dc7fd16dd5
CLI-40: port the exact-secret credential scrub to Rust/Java/.NET (Go/Python
already did it). AuthenticateUser/WriteSecured(2) helpers now redact the exact
caller-supplied secret from any surfaced error, as defense-in-depth on top of the
by-construction guarantee. Rust hand-writes a redacting Debug (derived Debug would
leak the reply); Java/.NET rebuild the same exception type with the redacted
message and do not carry the secret-bearing original forward (so ToString/stack
traces stay clean too).
CLI-41: uniform malformed-reply contract for AuthenticateUser/ArchestrAUserToId/
AddBufferedItem across all five clients — typed payload, else a present int32
return_value, else a typed malformed-reply error. Fixes Go/Java silent-0, .NET
NRE, and Rust's own internal inconsistency.
CLI-44: the Go event goroutine's Recv-error path now uses a non-blocking
sendTerminalEventResult on the reserved slot, so a genuine terminal stream error
is reported as itself instead of being mislabeled ErrSlowConsumer under overflow.
Riders from the CLI-37/38 review: (a) .NET ToDiagnosticSummary and Python
_mxaccess_message surface the raw success member (diagnostics-only parity with
Rust); (b) the status-conversion fixture carries an independent wantSuccess
boolean and the Go/.NET fixture tests assert against it instead of recomputing
the formula under test.
Shared fixtures (authenticate-user.{echoed-credential,missing-payload,
return-value-only}.reply.json) + manifest + ClientBehaviorFixtures.md +
ClientLibrariesDesign.md updated in the same change. Tracking: CLI-40/41/44 -> Done.
97 lines
3.3 KiB
Python
97 lines
3.3 KiB
Python
"""Tests for the uniform malformed-reply contract (CLI-41) and the CLI-40
|
|
credential-redaction regression, driven through the shared fixtures.
|
|
|
|
CLI-41: an OK reply that carries neither the expected typed payload nor a usable
|
|
``return_value`` int32 fallback raises :class:`MalformedReplyError`; a legacy
|
|
reply that populates only ``return_value`` falls back to that int32.
|
|
|
|
CLI-40: an OK reply whose diagnostics echo the caller's credential must never
|
|
surface that credential in the raised error message.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import json
|
|
from pathlib import Path
|
|
|
|
import pytest
|
|
from google.protobuf.json_format import ParseDict
|
|
|
|
from zb_mom_ww_mxgateway import MalformedReplyError, MxAccessError
|
|
from zb_mom_ww_mxgateway.generated import mxaccess_gateway_pb2 as pb
|
|
|
|
from test_typed_command_helpers import _session_with
|
|
|
|
FIXTURE_ROOT = Path(__file__).resolve().parents[2] / "proto" / "fixtures" / "behavior"
|
|
|
|
|
|
def _load_reply(relative: str) -> pb.MxCommandReply:
|
|
path = FIXTURE_ROOT / relative
|
|
return ParseDict(json.loads(path.read_text()), pb.MxCommandReply())
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_authenticate_user_missing_payload_raises_malformed_reply() -> None:
|
|
reply = _load_reply("command-replies/authenticate-user.missing-payload.reply.json")
|
|
session, _ = await _session_with([reply])
|
|
|
|
with pytest.raises(MalformedReplyError) as captured:
|
|
await session.authenticate_user(12, "operator", "any-password")
|
|
|
|
assert captured.value.raw_reply is reply
|
|
assert "malformed reply" in str(captured.value)
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_authenticate_user_return_value_only_falls_back_to_int32() -> None:
|
|
reply = _load_reply("command-replies/authenticate-user.return-value-only.reply.json")
|
|
session, _ = await _session_with([reply])
|
|
|
|
user_id = await session.authenticate_user(12, "operator", "any-password")
|
|
|
|
assert user_id == 7
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_add_buffered_item_falls_back_to_return_value_int32() -> None:
|
|
reply = pb.MxCommandReply(
|
|
session_id="session-1",
|
|
kind=pb.MX_COMMAND_KIND_ADD_BUFFERED_ITEM,
|
|
protocol_status=pb.ProtocolStatus(code=pb.PROTOCOL_STATUS_CODE_OK),
|
|
return_value=pb.MxValue(int32_value=99),
|
|
)
|
|
session, _ = await _session_with([reply])
|
|
|
|
item_handle = await session.add_buffered_item(12, "Object.Attribute", "ctx")
|
|
|
|
assert item_handle == 99
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_add_buffered_item_missing_payload_raises_malformed_reply() -> None:
|
|
reply = pb.MxCommandReply(
|
|
session_id="session-1",
|
|
kind=pb.MX_COMMAND_KIND_ADD_BUFFERED_ITEM,
|
|
protocol_status=pb.ProtocolStatus(code=pb.PROTOCOL_STATUS_CODE_OK),
|
|
)
|
|
session, _ = await _session_with([reply])
|
|
|
|
with pytest.raises(MalformedReplyError) as captured:
|
|
await session.add_buffered_item(12, "Object.Attribute", "ctx")
|
|
|
|
assert captured.value.raw_reply is reply
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_authenticate_user_echoed_credential_is_scrubbed() -> None:
|
|
credential = "sup3rSecretVerify9f3a2b"
|
|
reply = _load_reply("command-replies/authenticate-user.echoed-credential.reply.json")
|
|
session, _ = await _session_with([reply])
|
|
|
|
with pytest.raises(MxAccessError) as captured:
|
|
await session.authenticate_user(12, "operator", credential)
|
|
|
|
message = str(captured.value)
|
|
assert credential not in message
|
|
assert "[redacted]" in message
|