Files
XC_VM/tests/Unit/StreamTokenCallSitesTest.php
T
Divarion_D 52d801acb2 test: dual-backend TestDb (SQLite + MariaDB) + skip-on-panel guards
TestDb can now run the DB-touching unit tests against a real MariaDB as
well as the default in-memory SQLite, so the suite can be exercised on
the panel host (which ships pdo_mysql, not pdo_sqlite). When
XCVM_TEST_DB_DSN is set it connects there and translates the SQLite test
DDL on the fly: AUTOINCREMENT -> AUTO_INCREMENT, a bare INTEGER PRIMARY
KEY gains AUTO_INCREMENT, and each CREATE TABLE is preceded by DROP TABLE
IF EXISTS (a MariaDB schema persists across the per-test connections that
:memory: starts fresh). DDL is routed through exec() on both backends so
the ModuleMigrator path (which runs DDL via query()) works too, and the
MySQL session uses a permissive sql_mode to match SQLite's leniency.
AuthRepositoryTest back-quotes the reserved column `key`.

Three env-fragile guards are tagged #[Group('skip-on-panel')] so the
deployed-panel run can exclude them (--exclude-group skip-on-panel):
ArchitectureTest and StreamTokenCallSitesTest scan the repo src/ tree
(absent / polluted in a flat deploy; they also self-skip when it is
missing), and LoginSessionFixationTest runs in isolated child processes
that the panel's ionCube/OPcache PHP cannot reconstitute.

Verified green on all three backends: SQLite (local, 721), MariaDB 11.4
(container, 721), and the panel's bundled PHP 8.1 + server MariaDB
(713, with the group excluded).
2026-09-13 21:17:06 +03:00

49 lines
1.9 KiB
PHP

<?php
use PHPUnit\Framework\Attributes\Group;
use PHPUnit\Framework\TestCase;
/**
* Stream-link tokens go through Encryption::mintToken / readToken, which seal
* them when secure_stream_tokens is on. Calling the legacy encrypt()/decrypt()
* directly for a token quietly brings back the format that can be read and
* forged through padding errors, so only the uses that are not stream links —
* deterministic encryption of stored data — may do that.
*/
#[Group('skip-on-panel')]
final class StreamTokenCallSitesTest extends TestCase {
/** Stored data that must stay deterministic: HMAC keys are looked up by ciphertext, image cache names are reversed by the self-heal. */
private const LEGACY_ALLOWED = array(
'Core/Auth/AuthService.php',
'Core/Util/Encryption.php',
'Core/Util/ImageUtils.php',
'Cli/Commands/ToolsCommand.php',
);
public function testOnlyStoredDataUsesTheLegacyCipherDirectly(): void {
// Source-wide guard: scans the repo's src/ tree. On a flat deployment
// (/home/xc_vm) there is no such directory and the app root is mixed with
// runtime/test files, so this static guard only runs in the repo layout.
$rRoot = dirname(__DIR__, 2) . '/src/';
if (!is_dir($rRoot)) {
$this->markTestSkipped('source-tree guard runs only in the repo layout');
}
$rOffenders = array();
$rIterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($rRoot, FilesystemIterator::SKIP_DOTS));
foreach ($rIterator as $rFile) {
$rPath = $rFile->getPathname();
if (substr($rPath, -4) !== '.php' || strpos($rPath, '/vendor/') !== false) {
continue;
}
$rRelative = substr($rPath, strlen($rRoot));
if (in_array($rRelative, self::LEGACY_ALLOWED, true)) {
continue;
}
if (preg_match('/Encryption::(encrypt|decrypt)\s*\(/', (string) file_get_contents($rPath))) {
$rOffenders[] = $rRelative;
}
}
$this->assertSame(array(), $rOffenders, 'use Encryption::mintToken / readToken for stream-link tokens');
}
}