||
self.load_with_entry(" ")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
@@ -0,0 +1,33 @@
|
||||
import json
|
||||
import tempfile
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
|
||||
from beeos.core.runtime_api import BeeStorageAPI
|
||||
|
||||
|
||||
class BeeStorageAPITests(unittest.TestCase):
|
||||
def test_set_persists_json_and_leaves_no_temporary_file(self):
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
storage_file = Path(temp_dir) / "storage.json"
|
||||
storage = BeeStorageAPI(storage_file)
|
||||
|
||||
storage.set("launches", 3)
|
||||
|
||||
self.assertEqual(storage.get("launches"), 3)
|
||||
self.assertEqual(json.loads(storage_file.read_text(encoding="utf-8")), {"launches": 3})
|
||||
self.assertFalse(storage_file.with_name("storage.json.tmp").exists())
|
||||
|
||||
def test_delete_removes_key_without_corrupting_other_values(self):
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
storage = BeeStorageAPI(Path(temp_dir) / "storage.json")
|
||||
storage.set("launches", 3)
|
||||
storage.set("theme", "yellow")
|
||||
|
||||
storage.delete("launches")
|
||||
|
||||
self.assertEqual(storage.all(), {"theme": "yellow"})
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
Reference in New Issue
Block a user