Failing tests for splitting vulnerabilities into host and container scopes
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@ -167,3 +167,88 @@ async fn notification_threshold_setting_and_permissions() {
|
||||
StatusCode::UNAUTHORIZED
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn findings_are_scoped_into_host_and_containers() {
|
||||
let app = test_app_with_admin().await;
|
||||
let token = common::login(&app, ADMIN, PW).await.access;
|
||||
run_scan(&app, &token).await;
|
||||
|
||||
let host = get(
|
||||
&app,
|
||||
"/api/vulnerabilities?scope=host&min_severity=unknown",
|
||||
Some(&token),
|
||||
)
|
||||
.await;
|
||||
assert_eq!(host.status, StatusCode::OK, "{}", host.json);
|
||||
let host_list = host.json.as_array().unwrap();
|
||||
assert!(!host_list.is_empty());
|
||||
assert!(host_list
|
||||
.iter()
|
||||
.all(|f| f["target_kind"] == "os" && f["target"] == "os"));
|
||||
assert!(
|
||||
host_list.iter().any(|f| f["source"] == "debian"),
|
||||
"host findings name their package source"
|
||||
);
|
||||
|
||||
let containers = get(
|
||||
&app,
|
||||
"/api/vulnerabilities?scope=container&min_severity=unknown",
|
||||
Some(&token),
|
||||
)
|
||||
.await;
|
||||
let container_list = containers.json.as_array().unwrap();
|
||||
assert!(!container_list.is_empty());
|
||||
assert!(container_list.iter().all(|f| f["target_kind"] == "image"));
|
||||
assert!(container_list
|
||||
.iter()
|
||||
.any(|f| f["target"].as_str().unwrap().contains("gitea")));
|
||||
|
||||
let all = get(
|
||||
&app,
|
||||
"/api/vulnerabilities?min_severity=unknown",
|
||||
Some(&token),
|
||||
)
|
||||
.await;
|
||||
assert_eq!(
|
||||
all.json.as_array().unwrap().len(),
|
||||
host_list.len() + container_list.len()
|
||||
);
|
||||
assert_eq!(
|
||||
get(&app, "/api/vulnerabilities?scope=nope", Some(&token))
|
||||
.await
|
||||
.status,
|
||||
StatusCode::UNPROCESSABLE_ENTITY
|
||||
);
|
||||
|
||||
// the summary splits the same way
|
||||
let s = get(&app, "/api/vulnerabilities/summary", Some(&token)).await;
|
||||
let sum = |v: &serde_json::Value| {
|
||||
v["critical"].as_u64().unwrap()
|
||||
+ v["high"].as_u64().unwrap()
|
||||
+ v["medium"].as_u64().unwrap()
|
||||
+ v["low"].as_u64().unwrap()
|
||||
+ v["unknown"].as_u64().unwrap()
|
||||
};
|
||||
assert_eq!(sum(&s.json["os"]) as usize, host_list.len());
|
||||
assert_eq!(sum(&s.json["images"]) as usize, container_list.len());
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn targets_carry_their_scope_and_open_count() {
|
||||
let app = test_app_with_admin().await;
|
||||
let token = common::login(&app, ADMIN, PW).await.access;
|
||||
run_scan(&app, &token).await;
|
||||
|
||||
let res = get(&app, "/api/vulnerabilities/targets", Some(&token)).await;
|
||||
let targets = res.json.as_array().unwrap();
|
||||
assert_eq!(targets[0]["kind"], "os", "the host comes first");
|
||||
assert_eq!(targets[0]["target"], "os");
|
||||
assert!(targets[0]["open"].as_u64().unwrap() >= 3);
|
||||
let image = targets
|
||||
.iter()
|
||||
.find(|t| t["target"].as_str().unwrap().contains("gitea"))
|
||||
.unwrap();
|
||||
assert_eq!(image["kind"], "image");
|
||||
assert!(image["open"].as_u64().unwrap() >= 1);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user