Files
gohoarder/frontend/src/lib/ws.spec.ts
T
lukaszraczylo e39d6a0f0d feat: comprehensive audit + Tier 3 wiring (security/correctness/features)
Multi-agent audit + fix pass covering bugs, security, dead config wiring,
and missing features. All quality gates green: build/vet/test -race/govulncheck/
golangci-lint. Frontend tests 47/47.

SECURITY & CORRECTNESS

- Scanner pipeline fail-closed: cache.go scan timeout now 503 (was goto servePkg);
  scanner.go all-scanners-fail saves ScanStatusError; CheckVulnerabilities blocks
  on missing/error result instead of allowing.
- Scanner argv corrections: govulncheck source-mode + go.mod discovery;
  npm-audit generates lockfile via npm install --package-lock-only --ignore-scripts;
  pip-audit per-extension dispatch (wheel direct / sdist extract+pyproject).
- GHSA version-range filtering implemented (was always-include); url.QueryEscape
  on package name.
- pypi SSRF closed via host allowlist on original_url; url.QueryEscape on
  rewriteURL output.
- Path traversal: cache temp file uses os.CreateTemp; smb keyToPath sanitized;
  filesystem keyToPath returns error + filepath.Abs prefix-verify.
- Goroutine leaks plugged: cache.cleanupWorker stop channel; auth.ValidationCache
  Stop() with sync.Once; ws.unregister buffered with non-blocking send.
- WebSocket double-close panic fixed via sync.Once Client.closeSend().
- Race conditions: gormstore.registryCache sync.RWMutex (was concurrent map
  panic); auth.LastUsedAt no longer mutated under RLock; analytics strict
  lock-ordering invariant (statsMu before downloadsMu).
- Auth validator fails CLOSED on transport/unknown-status errors (was returning
  true,err 'allow cache fallback').
- Credential cache hash full SHA256 (was 8-byte truncate; eliminates 2^32
  collision risk).
- filesystem.fs.used incremented after successful rename (no quota inflation
  race).
- gormstore aggregation events deleted in same tx as insert (no double-counting).
- gormstore.SavePackage uses Updates(map) so zero-value security flags
  (RequiresAuth=false) can be cleared.
- partition_manager validates partition name regex before DROP TABLE.
- vcs/git: version regex validation rejects --option-injection; checkout uses
  --detach -- separator; removed TrimPrefix(repo,'v') that corrupted vault/
  vitess/vim-go.
- WebSocket CheckOrigin allowlist (was return true; CSWSH closed); same-origin
  default + ServerConfig.AllowedOrigins.
- fiber CVE GO-2026-4543 patched (v2.52.10 -> v2.52.12).

FUNCTIONAL FEATURES

- API key DB persistence: APIKeyModel + migration 202604280002, full CRUD,
  async LastUsedAt updates with WaitGroup-tracked goroutines drained on Close.
- Admin bootstrap via GOHOARDER_BOOTSTRAP_ADMIN_KEY env var; idempotent
  (skipped when non-revoked admin already exists).
- Auth middleware factory in pkg/app: RequireAuth, RequireRole, RequirePermission,
  OptionalAuth. Mounted on proxy + read APIs when Auth.Enabled=true.
  DELETE /api/packages/* requires admin role. /health public for k8s probes.
- NFS storage backend: pkg/storage/nfs wraps filesystem with /proc/mounts
  detection (Linux), post-write fsync, read-after-write health probe.
- WebSocket real-time pipeline: pkg/events Broadcaster interface; cache + scanner
  managers emit EventPackageCached / EventPackageDownloaded / EventScanComplete;
  app.go runs 30s EventStatsUpdate ticker. Frontend has full WS client (reconnect
  with exponential backoff 1s->30s, 25s heartbeat, subscriber pattern), Pinia
  realtime store, Dashboard live indicator + activity feed + reactive stats
  override.
- TLS termination: fiber.ListenTLS when Server.TLS.Enabled.
- Pre-warming: Prewarming.Enabled flag wired (was hardcoded false); Interval,
  MaxConcurrent, TopPackages plumbed.
- NetworkConfig wired (timeouts, retry, rate-limit, circuit-breaker).
- AuthConfig.BcryptCost wired.
- Security.Scanners.Static.MaxPackageSize plumbed to cache.io.LimitReader.
- Handlers.{Go,NPM,PyPI}.Enabled gates route mounting.
- Graceful shutdown: authManager.Close drains async writes.

