Gate POST /api/chat on the same step-up as /tools (#317)
/api/chat reaches the router, the LLM and, through applyAction, the whole act path, so it is the widest state-changing surface mavweb serves. It was the only one with no gate. It now goes through stepUpOK like POST /tools, POST /routines and POST /api/revert: unchanged in the default deploy (WebAuthn unconfigured, fail-open behind wg+nginx), 403 under -require-stepup or an unasserted passkey session. The route table now carries an explicit enumeration of every state-changing route and its gate, and the two startup SECURITY log lines name /routines and /api/chat alongside /tools and /api/revert. The loopback -addr default the task also asked for landed earlier in d12de58; the compose already publishes mavweb on 127.0.0.1 only.
This commit is contained in:
@@ -63,6 +63,18 @@ type fakeCore struct {
|
||||
// for handleTrace tests
|
||||
tickTrace ipc.TickTrace
|
||||
traceErr error
|
||||
|
||||
// for handleChatAPI tests
|
||||
chatText string
|
||||
chatErr error
|
||||
}
|
||||
|
||||
func (f *fakeCore) Chat(_ context.Context, text string) (string, error) {
|
||||
f.chatText = text
|
||||
if f.chatErr != nil {
|
||||
return "", f.chatErr
|
||||
}
|
||||
return "поняла", nil
|
||||
}
|
||||
|
||||
func (f *fakeCore) EnableTool(_ context.Context, name string, cmd []string, destructive bool, scope string, _ time.Time) error {
|
||||
@@ -1045,3 +1057,64 @@ func TestHandleRoutines_NilCore_503(t *testing.T) {
|
||||
t.Fatalf("status = %d, want 503", rr.Code)
|
||||
}
|
||||
}
|
||||
|
||||
// --- handleChatAPI step-up gate (Vikunja #317) ---
|
||||
//
|
||||
// POST /api/chat reaches the router, the LLM and the act path, so it carries
|
||||
// the same gate as POST /tools and POST /api/revert.
|
||||
|
||||
func postChat(text string) *http.Request {
|
||||
req := httptest.NewRequest(http.MethodPost, "/api/chat", strings.NewReader("text="+url.QueryEscape(text)))
|
||||
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
|
||||
return req
|
||||
}
|
||||
|
||||
func TestHandleChatAPI_RequireStepUp_FailsClosed(t *testing.T) {
|
||||
core := &fakeCore{}
|
||||
rr := httptest.NewRecorder()
|
||||
handleChatAPI(rr, postChat("выключи свет"), core, nil, true)
|
||||
if rr.Code != http.StatusForbidden {
|
||||
t.Fatalf("status = %d, want 403; body=%s", rr.Code, rr.Body.String())
|
||||
}
|
||||
if core.chatText != "" {
|
||||
t.Errorf("core.Chat called with %q, but -require-stepup should deny", core.chatText)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleChatAPI_UnassertedSession_Denied(t *testing.T) {
|
||||
core := &fakeCore{}
|
||||
rr := httptest.NewRecorder()
|
||||
handleChatAPI(rr, postChat("выключи свет"), core, webauthn.NewPasskeySession(5*time.Minute), false)
|
||||
if rr.Code != http.StatusForbidden {
|
||||
t.Fatalf("status = %d, want 403", rr.Code)
|
||||
}
|
||||
if core.chatText != "" {
|
||||
t.Errorf("core.Chat called with %q despite an unasserted session", core.chatText)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleChatAPI_AssertedSession_PassesGate(t *testing.T) {
|
||||
core := &fakeCore{}
|
||||
rr := httptest.NewRecorder()
|
||||
handleChatAPI(rr, postChat("привет"), core, stepUpSession(), true)
|
||||
if rr.Code != http.StatusSeeOther {
|
||||
t.Fatalf("status = %d, want 303; body=%s", rr.Code, rr.Body.String())
|
||||
}
|
||||
if core.chatText != "привет" {
|
||||
t.Errorf("core.Chat text = %q, want %q", core.chatText, "привет")
|
||||
}
|
||||
}
|
||||
|
||||
// Default deploy: WebAuthn unconfigured and -require-stepup off ⇒ chat keeps
|
||||
// working, resting on the transport-level auth in front of mavweb.
|
||||
func TestHandleChatAPI_FailOpenByDefault(t *testing.T) {
|
||||
core := &fakeCore{}
|
||||
rr := httptest.NewRecorder()
|
||||
handleChatAPI(rr, postChat("привет"), core, nil, false)
|
||||
if rr.Code != http.StatusSeeOther {
|
||||
t.Fatalf("status = %d, want 303", rr.Code)
|
||||
}
|
||||
if core.chatText != "привет" {
|
||||
t.Errorf("core.Chat text = %q, want %q", core.chatText, "привет")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user