|
6 | 6 |
|
7 | 7 | Phase 1k.1a (Task 25): Removed TemplateLoader and /api/templates tests. |
8 | 8 | Templates are deleted in Phase 1k.1a. |
| 9 | +
|
| 10 | +2026-08-14 security audit: added coverage for GET /api/printers/{id} and |
| 11 | +POST /api/jobs/{id}/retry, which shipped with NO auth dependency at all |
| 12 | +while their sibling endpoints in the same router file all required one |
| 13 | +(see tests/unit/api/test_route_auth_coverage_guardrail.py for the |
| 14 | +structural guardrail that now catches this class of gap for every route, |
| 15 | +not just these two). |
9 | 16 | """ |
10 | 17 |
|
11 | 18 | from __future__ import annotations |
@@ -119,3 +126,118 @@ async def test_pangolin_sso_header_grants_read(api_client_with_seed): |
119 | 126 | headers={"X-Pangolin-User": "testuser@example.com"}, |
120 | 127 | ) |
121 | 128 | assert resp.status_code == 200, f"SSO should grant read: {resp.status_code}" |
| 129 | + |
| 130 | + |
| 131 | +# --------------------------------------------------------------------------- |
| 132 | +# 2026-08-14 security audit regressions: |
| 133 | +# GET /api/printers/{id} and POST /api/jobs/{id}/retry had NO auth |
| 134 | +# dependency at all — any caller that could reach the backend got full |
| 135 | +# printer connection metadata / could trigger a real reprint with zero |
| 136 | +# credentials. See app/api/routes/printers.py::get_printer and |
| 137 | +# app/api/routes/jobs.py::retry_job. |
| 138 | +# --------------------------------------------------------------------------- |
| 139 | + |
| 140 | + |
| 141 | +async def _seed_printer(factory): |
| 142 | + from app.models.printer import Printer |
| 143 | + |
| 144 | + async with factory() as s: |
| 145 | + printer = Printer( |
| 146 | + name="audit-seed-printer", |
| 147 | + slug="audit-seed-printer", |
| 148 | + model="PT-P750W", |
| 149 | + backend="ptouch", |
| 150 | + connection={"host": "192.0.2.10", "port": 9100}, |
| 151 | + ) |
| 152 | + s.add(printer) |
| 153 | + await s.commit() |
| 154 | + await s.refresh(printer) |
| 155 | + return printer |
| 156 | + |
| 157 | + |
| 158 | +async def _seed_failed_job(factory, printer_id): |
| 159 | + from app.models.job import Job, JobState |
| 160 | + |
| 161 | + async with factory() as s: |
| 162 | + job = Job( |
| 163 | + printer_id=printer_id, |
| 164 | + template_key="audit-seed-template", |
| 165 | + state=JobState.FAILED.value, |
| 166 | + payload={"text": "audit"}, |
| 167 | + ) |
| 168 | + s.add(job) |
| 169 | + await s.commit() |
| 170 | + await s.refresh(job) |
| 171 | + return job |
| 172 | + |
| 173 | + |
| 174 | +@pytest.mark.asyncio |
| 175 | +async def test_get_printer_detail_without_auth_returns_401(api_client_with_seed): |
| 176 | + """GET /api/printers/{id} must reject unauthenticated requests. |
| 177 | +
|
| 178 | + Regression test: this endpoint previously had no auth dependency at |
| 179 | + all, unlike GET /api/printers (list) and every other single-printer |
| 180 | + endpoint (status/tape/queue/pause/resume) in the same file. |
| 181 | + """ |
| 182 | + import app.db.engine as _engine_module |
| 183 | + |
| 184 | + printer = await _seed_printer(_engine_module.async_session) |
| 185 | + |
| 186 | + resp = await api_client_with_seed.get(f"/api/printers/{printer.id}") |
| 187 | + assert resp.status_code == 401, f"Expected 401, got {resp.status_code}: {resp.text}" |
| 188 | + |
| 189 | + |
| 190 | +@pytest.mark.asyncio |
| 191 | +async def test_get_printer_detail_with_read_key_returns_200(api_client_with_seed): |
| 192 | + """GET /api/printers/{id} succeeds for a caller with a valid read-scope key.""" |
| 193 | + import app.db.engine as _engine_module |
| 194 | + |
| 195 | + factory = _engine_module.async_session |
| 196 | + printer = await _seed_printer(factory) |
| 197 | + read_key = await _make_read_key(factory) |
| 198 | + |
| 199 | + resp = await api_client_with_seed.get( |
| 200 | + f"/api/printers/{printer.id}", |
| 201 | + headers={"X-Label-Hub-Key": read_key}, |
| 202 | + ) |
| 203 | + assert resp.status_code == 200, f"Expected 200, got {resp.status_code}: {resp.text}" |
| 204 | + assert resp.json()["id"] == str(printer.id) |
| 205 | + |
| 206 | + |
| 207 | +@pytest.mark.asyncio |
| 208 | +async def test_retry_job_without_auth_returns_401(api_client_with_seed): |
| 209 | + """POST /api/jobs/{id}/retry must reject unauthenticated requests. |
| 210 | +
|
| 211 | + Regression test: this endpoint previously had no auth dependency at |
| 212 | + all, unlike list_jobs/get_job (read scope) and cancel_job (print scope) |
| 213 | + in the same file — despite retry_job creating a new QUEUED job that the |
| 214 | + worker actually dispatches to the physical printer. |
| 215 | + """ |
| 216 | + import app.db.engine as _engine_module |
| 217 | + |
| 218 | + factory = _engine_module.async_session |
| 219 | + printer = await _seed_printer(factory) |
| 220 | + job = await _seed_failed_job(factory, printer.id) |
| 221 | + |
| 222 | + resp = await api_client_with_seed.post(f"/api/jobs/{job.id}/retry") |
| 223 | + assert resp.status_code == 401, f"Expected 401, got {resp.status_code}: {resp.text}" |
| 224 | + |
| 225 | + |
| 226 | +@pytest.mark.asyncio |
| 227 | +async def test_retry_job_with_print_key_returns_201(api_client_with_seed): |
| 228 | + """POST /api/jobs/{id}/retry succeeds for a caller with a valid print-scope key.""" |
| 229 | + import app.db.engine as _engine_module |
| 230 | + |
| 231 | + factory = _engine_module.async_session |
| 232 | + printer = await _seed_printer(factory) |
| 233 | + job = await _seed_failed_job(factory, printer.id) |
| 234 | + print_key = await _make_print_key(factory) |
| 235 | + |
| 236 | + resp = await api_client_with_seed.post( |
| 237 | + f"/api/jobs/{job.id}/retry", |
| 238 | + headers={"X-Label-Hub-Key": print_key}, |
| 239 | + ) |
| 240 | + assert resp.status_code == 201, f"Expected 201, got {resp.status_code}: {resp.text}" |
| 241 | + body = resp.json() |
| 242 | + assert body["id"] != str(job.id) |
| 243 | + assert body["state"] == "queued" |
0 commit comments