Files
inkwell/tests/test_settings.py
T
bvandeusenandClaude Opus 5.5 7259708f28 Session length, trash retention and attachment size have bounds
Each accepted any integer. A session length of 0 expired every session at once,
the admin's own included; an attachment limit above the 64 MB body ceiling
allowed files no request could carry, and a negative one refused every upload.

- session_ttl_days 1..3650, trash_retention_days 0..3650 (0 = keep), and
  max_attachment_mb 1..MAX_BODY_MB-1, leaving room for the multipart envelope.
- MAX_BODY_MB is the one number app.py's MAX_CONTENT_LENGTH and that maximum
  both read.
- A value stored before its bounds existed reads as the nearest bound.

Fixes #5384.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-08 14:10:28 -04:00

71 lines
2.6 KiB
Python

from inkwell.settings import MAX_BODY_MB, REGISTRY, validate_updates
def test_registry_has_expected_keys():
keys = {d.key for d in REGISTRY}
assert {"site_name", "allow_registration", "session_ttl_days"} <= keys
def test_validate_rejects_unknown_key():
clean, error = validate_updates({"nope": 1})
assert error is not None
assert clean == {}
def test_validate_coerces_bool_and_int():
clean, error = validate_updates({"allow_registration": "true", "session_ttl_days": "45"})
assert error is None
assert clean["allow_registration"] is True
assert clean["session_ttl_days"] == 45
def test_each_integer_with_a_dangerous_range_is_bounded():
"""Session length 0 expired every session at once; an attachment limit above the
body ceiling allowed files no request could carry; a negative one refused all (#5384)."""
for key, bad, good in (
("session_ttl_days", 0, 1),
("trash_retention_days", -1, 0),
("max_attachment_mb", 0, 1),
("max_attachment_mb", MAX_BODY_MB, MAX_BODY_MB - 1),
):
clean, error = validate_updates({key: str(bad)})
assert error is not None and clean == {}, f"{key}={bad} refused"
clean, error = validate_updates({key: str(good)})
assert error is None and clean == {key: good}, f"{key}={good} kept"
def test_a_stored_value_from_before_the_bounds_reads_as_the_nearest_bound():
from inkwell.settings import _BY_KEY, _coerce
assert _coerce(_BY_KEY["session_ttl_days"], 0) == 1
assert _coerce(_BY_KEY["max_attachment_mb"], 500) == MAX_BODY_MB - 1
assert _coerce(_BY_KEY["trash_retention_days"], 30) == 30
def test_validate_rejects_bad_int():
clean, error = validate_updates({"session_ttl_days": "not-a-number"})
assert error is not None
assert clean == {}
def test_an_empty_secret_keeps_what_is_saved():
clean, error = validate_updates({"smtp_password": "", "smtp_host": "smtp.example.test"})
assert error is None
assert clean == {"smtp_host": "smtp.example.test"}
def test_a_choice_must_be_one_of_its_values():
assert validate_updates({"smtp_security": "tls"}) == ({"smtp_security": "tls"}, None)
clean, error = validate_updates({"smtp_security": "ssl"})
assert clean == {} and error
def test_the_public_address_is_an_http_url_without_a_trailing_slash():
assert validate_updates({"public_url": "https://notes.example.test/"}) == (
{"public_url": "https://notes.example.test"},
None,
)
assert validate_updates({"public_url": ""}) == ({"public_url": ""}, None)
clean, error = validate_updates({"public_url": "javascript:alert(1)"})
assert clean == {} and error