mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
First automated coverage for the RBAC layer (pegaprox/utils/rbac.py) — the highest-risk security surface in a multi-tenant cluster manager and the one static scanners (Aikido/CodeAnt) structurally can't see. 17 in-process tests (no live cluster needed) lock in the BOLA / tenant-isolation invariants that were historically fixed only by hand review (#490/#493/#495/#555): - cross-tenant VM access denied; cluster list scoped to tenant - VM-ACL additive-not-restrictive model; #555 pool/ACL cluster-reach guard - API-token privilege floor (min(token, owner)); no admin-bypass for an admin-owned viewer token; mint-ceiling - pool.admin vs granular pool perms; pool grant doesn't leak to non-member VMs or across clusters Harness: throwaway encrypted DB per test (temp dir + both DB singletons + rbac process-caches reset → order-independent). pytest is dev-only (requirements-dev.txt), not shipped in the appliance. The suite already caught one real broken-access-control bug: the vm_acls table has no inherit_role column, so an ACL saved with inherit_role=False (the UI's 'custom permissions' mode) is silently stored as FULL VM access. That test is marked xfail(strict) with the root-cause + fix pointer until it's fixed.
6 lines
195 B
INI
6 lines
195 B
INI
[pytest]
|
|
testpaths = tests
|
|
addopts = -ra
|
|
# The authorization regression suite runs fully in-process against a throwaway
|
|
# encrypted DB — no live PVE/ESXi cluster required. See tests/README.md.
|