mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-07 18:07:47 +08:00
feat(security): harden gateway boundaries and usage policies
Consolidate subscription usage policy enforcement, privacy-safe persistence, and gateway security hardening into one reviewable change. Includes bounded HTTP and execution envelopes, header and protocol guards, DNS and relay validation, authentication and secret projection hardening, secure backup/install paths, and regression coverage.
This commit is contained in:
@@ -425,4 +425,37 @@ mod tests {
|
||||
.expect("analyze tuning migration should be embedded");
|
||||
assert!(!analyze_tuning.no_tx);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tunnel_generation_backfill_does_not_require_pgcrypto() {
|
||||
let migration = POSTGRES_MIGRATOR
|
||||
.iter()
|
||||
.find(|migration| migration.version == 20260831010000)
|
||||
.expect("tunnel generation migration should be embedded");
|
||||
let sql = migration.sql.as_ref();
|
||||
|
||||
// Existing installations may not have the optional pgcrypto extension.
|
||||
// Legacy rows only need an opaque epoch marker; new registrations use a
|
||||
// CSPRNG in the application layer.
|
||||
assert!(sql.contains("SET tunnel_generation = md5("));
|
||||
assert!(sql.contains("ctid::text"));
|
||||
assert!(!sql.contains("gen_random_uuid"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn gemini_file_mapping_metadata_migration_expands_legacy_columns() {
|
||||
let migration = POSTGRES_MIGRATOR
|
||||
.iter()
|
||||
.find(|migration| migration.version == 20260901000000)
|
||||
.expect("Gemini file mapping metadata migration should be embedded");
|
||||
let sql = migration.sql.as_ref();
|
||||
|
||||
for expected in [
|
||||
"file_name TYPE character varying(512)",
|
||||
"display_name TYPE character varying(512)",
|
||||
"mime_type TYPE character varying(255)",
|
||||
] {
|
||||
assert!(sql.contains(expected), "migration is missing {expected}");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user