|
| 1 | +"""Who is allowed to suppress an alert with @SocketSecurity ignore. |
| 2 | +
|
| 3 | +An ignore command silences a security finding, so it is honored only from someone |
| 4 | +with write access to the repository. The gate lives in check_for_socket_comments, |
| 5 | +so a rejected command never reaches the ignore parser, the alert filter, or the |
| 6 | +ignore telemetry. |
| 7 | +""" |
| 8 | +from types import SimpleNamespace |
| 9 | + |
| 10 | +import pytest |
| 11 | + |
| 12 | +from socketsecurity.core.classes import Comment |
| 13 | +from socketsecurity.core.scm.github import Github |
| 14 | +from socketsecurity.core.scm.gitlab import Gitlab |
| 15 | +from socketsecurity.core.scm_comments import Comments |
| 16 | + |
| 17 | + |
| 18 | +def _comment(body="@SocketSecurity ignore npm/lodash@4.17.21", **fields): |
| 19 | + return Comment(id=1, body=body, body_list=body.split("\n"), **fields) |
| 20 | + |
| 21 | + |
| 22 | +# --- GitHub: author_association ships with the comment, no extra request ----- |
| 23 | + |
| 24 | + |
| 25 | +@pytest.mark.parametrize("association", ["OWNER", "MEMBER", "COLLABORATOR"]) |
| 26 | +def test_github_write_access_may_ignore(association): |
| 27 | + github = Github.__new__(Github) |
| 28 | + assert github.is_ignore_authorized(_comment(author_association=association)) is True |
| 29 | + |
| 30 | + |
| 31 | +@pytest.mark.parametrize( |
| 32 | + "association", |
| 33 | + ["CONTRIBUTOR", "FIRST_TIME_CONTRIBUTOR", "FIRST_TIMER", "MANNEQUIN", "NONE", ""], |
| 34 | +) |
| 35 | +def test_github_without_write_access_may_not_ignore(association): |
| 36 | + github = Github.__new__(Github) |
| 37 | + assert github.is_ignore_authorized(_comment(author_association=association)) is False |
| 38 | + |
| 39 | + |
| 40 | +def test_github_missing_association_is_not_trusted(): |
| 41 | + """Absent field means unverified, which is not the same as authorized.""" |
| 42 | + github = Github.__new__(Github) |
| 43 | + assert github.is_ignore_authorized(_comment()) is False |
| 44 | + |
| 45 | + |
| 46 | +def test_unauthorized_command_never_reaches_the_ignore_bucket(): |
| 47 | + github = Github.__new__(Github) |
| 48 | + outsider = _comment(author_association="NONE") |
| 49 | + |
| 50 | + bucketed = Comments.check_for_socket_comments( |
| 51 | + {outsider.id: outsider}, github.is_ignore_authorized |
| 52 | + ) |
| 53 | + |
| 54 | + assert "ignore" not in bucketed |
| 55 | + # ...so the alert it named survives. |
| 56 | + alert = SimpleNamespace( |
| 57 | + pkg_name="lodash", pkg_version="4.17.21", pkg_type="npm", type="malware" |
| 58 | + ) |
| 59 | + assert Comments.remove_alerts(bucketed, [alert]) == [alert] |
| 60 | + |
| 61 | + |
| 62 | +def test_ignore_all_from_an_outsider_is_rejected_too(): |
| 63 | + """ignore-all is the more powerful command; it goes through the same gate.""" |
| 64 | + github = Github.__new__(Github) |
| 65 | + outsider = _comment(body="@SocketSecurity ignore-all", author_association="NONE") |
| 66 | + |
| 67 | + assert "ignore" not in Comments.check_for_socket_comments( |
| 68 | + {outsider.id: outsider}, github.is_ignore_authorized |
| 69 | + ) |
| 70 | + |
| 71 | + |
| 72 | +# --- GitLab: notes carry no permission field, so membership is looked up ----- |
| 73 | + |
| 74 | + |
