mirror of
https://github.com/Vateron-Media/XC_VM.git
synced 2026-10-03 12:02:29 +02:00
Third coverage batch — the pure/near-pure cores of the auth layer: - AuthorizationTest: hasResellerPermissions() flag lookup; check() short-circuit when identity globals are absent; the 'user'/'line' report-tree scoping via a real SQLite query (owner/member within self + all_reports); and the 'adv' permission logic (admin required, super-admin group 1 bypasses the advanced list, other groups gated by it). - BruteforceGuardTest: truncateAttempts() drops entries older than the window in both indexed (reindexed) and associative (keys preserved) shapes; all-recent and empty inputs. The IO-bound check* methods are left for integration tests. +12 tests. Suite: 646 tests, 0 errors.
44 lines
1.4 KiB
PHP
44 lines
1.4 KiB
PHP
<?php
|
|
|
|
use XcVm\Core\Auth\BruteforceGuard;
|
|
use PHPUnit\Framework\TestCase;
|
|
|
|
/**
|
|
* BruteforceGuard::truncateAttempts — drops attempts older than the flood
|
|
* window. The rest of the guard is IO-bound (DB inserts, signals, flood files);
|
|
* this pure helper is the reusable core of every flood check, in both the
|
|
* indexed (list) and associative shapes.
|
|
*/
|
|
final class BruteforceGuardTest extends TestCase {
|
|
|
|
public function testKeepsRecentAndDropsExpiredInListMode(): void {
|
|
$now = time();
|
|
$attempts = [$now - 5, $now - 7200];
|
|
|
|
$kept = BruteforceGuard::truncateAttempts($attempts, 3600, true);
|
|
|
|
$this->assertSame([$now - 5], array_values($kept), 'reindexed list of survivors');
|
|
}
|
|
|
|
public function testKeepsRecentAndDropsExpiredInAssociativeMode(): void {
|
|
$now = time();
|
|
$attempts = ['alice' => $now - 5, 'bob' => $now - 7200];
|
|
|
|
$kept = BruteforceGuard::truncateAttempts($attempts, 3600, false);
|
|
|
|
$this->assertSame(['alice' => $now - 5], $kept, 'keys preserved for survivors');
|
|
$this->assertArrayNotHasKey('bob', $kept);
|
|
}
|
|
|
|
public function testEverythingWithinWindowIsKept(): void {
|
|
$now = time();
|
|
$attempts = [$now, $now - 1, $now - 10];
|
|
$this->assertCount(3, BruteforceGuard::truncateAttempts($attempts, 3600, true));
|
|
}
|
|
|
|
public function testEmptyInputYieldsEmpty(): void {
|
|
$this->assertSame([], BruteforceGuard::truncateAttempts([], 60, true));
|
|
$this->assertSame([], BruteforceGuard::truncateAttempts([], 60, false));
|
|
}
|
|
}
|