Files
SnapOtter/tests/unit/api/object-storage-workspace-cap.test.ts
T
SnapOtterandGitHub 079fcd2631 fix(security): close the gaps a full 2.0 re-audit left open (#620)
Follow-up to a full re-audit of the 2.0 tree. Most prior findings were already
fixed; this closes the ones that were not:

- SAML assertion replay: validateInResponseTo ifPresent plus a Redis-backed
  CacheProvider, so a captured signed assertion cannot be replayed. ifPresent
  keeps IdP-initiated SSO working.
- MFA login challenge burned after 5 wrong TOTP codes.
- api_keys.key_prefix indexed; the per-request lookup was a full table scan.
- MAX_AI_JOBS_PER_USER caps a user's in-flight single-file AI jobs (the AI pool
  runs at concurrency 1). Batch and pipeline AI stay uncapped.
- MAX_WORKSPACE_SIZE_GB enforced instead of being dead config.
- SUBPROCESS_MEMORY_LIMIT_MB (default off) for the native media and doc engines;
  not applied to the AI sidecar.
- SVG sanitizer closes unquoted and whitespace-prefixed javascript: hrefs and
  the animateTransform/animateMotion/handler/mpath elements.
- Windows-style paths stripped from error output to match the Sentry scrubber.
- Postgres and Redis compose services get cap_drop plus pids_limit and cpus.
- .env.example ships MAX_SVG_SIZE_MB=50 (0 disabled the cap).

Adds security-focused unit and integration tests. typecheck, biome, and the
full unit and integration suites pass.
2026-07-23 00:18:16 +08:00

46 lines
1.6 KiB
TypeScript

import { mkdir, mkdtemp, rm, writeFile } from "node:fs/promises";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { afterEach, describe, expect, it } from "vitest";
import {
computeWorkspaceUsedBytes,
isOverWorkspaceCap,
} from "../../../apps/api/src/lib/object-storage.js";
describe("isOverWorkspaceCap", () => {
it("is disabled (never over) when maxGb is 0", () => {
expect(isOverWorkspaceCap(999 * 1024 ** 3, 0)).toBe(false);
});
it("is false when usage is under the cap", () => {
expect(isOverWorkspaceCap(5 * 1024 ** 3, 10)).toBe(false);
});
it("is true when usage exceeds the cap", () => {
expect(isOverWorkspaceCap(11 * 1024 ** 3, 10)).toBe(true);
});
});
describe("computeWorkspaceUsedBytes", () => {
let root = "";
afterEach(async () => {
if (root) await rm(root, { recursive: true, force: true });
root = "";
});
it("sums file sizes across uploads/ and outputs/ job dirs", async () => {
root = await mkdtemp(join(tmpdir(), "snapotter-wscap-"));
await mkdir(join(root, "uploads", "job1"), { recursive: true });
await mkdir(join(root, "outputs", "job2"), { recursive: true });
await writeFile(join(root, "uploads", "job1", "a.bin"), Buffer.alloc(1000));
await writeFile(join(root, "outputs", "job2", "b.bin"), Buffer.alloc(2000));
expect(await computeWorkspaceUsedBytes(root)).toBe(3000);
});
it("returns 0 for an empty or missing workspace", async () => {
root = await mkdtemp(join(tmpdir(), "snapotter-wscap-"));
expect(await computeWorkspaceUsedBytes(root)).toBe(0);
expect(await computeWorkspaceUsedBytes(join(root, "nope"))).toBe(0);
});
});