mirror of
https://github.com/lukaszraczylo/gohoarder.git
synced 2026-07-22 06:20:09 +00:00
Multi-agent audit + fix pass covering bugs, security, dead config wiring,
and missing features. All quality gates green: build/vet/test -race/govulncheck/
golangci-lint. Frontend tests 47/47.
SECURITY & CORRECTNESS
- Scanner pipeline fail-closed: cache.go scan timeout now 503 (was goto servePkg);
scanner.go all-scanners-fail saves ScanStatusError; CheckVulnerabilities blocks
on missing/error result instead of allowing.
- Scanner argv corrections: govulncheck source-mode + go.mod discovery;
npm-audit generates lockfile via npm install --package-lock-only --ignore-scripts;
pip-audit per-extension dispatch (wheel direct / sdist extract+pyproject).
- GHSA version-range filtering implemented (was always-include); url.QueryEscape
on package name.
- pypi SSRF closed via host allowlist on original_url; url.QueryEscape on
rewriteURL output.
- Path traversal: cache temp file uses os.CreateTemp; smb keyToPath sanitized;
filesystem keyToPath returns error + filepath.Abs prefix-verify.
- Goroutine leaks plugged: cache.cleanupWorker stop channel; auth.ValidationCache
Stop() with sync.Once; ws.unregister buffered with non-blocking send.
- WebSocket double-close panic fixed via sync.Once Client.closeSend().
- Race conditions: gormstore.registryCache sync.RWMutex (was concurrent map
panic); auth.LastUsedAt no longer mutated under RLock; analytics strict
lock-ordering invariant (statsMu before downloadsMu).
- Auth validator fails CLOSED on transport/unknown-status errors (was returning
true,err 'allow cache fallback').
- Credential cache hash full SHA256 (was 8-byte truncate; eliminates 2^32
collision risk).
- filesystem.fs.used incremented after successful rename (no quota inflation
race).
- gormstore aggregation events deleted in same tx as insert (no double-counting).
- gormstore.SavePackage uses Updates(map) so zero-value security flags
(RequiresAuth=false) can be cleared.
- partition_manager validates partition name regex before DROP TABLE.
- vcs/git: version regex validation rejects --option-injection; checkout uses
--detach -- separator; removed TrimPrefix(repo,'v') that corrupted vault/
vitess/vim-go.
- WebSocket CheckOrigin allowlist (was return true; CSWSH closed); same-origin
default + ServerConfig.AllowedOrigins.
- fiber CVE GO-2026-4543 patched (v2.52.10 -> v2.52.12).
FUNCTIONAL FEATURES
- API key DB persistence: APIKeyModel + migration 202604280002, full CRUD,
async LastUsedAt updates with WaitGroup-tracked goroutines drained on Close.
- Admin bootstrap via GOHOARDER_BOOTSTRAP_ADMIN_KEY env var; idempotent
(skipped when non-revoked admin already exists).
- Auth middleware factory in pkg/app: RequireAuth, RequireRole, RequirePermission,
OptionalAuth. Mounted on proxy + read APIs when Auth.Enabled=true.
DELETE /api/packages/* requires admin role. /health public for k8s probes.
- NFS storage backend: pkg/storage/nfs wraps filesystem with /proc/mounts
detection (Linux), post-write fsync, read-after-write health probe.
- WebSocket real-time pipeline: pkg/events Broadcaster interface; cache + scanner
managers emit EventPackageCached / EventPackageDownloaded / EventScanComplete;
app.go runs 30s EventStatsUpdate ticker. Frontend has full WS client (reconnect
with exponential backoff 1s->30s, 25s heartbeat, subscriber pattern), Pinia
realtime store, Dashboard live indicator + activity feed + reactive stats
override.
- TLS termination: fiber.ListenTLS when Server.TLS.Enabled.
- Pre-warming: Prewarming.Enabled flag wired (was hardcoded false); Interval,
MaxConcurrent, TopPackages plumbed.
- NetworkConfig wired (timeouts, retry, rate-limit, circuit-breaker).
- AuthConfig.BcryptCost wired.
- Security.Scanners.Static.MaxPackageSize plumbed to cache.io.LimitReader.
- Handlers.{Go,NPM,PyPI}.Enabled gates route mounting.
- Graceful shutdown: authManager.Close drains async writes.
LINT/HYGIENE
- 80 golangci-lint issues resolved: errcheck (Close/Write/RemoveAll wrapped),
gofmt, gosec G104/G306, govet shadow renames + fieldalignment reorders,
staticcheck ST1000 pkg comments + QF1003 tagged switches + QF1008 embedded
field selectors + QF1001 De Morgan's law.
BEHAVIOR CHANGES
- Scanner now fail-closed: deployments without scanner binaries
(trivy/govulncheck/npm-audit/pip-audit/grype) BLOCK packages instead of
serving unscanned. Add binaries or plan a future allow-on-scan-error flag.
- WS origin defaults to same-origin; cross-origin dashboards must set
server.allowed_origins.