| 75 | +def _gitlab(members_pages=None, raises=None): |
| 76 | + gitlab = Gitlab.__new__(Gitlab) |
| 77 | + gitlab.config = SimpleNamespace(mr_project_id="42", headers={}, api_url="https://gl/api/v4") |
| 78 | + gitlab._member_access = None |
| 79 | + gitlab._member_lookup_attempted = False |
| 80 | + |
| 81 | + calls = [] |
| 82 | + |
| 83 | + def fake_request(**kwargs): |
| 84 | + calls.append(kwargs["path"]) |
| 85 | + if raises: |
| 86 | + raise raises |
| 87 | + return SimpleNamespace(json=lambda: members_pages.pop(0)) |
| 88 | + |
| 89 | + gitlab._request_with_fallback = fake_request |
| 90 | + gitlab.calls = calls |
| 91 | + return gitlab |
| 92 | + |
| 93 | + |
| 94 | +@pytest.mark.parametrize("access_level,expected", [(50, True), (40, True), (30, True), (20, False), (10, False)]) |
| 95 | +def test_gitlab_requires_developer_access(access_level, expected): |
| 96 | + gitlab = _gitlab([[{"id": 7, "access_level": access_level}]]) |
| 97 | + comment = _comment(author={"id": 7, "username": "someone"}) |
| 98 | + |
| 99 | + assert gitlab.is_ignore_authorized(comment) is expected |
| 100 | + |
| 101 | + |
| 102 | +def test_gitlab_non_member_may_not_ignore(): |
| 103 | + """The outsider case: a 200 listing that simply does not contain them.""" |
| 104 | + gitlab = _gitlab([[{"id": 7, "access_level": 40}]]) |
| 105 | + comment = _comment(author={"id": 999, "username": "outsider"}) |
| 106 | + |
| 107 | + assert gitlab.is_ignore_authorized(comment) is False |
| 108 | + |
| 109 | + |
| 110 | +def test_gitlab_membership_is_fetched_once_per_run(): |
| 111 | + gitlab = _gitlab([[{"id": 7, "access_level": 40}]]) |
| 112 | + |
| 113 | + gitlab.is_ignore_authorized(_comment(author={"id": 7})) |
| 114 | + gitlab.is_ignore_authorized(_comment(author={"id": 8})) |
| 115 | + |
| 116 | + assert len(gitlab.calls) == 1 |
| 117 | + |
| 118 | + |
| 119 | +def test_gitlab_paginates_until_a_short_page(): |
| 120 | + first = [{"id": i, "access_level": 30} for i in range(Gitlab.MEMBER_PAGE_SIZE)] |
| 121 | + gitlab = _gitlab([first, [{"id": 999, "access_level": 40}]]) |
| 122 | + |
| 123 | + assert gitlab.is_ignore_authorized(_comment(author={"id": 999})) is True |
| 124 | + assert len(gitlab.calls) == 2 |
| 125 | + |
| 126 | + |
| 127 | +def test_gitlab_unreadable_membership_honors_the_command_with_a_warning(caplog): |
| 128 | + """A CI_JOB_TOKEN usually cannot read members; that must not break pipelines.""" |
| 129 | + gitlab = _gitlab(raises=Exception("403 Forbidden")) |
| 130 | + |
| 131 | + with caplog.at_level("WARNING", logger="socketcli"): |
| 132 | + allowed = gitlab.is_ignore_authorized(_comment(author={"id": 7, "username": "dev"})) |
| 133 | + |
| 134 | + assert allowed is True |
| 135 | + assert "without verifying write access" in caplog.text |
| 136 | + |
| 137 | + |
| 138 | +def test_gitlab_oversized_membership_is_undetermined(): |
| 139 | + full = [{"id": i, "access_level": 30} for i in range(Gitlab.MEMBER_PAGE_SIZE)] |
| 140 | + gitlab = _gitlab([list(full) for _ in range(Gitlab.MEMBER_PAGE_LIMIT)]) |
| 141 | + |
| 142 | + # Undetermined falls back to honoring the command, same as an API failure. |
| 143 | + assert gitlab.is_ignore_authorized(_comment(author={"id": 999})) is True |
| 144 | + assert len(gitlab.calls) == Gitlab.MEMBER_PAGE_LIMIT |
0 commit comments