LINT/HYGIENE

- 80 golangci-lint issues resolved: errcheck (Close/Write/RemoveAll wrapped),
  gofmt, gosec G104/G306, govet shadow renames + fieldalignment reorders,
  staticcheck ST1000 pkg comments + QF1003 tagged switches + QF1008 embedded
  field selectors + QF1001 De Morgan's law.

BEHAVIOR CHANGES

- Scanner now fail-closed: deployments without scanner binaries
  (trivy/govulncheck/npm-audit/pip-audit/grype) BLOCK packages instead of
  serving unscanned. Add binaries or plan a future allow-on-scan-error flag.
- WS origin defaults to same-origin; cross-origin dashboards must set
  server.allowed_origins.
- Validator no longer fails open; private packages won't serve from cache when
  validation can't be performed.
- download_events retention dropped from 24h to ~5min (deleted in agg tx).
  Migration 202604280001 purges pre-upgrade events.
- DELETE /api/packages/* requires admin role when auth enabled.

NEW PACKAGES

- pkg/events  - Broadcaster interface
- pkg/storage/nfs  - NFS-aware filesystem wrapper

DEFERRED (out of scope this pass)

- Static scanner implementation (config defines AllowedLicenses/MaxPackageSize/
  BlockSuspicious but pkg/scanner/static/ does not exist).
- AuthConfig.AuditLog wiring (no audit log infra yet).
- CacheConfig.TTLOverrides passthrough (would touch cache.Config beyond
  integrator scope).
2026-07-10 09:37:55 +01:00

