CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / TypeScript typecheck (push) Successful in 7s
CI & Build / Python tests (push) Successful in 15s
CI & Build / integration (push) Successful in 45s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 4m17s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 7m33s
Desktop (Tauri) / Update manifest (push) Successful in 7s
Android / Kotlin + Rust (APK) (push) Successful in 11m25s
Step 2 of milestone 481. The operator chose a full rename (Scribe note 5071), so this goes past the display strings into the identities: - src/thoughtsync → src/inkwell; every import, the Dockerfile and both compose commands, alembic env, pyproject - THOUGHTSYNC_* → INKWELL_* (database URL, secret key, log level, tag/port/bind) - container data dir /var/thoughtsync → /var/inkwell - image git.fabledsword.com/bvandeusen/inkwell; Postgres user/db default inkwell; CI's integration service follows - the files the image serves are inkwell.*. fetch-clients.sh still fetches the thoughtsync-named release assets, because the lanes that publish them are renamed in steps 3 and 4 - exports are written with app "inkwell" Two deliberate exceptions, both because data rides on them: - compose volumes are now named explicitly and overridable (INKWELL_DB_VOLUME, INKWELL_DATA_VOLUME), so a deployment installed as ThoughtSync points at the volumes and DB identity it already has. .env.example says exactly what to set - import still accepts app "thoughtsync", because exports written before the rename are backups. Tested both ways Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
75 lines
2.9 KiB
Python
75 lines
2.9 KiB
Python
import ipaddress
|
|
|
|
import pytest
|
|
|
|
from inkwell.app import create_app
|
|
from inkwell.unfurl import UnfurlError, extract_preview, is_public_ip, validate_url
|
|
|
|
|
|
@pytest.fixture
|
|
def app():
|
|
return create_app()
|
|
|
|
|
|
def test_is_public_ip_blocks_internal_ranges():
|
|
assert is_public_ip(ipaddress.ip_address("8.8.8.8"))
|
|
assert is_public_ip(ipaddress.ip_address("2606:4700:4700::1111"))
|
|
# everything internal / special is rejected (the SSRF core)
|
|
assert not is_public_ip(ipaddress.ip_address("10.0.0.1")) # private
|
|
assert not is_public_ip(ipaddress.ip_address("192.168.1.1")) # private
|
|
assert not is_public_ip(ipaddress.ip_address("127.0.0.1")) # loopback
|
|
assert not is_public_ip(ipaddress.ip_address("169.254.169.254")) # link-local (cloud metadata)
|
|
assert not is_public_ip(ipaddress.ip_address("0.0.0.0")) # unspecified
|
|
assert not is_public_ip(ipaddress.ip_address("::1")) # loopback v6
|
|
assert not is_public_ip(ipaddress.ip_address("fc00::1")) # unique-local v6
|
|
|
|
|
|
def test_validate_url_scheme_and_parts():
|
|
assert validate_url("https://example.com/a?b=c") == ("https", "example.com", 443, "/a?b=c")
|
|
assert validate_url("http://x.io")[3] == "/" # default path
|
|
assert validate_url("http://x.io:8080/p")[2] == 8080 # explicit port
|
|
for bad in ("file:///etc/passwd", "ftp://x", "gopher://x", "not a url", ""):
|
|
with pytest.raises(UnfurlError):
|
|
validate_url(bad)
|
|
|
|
|
|
def test_extract_preview_opengraph():
|
|
html = (
|
|
b"<html><head>"
|
|
b'<meta property="og:title" content="Hello & World">'
|
|
b'<meta property="og:description" content="A page">'
|
|
b'<meta property="og:image" content="/img.png">'
|
|
b'<meta property="og:site_name" content="Example">'
|
|
b"</head></html>"
|
|
)
|
|
p = extract_preview("https://example.com/page", html)
|
|
assert p["title"] == "Hello & World" # entities decoded
|
|
assert p["description"] == "A page"
|
|
assert p["image_url"] == "https://example.com/img.png" # relative resolved to absolute
|
|
assert p["site_name"] == "Example"
|
|
|
|
|
|
def test_extract_preview_title_fallback_and_host_defaults():
|
|
html = b"<html><head><title> Just a Title </title></head></html>"
|
|
p = extract_preview("https://example.com", html)
|
|
assert p["title"] == "Just a Title" # whitespace collapsed
|
|
assert p["description"] is None
|
|
assert p["image_url"] is None
|
|
assert p["site_name"] == "example.com" # falls back to host
|
|
|
|
|
|
async def test_unfurl_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.post(
|
|
"/api/notes/00000000-0000-0000-0000-000000000000/unfurl", json={"url": "https://x.com"}
|
|
)
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_delete_preview_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.delete(
|
|
"/api/notes/00000000-0000-0000-0000-000000000000/previews/00000000-0000-0000-0000-000000000001"
|
|
)
|
|
assert resp.status_code == 401
|