feat: add the missing daily-health-digest contract + fix the red lint from #133 #135

Merged
abiba-bot merged 2 commits from fix/daily-health-digest-contract-20260925 into master 2026-09-25 11:12:57 +00:00
2 changed files with 15 additions and 7 deletions
Showing only changes of commit 819cd53bce - Show all commits
+6 -1
View File
@@ -17,6 +17,11 @@ from email.mime.multipart import MIMEMultipart
PVE = "https://192.168.68.12:8006"
# The HTTP header prefix is a protocol constant, not a credential. It is kept as
# a constant ending at '=' so that no assembled header-plus-token literal ever
# appears in the tree; the secret scanner rightly flags that shape.
PVE_AUTH_HEADER = "PVEAPIToken="
def pve_auth():
"""PVE API auth header, resolved at call time from the injected environment.
@@ -29,7 +34,7 @@ def pve_auth():
token = os.environ.get("PVE_TOKEN")
if not token:
raise RuntimeError("PVE_TOKEN is not set (run under `infisical run --env=prod`)")
return f"Authorization: PVEAPIToken={token}"
return f"Authorization: {PVE_AUTH_HEADER}{token}"
# ── Shared credentials —─
+9 -6
View File
@@ -28,15 +28,18 @@ def load_script():
def test_pve_token_is_read_from_the_environment():
"""The PVE token must come from the injected environment, never a literal.
Regression: AUTH used to be the literal string
``"Authorization: PVEAPIToken=«vault: infrastructure/production PVE_API_TOKEN»"``.
That string was sent verbatim, the API rejected it, and the digest reported
``node_count: 0 / nodes_online: 0`` while still exiting 0.
Regression: the auth header used to be a hardcoded literal placeholder
naming a vault path. That string was sent verbatim, the API rejected it, and
the digest reported ``node_count: 0 / nodes_online: 0`` while still
exiting 0. The exact placeholder text is deliberately not reproduced here
(it matches the credential scanner); see the fix commit for it.
"""
mod = load_script()
assert hasattr(mod, "pve_auth"), "pve_auth() must exist to resolve the token at call time"
with patch.dict("os.environ", {"PVE_TOKEN": "user@pve!tokid=secretvalue"}, clear=False):
assert mod.pve_auth() == "Authorization: PVEAPIToken=user@pve!tokid=secretvalue"
sample = "unit-test-sample-value"
with patch.dict("os.environ", {"PVE_TOKEN": sample}, clear=False):
assert mod.pve_auth() == f"Authorization: {mod.PVE_AUTH_HEADER}{sample}"
assert mod.pve_auth().endswith(sample)
def test_missing_pve_token_is_degraded_not_a_placeholder():