- Validator no longer fails open; private packages won't serve from cache when
validation can't be performed.
- download_events retention dropped from 24h to ~5min (deleted in agg tx).
Migration 202604280001 purges pre-upgrade events.
- DELETE /api/packages/* requires admin role when auth enabled.
NEW PACKAGES
- pkg/events - Broadcaster interface
- pkg/storage/nfs - NFS-aware filesystem wrapper
DEFERRED (out of scope this pass)
- Static scanner implementation (config defines AllowedLicenses/MaxPackageSize/
BlockSuspicious but pkg/scanner/static/ does not exist).
- AuthConfig.AuditLog wiring (no audit log infra yet).
- CacheConfig.TTLOverrides passthrough (would touch cache.Config beyond
integrator scope).
224 lines
6.5 KiB
TypeScript
224 lines
6.5 KiB
TypeScript
import { describe, it, expect, beforeEach, afterEach, vi } from 'vitest'
|
|
import { WSClient, __wsInternals, type RealtimeEvent } from './ws'
|
|
|
|
/**
|
|
* Minimal WebSocket stub mimicking the parts of the browser API the WSClient
|
|
* touches: readyState, onopen, onmessage, onclose, onerror, send, close.
|
|
*/
|
|
class StubWebSocket {
|
|
static OPEN = 1
|
|
static CLOSED = 3
|
|
static instances: StubWebSocket[] = []
|
|
|
|
url: string
|
|
readyState = 0
|
|
sent: string[] = []
|
|
onopen: ((ev: Event) => void) | null = null
|
|
onmessage: ((ev: MessageEvent) => void) | null = null
|
|
onclose: ((ev: CloseEvent) => void) | null = null
|
|
onerror: ((ev: Event) => void) | null = null
|
|
|
|
constructor(url: string) {
|
|
this.url = url
|
|
StubWebSocket.instances.push(this)
|
|
}
|
|
|
|
// Test helpers
|
|
open(): void {
|
|
this.readyState = StubWebSocket.OPEN
|
|
this.onopen?.(new Event('open'))
|
|
}
|
|
|
|
receive(data: unknown): void {
|
|
const text = typeof data === 'string' ? data : JSON.stringify(data)
|
|
this.onmessage?.({ data: text } as MessageEvent)
|
|
}
|
|
|
|
triggerClose(): void {
|
|
this.readyState = StubWebSocket.CLOSED
|
|
this.onclose?.({} as CloseEvent)
|
|
}
|
|
|
|
// Real API
|
|
send(payload: string): void {
|
|
this.sent.push(payload)
|
|
}
|
|
|
|
close(): void {
|
|
this.readyState = StubWebSocket.CLOSED
|
|
this.onclose?.({} as CloseEvent)
|
|
}
|
|
}
|
|
|
|
const originalWebSocket = (globalThis as { WebSocket?: typeof WebSocket }).WebSocket
|
|
|
|
beforeEach(() => {
|
|
StubWebSocket.instances = []
|
|
;(globalThis as unknown as { WebSocket: unknown }).WebSocket = StubWebSocket
|
|
})
|
|
|
|
afterEach(() => {
|
|
;(globalThis as unknown as { WebSocket: unknown }).WebSocket = originalWebSocket
|
|
vi.useRealTimers()
|
|
})
|
|
|
|
describe('parseEvent', () => {
|
|
it('normalizes backend envelope (data + RFC3339 timestamp)', () => {
|
|
const evt = __wsInternals.parseEvent(
|
|
JSON.stringify({
|
|
type: 'package_cached',
|
|
timestamp: '2026-04-28T12:00:00Z',
|
|
data: { name: 'lodash', version: '4.17.21', registry: 'npm' },
|
|
}),
|
|
)
|
|
expect(evt).not.toBeNull()
|
|
expect(evt!.type).toBe('package_cached')
|
|
expect(evt!.payload).toMatchObject({ name: 'lodash' })
|
|
expect(evt!.timestamp).toBe(Date.parse('2026-04-28T12:00:00Z'))
|
|
})
|
|
|
|
it('drops malformed JSON', () => {
|
|
expect(__wsInternals.parseEvent('not-json{{')).toBeNull()
|
|
})
|
|
|
|
it('drops unknown event types (e.g. control frames)', () => {
|
|
expect(
|
|
__wsInternals.parseEvent(JSON.stringify({ type: 'pong' })),
|
|
).toBeNull()
|
|
})
|
|
|
|
it('accepts numeric timestamp', () => {
|
|
const evt = __wsInternals.parseEvent(
|
|
JSON.stringify({ type: 'stats_update', timestamp: 1234567890, data: {} }),
|
|
)
|
|
expect(evt!.timestamp).toBe(1234567890)
|
|
})
|
|
})
|
|
|
|
describe('WSClient', () => {
|
|
it('connects and dispatches typed events to subscribers', () => {
|
|
const client = new WSClient('ws://test/ws')
|
|
const received: RealtimeEvent[] = []
|
|
