Files
XC_VM/tests/Unit/BruteforceGuardTest.php
T
Divarion_D a1228039fe test(core): cover Authorization checks and BruteforceGuard flood truncation
Third coverage batch — the pure/near-pure cores of the auth layer:

- AuthorizationTest: hasResellerPermissions() flag lookup; check() short-circuit
  when identity globals are absent; the 'user'/'line' report-tree scoping via a
  real SQLite query (owner/member within self + all_reports); and the 'adv'
  permission logic (admin required, super-admin group 1 bypasses the advanced
  list, other groups gated by it).
- BruteforceGuardTest: truncateAttempts() drops entries older than the window in
  both indexed (reindexed) and associative (keys preserved) shapes; all-recent
  and empty inputs. The IO-bound check* methods are left for integration tests.

+12 tests. Suite: 646 tests, 0 errors.
2026-09-13 14:42:08 +03:00

44 lines
1.4 KiB
PHP

<?php
use XcVm\Core\Auth\BruteforceGuard;
use PHPUnit\Framework\TestCase;
/**
* BruteforceGuard::truncateAttempts — drops attempts older than the flood
* window. The rest of the guard is IO-bound (DB inserts, signals, flood files);
* this pure helper is the reusable core of every flood check, in both the
* indexed (list) and associative shapes.
*/
final class BruteforceGuardTest extends TestCase {
public function testKeepsRecentAndDropsExpiredInListMode(): void {
$now = time();
$attempts = [$now - 5, $now - 7200];
$kept = BruteforceGuard::truncateAttempts($attempts, 3600, true);
$this->assertSame([$now - 5], array_values($kept), 'reindexed list of survivors');
}
public function testKeepsRecentAndDropsExpiredInAssociativeMode(): void {
$now = time();
$attempts = ['alice' => $now - 5, 'bob' => $now - 7200];
$kept = BruteforceGuard::truncateAttempts($attempts, 3600, false);
$this->assertSame(['alice' => $now - 5], $kept, 'keys preserved for survivors');
$this->assertArrayNotHasKey('bob', $kept);
}
public function testEverythingWithinWindowIsKept(): void {
$now = time();
$attempts = [$now, $now - 1, $now - 10];
$this->assertCount(3, BruteforceGuard::truncateAttempts($attempts, 3600, true));
}
public function testEmptyInputYieldsEmpty(): void {
$this->assertSame([], BruteforceGuard::truncateAttempts([], 60, true));
$this->assertSame([], BruteforceGuard::truncateAttempts([], 60, false));
}
}