π§ͺ test(hub): cover the lite-enrollment GitHub auth path β verifyGitHubRepoAccess and discoverLiteInstallation - #4948
Conversation
Every existing test stubs verifyLiteRepoAccess, so the REAL verifyGitHubRepoAccess β the function that decides whether an enrolling user's GitHub token has admin/maintain on the target repo β sat at 7.1% coverage, and discoverLiteInstallation (App-installation auto-discovery for enrollments that supply no installation_id) at 36.4%. New src/pkg/hub/lite_enrollment_authcheck_test.go: - verifyGitHubRepoAccess: admin/maintain grant, push-only denied, 401/403/404 as (false, nil), 5xx as errors naming status+body, malformed JSON, transport failure, GHE hosts checked against /api/v3, private hosts rejected before any request leaves the process (SSRF gate). - validateLiteGitHubHost: public GHE hostname passes, unresolvable fails closed. - liteRepoAccessHTTPClient: public redirect within the limit is allowed. - discoverLiteInstallation: app-without-key error, non-RSA key error, discovery success and org-not-found against a local httptest server. Requests reach a local httptest server via a scoped http.DefaultTransport swap (the client uses a nil Transport), mirroring the pattern in pkg/dashboard/import_test_transport_test.go. No production code changes. Coverage: verifyGitHubRepoAccess 7.1% -> 92.9%, discoverLiteInstallation 36.4% -> 100%, validateLiteGitHubHost and liteRepoAccessHTTPClient -> 100%. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Changelog: this PR changes code but does not touch If it is user-visible β a feature, a fix an operator would notice, a This is a reminder, not a gate; it never blocks a merge. |
|
Thank you for your contribution! Your PR has been merged. Check out what's new:
Stay connected: Slack #kubestellar-dev | Multi-Cluster Survey |
What this covers
Files/functions claimed:
src/pkg/hub/lite_enrollment.goβverifyGitHubRepoAccess,discoverLiteInstallation,validateLiteGitHubHost,liteRepoAccessHTTPClientβ via new test filesrc/pkg/hub/lite_enrollment_authcheck_test.go. Test-only; no production code changes.Disjoint from the open PR snapshot: #4939 covers
pkg/linearagent+ dashboard Linear token export, #4931 covers dashboard state-readout handlers, #4946/#4923/#4905 covercmd/*. None touchpkg/hub/lite_enrollment.go.Why
Every existing test stubs
verifyLiteRepoAccess, so the REALverifyGitHubRepoAccessβ the function that decides whether an enrolling user's GitHub token actually has admin/maintain on the target repo, i.e. the lite-enrollment authorization gate β sat at 7.1% coverage. A regression that returns true for a push-only token would silently over-grant enrollment.discoverLiteInstallation(App-installation auto-discovery when the enrollment supplies noinstallation_id) was at 36.4%.New tests
verifyGitHubRepoAccess: admin/maintain grant access; push-only does NOT; 401/403/404 are (false, nil) not errors; 5xx surfaces as an error naming status + body snippet; malformed JSON is a decode error; transport failure is reported; GHE hosts are checked against their/api/v3base with the caller's bearer token and Accept header asserted; private/internal hosts (incl.169.254.169.254) are rejected before any request leaves the process (SSRF gate).validateLiteGitHubHost: public GHE hostname passes; unresolvable host fails closed (complements the literal-prefix cases inlite_enrollment_branches_test.go).liteRepoAccessHTTPClient: a public redirect within the limit is allowed (the blocking branches are already covered inreach_pr_source_test.go).discoverLiteInstallation: cluster App with no uploaded key β actionableinstallation_id is required; non-RSA (EC) key βnot usable for discovery; discovery success (id adopted) and org-not-found against a local httptest server.Requests reach a local httptest server via a test-scoped
http.DefaultTransportswap (the production client uses a nil Transport), mirroringpkg/dashboard/import_test_transport_test.go; DNS is stubbed with the existingstubPrivateURLResolverhelper. Hermetic β no real network.Coverage
Full
go test ./pkg/hub/passes (141s),go vetclean, gofmt clean.Filed by quality agent (hold-gated mode). Human review required.
β hive: agent=quality backend=copilot model=claude-fable-5