mkellermann97 48a04661a2 test: add authorization / tenant-isolation regression suite
First automated coverage for the RBAC layer (pegaprox/utils/rbac.py) — the
highest-risk security surface in a multi-tenant cluster manager and the one
static scanners (Aikido/CodeAnt) structurally can't see. 17 in-process tests
(no live cluster needed) lock in the BOLA / tenant-isolation invariants that
were historically fixed only by hand review (#490/#493/#495/#555):

  - cross-tenant VM access denied; cluster list scoped to tenant
  - VM-ACL additive-not-restrictive model; #555 pool/ACL cluster-reach guard
  - API-token privilege floor (min(token, owner)); no admin-bypass for an
    admin-owned viewer token; mint-ceiling
  - pool.admin vs granular pool perms; pool grant doesn't leak to non-member
    VMs or across clusters

Harness: throwaway encrypted DB per test (temp dir + both DB singletons +
rbac process-caches reset → order-independent). pytest is dev-only
(requirements-dev.txt), not shipped in the appliance.

The suite already caught one real broken-access-control bug: the vm_acls table
has no inherit_role column, so an ACL saved with inherit_role=False (the UI's
'custom permissions' mode) is silently stored as FULL VM access. That test is
marked xfail(strict) with the root-cause + fix pointer until it's fixed.
2026-07-12 01:00:34 +02:00

6 lines
195 B
INI

[pytest]
testpaths = tests
addopts = -ra
# The authorization regression suite runs fully in-process against a throwaway
# encrypted DB — no live PVE/ESXi cluster required. See tests/README.md.