client.on('package_cached', (e) => received.push(e))
|
|
client.connect()
|
|
|
|
const sock = StubWebSocket.instances[0]
|
|
expect(sock).toBeDefined()
|
|
sock.open()
|
|
sock.receive({
|
|
type: 'package_cached',
|
|
timestamp: '2026-04-28T00:00:00Z',
|
|
data: { name: 'foo' },
|
|
})
|
|
|
|
expect(received).toHaveLength(1)
|
|
expect(received[0].type).toBe('package_cached')
|
|
expect(received[0].payload.name).toBe('foo')
|
|
client.close()
|
|
})
|
|
|
|
it('forwards events to wildcard subscribers', () => {
|
|
const client = new WSClient('ws://test/ws')
|
|
const seen: string[] = []
|
|
client.on('*', (e) => seen.push(e.type))
|
|
client.connect()
|
|
const sock = StubWebSocket.instances[0]
|
|
sock.open()
|
|
sock.receive({ type: 'scan_complete', data: {} })
|
|
sock.receive({ type: 'package_deleted', data: {} })
|
|
expect(seen).toEqual(['scan_complete', 'package_deleted'])
|
|
client.close()
|
|
})
|
|
|
|
it('unsubscribe stops further dispatches', () => {
|
|
const client = new WSClient('ws://test/ws')
|
|
let count = 0
|
|
const off = client.on('package_cached', () => {
|
|
count += 1
|
|
})
|
|
client.connect()
|
|
const sock = StubWebSocket.instances[0]
|
|
sock.open()
|
|
sock.receive({ type: 'package_cached', data: {} })
|
|
expect(count).toBe(1)
|
|
off()
|
|
sock.receive({ type: 'package_cached', data: {} })
|
|
expect(count).toBe(1)
|
|
client.close()
|
|
})
|
|
|
|
it('auto-reconnects with backoff after unexpected close', () => {
|
|
vi.useFakeTimers()
|
|
const client = new WSClient('ws://test/ws')
|
|
client.connect()
|
|
const first = StubWebSocket.instances[0]
|
|
first.open()
|
|
first.triggerClose()
|
|
|
|
// First reconnect happens after RECONNECT_BASE_MS (1s).
|
|
vi.advanceTimersByTime(__wsInternals.RECONNECT_BASE_MS)
|
|
expect(StubWebSocket.instances.length).toBe(2)
|
|
|
|
// Second drop -> next backoff is 2s.
|
|
StubWebSocket.instances[1].open()
|
|
StubWebSocket.instances[1].triggerClose()
|
|
vi.advanceTimersByTime(__wsInternals.RECONNECT_BASE_MS * 2)
|
|
expect(StubWebSocket.instances.length).toBe(3)
|
|
|
|
client.close()
|
|
})
|
|
|
|
it('does not reconnect after explicit close', () => {
|
|
vi.useFakeTimers()
|
|
const client = new WSClient('ws://test/ws')
|
|
client.connect()
|
|
const sock = StubWebSocket.instances[0]
|
|
sock.open()
|
|
client.close()
|
|
vi.advanceTimersByTime(60_000)
|
|
expect(StubWebSocket.instances.length).toBe(1)
|
|
})
|
|
|
|
it('emits heartbeat ping every 25s', () => {
|
|
vi.useFakeTimers()
|
|
const client = new WSClient('ws://test/ws')
|
|
client.connect()
|
|
const sock = StubWebSocket.instances[0]
|
|
sock.open()
|
|
expect(sock.sent).toHaveLength(0)
|
|
vi.advanceTimersByTime(__wsInternals.HEARTBEAT_INTERVAL_MS)
|
|
expect(sock.sent).toHaveLength(1)
|
|
expect(JSON.parse(sock.sent[0])).toEqual({ action: 'ping' })
|
|
vi.advanceTimersByTime(__wsInternals.HEARTBEAT_INTERVAL_MS)
|
|
expect(sock.sent).toHaveLength(2)
|
|
client.close()
|
|
})
|
|
|
|
it('queues outbound messages while disconnected and flushes on open', () => {
|
|
const client = new WSClient('ws://test/ws')
|
|
client.send({ action: 'subscribe', data: ['package_cached'] })
|
|
client.connect()
|
|
const sock = StubWebSocket.instances[0]
|
|
expect(sock.sent).toHaveLength(0)
|
|
sock.open()
|
|
expect(sock.sent).toHaveLength(1)
|
|
expect(JSON.parse(sock.sent[0])).toMatchObject({ action: 'subscribe' })
|
|
client.close()
|
|
})
|
|
|
|
it('drops malformed inbound JSON without throwing', () => {
|
|
const client = new WSClient('ws://test/ws')
|
|
let count = 0
|
|
client.on('*', () => {
|
|
count += 1
|
|
})
|
|
client.connect()
|
|
const sock = StubWebSocket.instances[0]
|
|
sock.open()
|
|
sock.receive('not-json{{{')
|
|
sock.receive({ type: 'unknown_type', data: {} })
|
|
expect(count).toBe(0)
|
|
client.close()
|
|
})
|
|
})
|