test: add Pest v1 security test infrastructure - #20
somethingwithproof wants to merge 4 commits into
Conversation
Add source-scan tests verifying security patterns (prepared statements, output escaping, auth guards, PHP 7.4 compatibility) remain in place across refactors. Tests run with Pest v1 (PHP 7.3+) and stub the Cacti framework so plugins can be tested in isolation. Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
There was a problem hiding this comment.
Pull request overview
Adds a Pest v1 testing scaffold intended to enforce basic security/compatibility invariants for the npc plugin via lightweight source-scanning tests.
Changes:
- Add
composer.jsonwith Pest v1 as a dev dependency. - Add Pest bootstrap/config files under
tests/with Cacti-framework stub functions. - Add security-focused Pest tests for setup.php structure, prepared-statement usage consistency, and PHP 7.4 compatibility checks.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
composer.json |
Introduces Pest v1 as a dev dependency and wires in the test bootstrap. |
tests/Pest.php |
Loads the test bootstrap for Pest runs. |
tests/bootstrap.php |
Provides minimal stubs/constants to support loading plugin code in tests. |
tests/Security/SetupStructureTest.php |
Adds structural checks against setup.php (plugin hooks/version expectations). |
tests/Security/PreparedStatementConsistencyTest.php |
Adds source-scan enforcement for prepared DB helper usage. |
tests/Security/Php74CompatibilityTest.php |
Adds source-scan checks for a small set of PHP 8.0-only APIs/operators. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
…dabot - Throw RuntimeException when realpath/file_get_contents fails (previously silent continue hid unscanned files) - Fix Dependabot ecosystem from npm to composer - Remove committed .omc session artifacts, add .omc/ to .gitignore Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
|
Converted to draft to serialize the stack in this repo. Blocked by #18; will un-draft after that merges to avoid cross-PR merge conflicts. |
Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
- SetupStructureTest: parse INFO directly and assert name/version keys via toHaveKey() instead of regex-matching the raw source, per PR #20. - Php74CompatibilityTest: add PHP 8.0-construct checks (str_contains, str_starts_with, str_ends_with, nullsafe operator) for the entry-point files (cli.php, config.php, controllers/cacti.php, controllers/hosts.php, controllers/services.php, setup.php) covered by PR #20, with fail-fast error handling on unreadable files. composer.json/composer.lock/phpunit.xml/tests/bootstrap.php from PR #20 are intentionally not carried over since this repo already has an equivalent, newer Pest test framework (tests/bootstrap-unit.php, tests/TestCase.php, root phpunit.xml) merged via #26.
|
Superseded by #27, which extracts the test cases from this PR (updated Closing in favor of #27. |
* test: extract test cases from PR #20 into the current Pest framework - SetupStructureTest: parse INFO directly and assert name/version keys via toHaveKey() instead of regex-matching the raw source, per PR #20. - Php74CompatibilityTest: add PHP 8.0-construct checks (str_contains, str_starts_with, str_ends_with, nullsafe operator) for the entry-point files (cli.php, config.php, controllers/cacti.php, controllers/hosts.php, controllers/services.php, setup.php) covered by PR #20, with fail-fast error handling on unreadable files. composer.json/composer.lock/phpunit.xml/tests/bootstrap.php from PR #20 are intentionally not carried over since this repo already has an equivalent, newer Pest test framework (tests/bootstrap-unit.php, tests/TestCase.php, root phpunit.xml) merged via #26. * test: keep parse_ini_file source assertion in SetupStructureTest Address Copilot review feedback on #27 - toHaveKey() alone would still pass if setup.php stopped loading INFO via parse_ini_file(), so keep the source-level check alongside the parsed-metadata assertion.
Summary
Test plan
composer install && vendor/bin/pestpasses