224 lines
6.5 KiB
TypeScript

import { describe, it, expect, beforeEach, afterEach, vi } from 'vitest'
import { WSClient, __wsInternals, type RealtimeEvent } from './ws'
/**
* Minimal WebSocket stub mimicking the parts of the browser API the WSClient
* touches: readyState, onopen, onmessage, onclose, onerror, send, close.
*/
class StubWebSocket {
static OPEN = 1
static CLOSED = 3
static instances: StubWebSocket[] = []
url: string
readyState = 0
sent: string[] = []
onopen: ((ev: Event) => void) | null = null
onmessage: ((ev: MessageEvent) => void) | null = null
onclose: ((ev: CloseEvent) => void) | null = null
onerror: ((ev: Event) => void) | null = null
constructor(url: string) {
this.url = url
StubWebSocket.instances.push(this)
}
// Test helpers
open(): void {
this.readyState = StubWebSocket.OPEN
this.onopen?.(new Event('open'))
}
receive(data: unknown): void {
const text = typeof data === 'string' ? data : JSON.stringify(data)
this.onmessage?.({ data: text } as MessageEvent)
}
triggerClose(): void {
this.readyState = StubWebSocket.CLOSED
this.onclose?.({} as CloseEvent)
}
// Real API
send(payload: string): void {
this.sent.push(payload)
}
close(): void {
this.readyState = StubWebSocket.CLOSED
this.onclose?.({} as CloseEvent)
}
}
const originalWebSocket = (globalThis as { WebSocket?: typeof WebSocket }).WebSocket
beforeEach(() => {
StubWebSocket.instances = []
;(globalThis as unknown as { WebSocket: unknown }).WebSocket = StubWebSocket
})
afterEach(() => {
;(globalThis as unknown as { WebSocket: unknown }).WebSocket = originalWebSocket
vi.useRealTimers()
})
describe('parseEvent', () => {
it('normalizes backend envelope (data + RFC3339 timestamp)', () => {
const evt = __wsInternals.parseEvent(
JSON.stringify({
type: 'package_cached',
timestamp: '2026-04-28T12:00:00Z',
data: { name: 'lodash', version: '4.17.21', registry: 'npm' },
}),
)
expect(evt).not.toBeNull()
expect(evt!.type).toBe('package_cached')
expect(evt!.payload).toMatchObject({ name: 'lodash' })
expect(evt!.timestamp).toBe(Date.parse('2026-04-28T12:00:00Z'))
})
it('drops malformed JSON', () => {
expect(__wsInternals.parseEvent('not-json{{')).toBeNull()
})
it('drops unknown event types (e.g. control frames)', () => {
expect(
__wsInternals.parseEvent(JSON.stringify({ type: 'pong' })),
).toBeNull()
})
it('accepts numeric timestamp', () => {
const evt = __wsInternals.parseEvent(
JSON.stringify({ type: 'stats_update', timestamp: 1234567890, data: {} }),
)
expect(evt!.timestamp).toBe(1234567890)
})
})
describe('WSClient', () => {
it('connects and dispatches typed events to subscribers', () => {
const client = new WSClient('ws://test/ws')
const received: RealtimeEvent[] = []
client.on('package_cached', (e) => received.push(e))
client.connect()
const sock = StubWebSocket.instances[0]
expect(sock).toBeDefined()
sock.open()
sock.receive({
type: 'package_cached',
timestamp: '2026-04-28T00:00:00Z',
data: { name: 'foo' },
})
expect(received).toHaveLength(1)
expect(received[0].type).toBe('package_cached')
expect(received[0].payload.name).toBe('foo')
client.close()
})
it('forwards events to wildcard subscribers', () => {
const client = new WSClient('ws://test/ws')
const seen: string[] = []
client.on('*', (e) => seen.push(e.type))
client.connect()
const sock = StubWebSocket.instances[0]
sock.open()
sock.receive({ type: 'scan_complete', data: {} })
sock.receive({ type: 'package_deleted', data: {} })
expect(seen).toEqual(['scan_complete', 'package_deleted'])
client.close()
})
it('unsubscribe stops further dispatches', () => {
const client = new WSClient('ws://test/ws')
let count = 0
const off = client.on('package_cached', () => {
count += 1
})
client.connect()
const sock = StubWebSocket.instances[0]
sock.open()
sock.receive({ type: 'package_cached', data: {} })
expect(count).toBe(1)
off()
sock.receive({ type: 'package_cached', data: {} })
expect(count).toBe(1)
client.close()
})
it('auto-reconnects with backoff after unexpected close', () => {
vi.useFakeTimers()
const client = new WSClient('ws://test/ws')
client.connect()
const first = StubWebSocket.instances[0]
first.open()
first.triggerClose()
// First reconnect happens after RECONNECT_BASE_MS (1s).
vi.advanceTimersByTime(__wsInternals.RECONNECT_BASE_MS)
expect(StubWebSocket.instances.length).toBe(2)
// Second drop -> next backoff is 2s.
StubWebSocket.instances[1].open()
StubWebSocket.instances[1].triggerClose()
vi.advanceTimersByTime(__wsInternals.RECONNECT_BASE_MS * 2)
expect(StubWebSocket.instances.length).toBe(3)
client.close()
})
it('does not reconnect after explicit close', () => {
vi.useFakeTimers()
const client = new WSClient('ws://test/ws')
client.connect()
const sock = StubWebSocket.instances[0]
sock.open()
client.close()
vi.advanceTimersByTime(60_000)
expect(StubWebSocket.instances.length).toBe(1)
})
it('emits heartbeat ping every 25s', () => {
vi.useFakeTimers()
const client = new WSClient('ws://test/ws')
client.connect()
const sock = StubWebSocket.instances[0]
sock.open()
expect(sock.sent).toHaveLength(0)
vi.advanceTimersByTime(__wsInternals.HEARTBEAT_INTERVAL_MS)
expect(sock.sent).toHaveLength(1)
expect(JSON.parse(sock.sent[0])).toEqual({ action: 'ping' })
vi.advanceTimersByTime(__wsInternals.HEARTBEAT_INTERVAL_MS)
expect(sock.sent).toHaveLength(2)
client.close()
})
it('queues outbound messages while disconnected and flushes on open', () => {
const client = new WSClient('ws://test/ws')
client.send({ action: 'subscribe', data: ['package_cached'] })
client.connect()
const sock = StubWebSocket.instances[0]
expect(sock.sent).toHaveLength(0)
sock.open()
expect(sock.sent).toHaveLength(1)
expect(JSON.parse(sock.sent[0])).toMatchObject({ action: 'subscribe' })
client.close()
})
it('drops malformed inbound JSON without throwing', () => {
const client = new WSClient('ws://test/ws')
let count = 0
client.on('*', () => {
count += 1
})
client.connect()
const sock = StubWebSocket.instances[0]
sock.open()
sock.receive('not-json{{{')
sock.receive({ type: 'unknown_type', data: {} })
expect(count).toBe(0)
client.close()
})
})