Files
OwnCord/Server/admin/audit_coverage_test.go
T
J3vbandClaude Fable 5 63c87df487 refactor(b3-8): settings/audit family behind SettingsService (S-09, family 1) (#1477)
* feat(service): settings family — SettingsService over the Store seam

The B3-8 settings/audit family's service: List, Patch (whitelist,
boolean normalization, the require_2fa preconditions incl. the TOTP
census and the unrelated-key guard, atomic apply, one audit row per
changed key) and Setting (the read the hub and the backup scheduler
consume; wraps db.ErrNotFound as the store reports it). db gains
ApplySettings — the handler's raw upsert loop as one hand-written
transactional wrapper where raw SQL belongs — and Store carries it.

parseSettingsPatchBool duplicates auth.go's parseBooleanSettingValue
with the admin surface's own pinned error wording; both messages are
test-pinned, so the twins stay separate.

Service-level characterization in settings_test.go mirrors the
admin/api_test.go PATCH rows and adds the service-only contracts
(ErrNotFound wrap, audit rows, multi-key apply).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

* refactor(admin): settings handlers thin over SettingsService; scheduler reads via it

handleGetSettings/handlePatchSettings become adapters (decode, delegate,
map ErrBadRequest to 400 with the service's prefix-free message); the
whitelist and every precondition now live only in the service, so
admin/types.go's copy is gone. MaintainBackups reads backup_schedule and
backup_retention through the service — its backup mechanics keep the
handle — and the maintenance chain threads Settings from the runtime the
hub stage built. NewHandler/NewAdminAPI gain the settings parameter;
all 207 construction sites wired via the newTestSettingsService helper.

Behavior parity pinned by the existing TestAdminAPI_*Settings* rows
(all green); the only unpinned change is the PATCH 500 path collapsing
its four stage-specific internal messages into one.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

* refactor(ws): hub settings cache reads through a SettingsReader

The hub's server_name/motd cache consumes a consumer-side SettingsReader
interface (service.SettingsService satisfies it; HubOptions.Settings is
required and validated like DB and Limiter — the RequiredCollaborators
pin gains the refusal case). hub_settings.go no longer touches db at
all, so the import pin from the B3-5 finisher goes, and its allowlist
row goes with it; the thinned admin settings handler's row is deleted
too — two allowlist rows down, the settings family's persistence now
lives only in db/ and service/.

Test helpers (both ws package namespaces) default the reader over the
test database; newBareHub wires it explicitly; production passes
Services.Settings from StartRuntime.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

* docs(boundaries,b3): settings/audit family re-measure and evidence

The backup pair takes its forecast boundary disposition; the family's
two deleted rows and the disposition counts (28/18/15 -> 24/18/17)
re-derived from the tool. Family evidence block appended to the B3-8
section; README B3 row records B3-5 complete and the family opened.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

* fix(service): prefix-free ErrBadRequest wraps for the pinned admin bodies

The %.0w rework was meant to ride the service commit but was left
unstaged: with the plain %w wrap the PATCH error bodies carry a
'bad request: ' prefix the admin pins reject. Zero-width wrapping keeps
errors.Is(ErrBadRequest) while err.Error() stays exactly the pinned
message.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

* test(app): lifecycle hub fixtures wire the required Settings reader

The two direct ws.NewHub sites in lifecycle_test predate Settings
becoming required; race across internal/app is green again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

* test(db): cover ApplySettings — the db coverage floor caught the gap

CI's coverage floor failed db at 78.9% against 79.3%: ApplySettings was
exercised only from service tests, which do not count toward db's own
figure. Four db-side rows cover the apply, the empty no-op, the
in-transaction failure rollback and the begin failure, using the
package's full-migration opener.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

* chore(coverage): raise the service floor to the branch's measured 69.2

The settings family's tested service code raised the Linux figure from
the 67.8 floor to 69.2; the ratchet raises the floor in the same PR
(service is not in the run-varying set). db stays at 79.3 — this PR
restores its figure (79.5 with the ApplySettings tests), it did not set
out to raise it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-31 15:13:38 +00:00

172 lines
7.0 KiB
Go

package admin_test
import (
"context"
"encoding/json"
"net/http"
"path/filepath"
"testing"
"github.com/J3vb/OwnCord/Server/admin"
"github.com/J3vb/OwnCord/Server/db"
"github.com/J3vb/OwnCord/Server/db/audittest"
"github.com/J3vb/OwnCord/Server/permissions"
)
// TestAuditCoverage_AdminMutations is the B2-6 audit table for the
// admin-owned security-sensitive mutations: channel permission edits (role
// and user layer), API-token create/revoke, settings changes and the setup
// wizard's config write. The closing subtest runs the detail denylist over
// the recorded corpus (plan docs/plans/b2-protocol-trust-compat-2026-08-28.md
// § B2-6).
func TestAuditCoverage_AdminMutations(t *testing.T) {
// fixture returns a handler, an owner token and a channel id, with the
// recorder installed after seeding.
fixture := func(t *testing.T) (http.Handler, *db.DB, string, int64) {
t.Helper()
database := openAdminTestDB(t)
handler := admin.NewAdminAPI(database, "1.0.0", &mockHub{}, nil, nil, nil, &mockPermInvalidator{},
newTestModService(database), newTestRoleService(database), newTestSettingsService(database))
token := createAdminUser(t, database)
chID, err := database.CreateChannel(context.Background(), "secret", "text", "", "", 0)
if err != nil {
t.Fatalf("CreateChannel: %v", err)
}
return handler, database, token, chID
}
rows := []struct {
name string
action string
run func(t *testing.T) (*audittest.Recorder, []string)
}{
{"channel role perms set", "channel_perms_update", func(t *testing.T) (*audittest.Recorder, []string) {
handler, database, token, chID := fixture(t)
rec := audittest.Install(t, database)
w := doRequest(t, handler, http.MethodPut, "/channels/"+itoa(chID)+"/permissions/3", token,
map[string]any{"allow": 0, "deny": permissions.ReadMessages})
if w.Code != http.StatusOK {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
return rec, nil
}},
{"channel role perms clear", "channel_perms_clear", func(t *testing.T) (*audittest.Recorder, []string) {
handler, database, token, chID := fixture(t)
if w := doRequest(t, handler, http.MethodPut, "/channels/"+itoa(chID)+"/permissions/3", token,
map[string]any{"allow": 0, "deny": permissions.ReadMessages}); w.Code != http.StatusOK {
t.Fatalf("seed override: status = %d; body = %s", w.Code, w.Body.String())
}
rec := audittest.Install(t, database)
w := doRequest(t, handler, http.MethodDelete, "/channels/"+itoa(chID)+"/permissions/3", token, nil)
if w.Code != http.StatusNoContent && w.Code != http.StatusOK {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
return rec, nil
}},
{"channel user perms set", "channel_user_perms_update", func(t *testing.T) (*audittest.Recorder, []string) {
handler, database, token, chID := fixture(t)
target := seedOverrideTarget(t, database, "override-target")
rec := audittest.Install(t, database)
w := doRequest(t, handler, http.MethodPut, "/channels/"+itoa(chID)+"/user-permissions/"+itoa(target), token,
map[string]any{"allow": permissions.ReadMessages, "deny": permissions.SendMessages})
if w.Code != http.StatusOK {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
return rec, nil
}},
{"channel user perms clear", "channel_user_perms_clear", func(t *testing.T) (*audittest.Recorder, []string) {
handler, database, token, chID := fixture(t)
target := seedOverrideTarget(t, database, "override-target")
if w := doRequest(t, handler, http.MethodPut, "/channels/"+itoa(chID)+"/user-permissions/"+itoa(target), token,
map[string]any{"allow": permissions.ReadMessages, "deny": permissions.SendMessages}); w.Code != http.StatusOK {
t.Fatalf("seed override: status = %d; body = %s", w.Code, w.Body.String())
}
rec := audittest.Install(t, database)
w := doRequest(t, handler, http.MethodDelete, "/channels/"+itoa(chID)+"/user-permissions/"+itoa(target), token, nil)
if w.Code != http.StatusNoContent && w.Code != http.StatusOK {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
return rec, nil
}},
{"api token create", "api_token_create", func(t *testing.T) (*audittest.Recorder, []string) {
handler, database, token, _ := fixture(t)
rec := audittest.Install(t, database)
w := doRequest(t, handler, http.MethodPost, "/tokens", token,
map[string]any{"label": "ci bot", "username": "adminuser"})
if w.Code != http.StatusCreated {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
var resp struct {
Token string `json:"token"`
}
_ = json.Unmarshal(w.Body.Bytes(), &resp)
return rec, []string{resp.Token, token}
}},
{"api token revoke", "api_token_revoke", func(t *testing.T) (*audittest.Recorder, []string) {
handler, database, token, _ := fixture(t)
w := doRequest(t, handler, http.MethodPost, "/tokens", token,
map[string]any{"label": "ci bot", "username": "adminuser"})
if w.Code != http.StatusCreated {
t.Fatalf("seed token: status = %d; body = %s", w.Code, w.Body.String())
}
var resp struct {
ID int64 `json:"id"`
Token string `json:"token"`
}
_ = json.Unmarshal(w.Body.Bytes(), &resp)
rec := audittest.Install(t, database)
if w := doRequest(t, handler, http.MethodDelete, "/tokens/"+itoa(resp.ID), token, nil); w.Code != http.StatusNoContent {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
return rec, []string{resp.Token, token}
}},
{"setting change", "setting_change", func(t *testing.T) (*audittest.Recorder, []string) {
handler, database, token, _ := fixture(t)
rec := audittest.Install(t, database)
w := doRequest(t, handler, http.MethodPatch, "/settings", token,
map[string]string{"motd": "welcome 4d0d1405"})
if w.Code != http.StatusOK {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
return rec, []string{"welcome 4d0d1405", token}
}},
{"config write (setup wizard)", "config_write", func(t *testing.T) (*audittest.Recorder, []string) {
database := openAdminTestDB(t)
cfgPath := filepath.Join(t.TempDir(), "config.yaml")
handler := wizardHandler(t, database, cfgPath, make(chan string, 1))
rec := audittest.Install(t, database)
const password = "SecurePass123!"
w := doRequest(t, handler, http.MethodPost, "/setup", "", map[string]any{
"username": "owner",
"password": password,
"wizard": map[string]any{"server_name": "Audit Server"},
})
if w.Code != http.StatusCreated {
t.Fatalf("status = %d; body = %s", w.Code, w.Body.String())
}
var resp struct {
Token string `json:"token"`
}
_ = json.Unmarshal(w.Body.Bytes(), &resp)
return rec, []string{password, resp.Token}
}},
}
var corpus []db.AuditEntry
var secrets []string
for _, row := range rows {
t.Run(row.name, func(t *testing.T) {
rec, s := row.run(t)
rec.Wait(t, row.action)
corpus = append(corpus, rec.Entries()...)
secrets = append(secrets, s...)
})
}
t.Run("detail denylist", func(t *testing.T) {
if len(corpus) == 0 {
t.Fatal("no audit entries recorded")
}
audittest.AssertSafeDetails(t, corpus, secrets...)
})
}