fix(newman): resolve API integration test failures — auth header, negative test body, and issues assertion - #2
Closed
nageshbhagelli wants to merge 3 commits into
Closed
Conversation
BREAKING CHANGES: - API key authentication now required on /validate-chart, /validate-chart/batch, /history - Server hard-exits on startup if default SECRET_KEY or API_KEY used in production (DEBUG=false) Security: - SecretStr for SECRET_KEY and API_KEY (values never appear in logs/repr) - secrets.compare_digest for timing-attack-safe key comparison - Input sanitisation: max_length on all strings, max_items on all lists (→ 422) - Rate limiting: 30 req/min (single), 10 req/min (batch) via slowapi Persistence: - SQLAlchemy 2.0 async engine with aiosqlite - ValidationHistory ORM model — every validation result persisted - /metrics now reads from DB (survives server restarts) - /history endpoint: paginated, filterable by status + chart_type CI/CD fixes: - Fixed startup guard blocking test/newman jobs (added DEBUG=true, API_KEY_ENABLED=false) - Fixed smoke test missing X-API-Key header (auth now enforced) - Fixed Bandit --exit-zero negating HIGH severity check - Fixed trivy-action tag: 0.20.0 → v0.36.0 (v prefix required, bumped to latest) - Fixed publish job if-condition with !failure() && !cancelled() guard - Added security-events: write permission to trivy-scan job Testing: - 36 tests (was 24) — 86% coverage — 0 warnings - conftest.py: in-memory SQLite override, session-scoped TestClient fixture - New tests: auth 401/403, input sanitisation 422, /history pagination/filters, metrics DB persistence, X-Correlation-ID echo, X-Response-Time header New files: - app/core/database.py — async SQLAlchemy engine + session + init_db() - app/core/security.py — X-API-Key FastAPI dependency - app/models/db_models.py — ValidationHistory ORM model - tests/conftest.py — in-memory DB + TestClient fixture - pytest.ini — asyncio_mode=auto, silences pytest-asyncio warning - frontend/index.html — dark dashboard with animated gauge + Chart.js - Dockerfile — multi-stage, non-root user, HEALTHCHECK - docker-compose.yml — local stack with healthchecks - Makefile — dev/test/build/trivy/compose-up targets - .bandit / .env.example / .dockerignore README: full rewrite with architecture diagram, pipeline flow, curl examples
Two bugs on adjacent lines caused the Docker build to fail entirely: 1. Line 9 had a fake SHA256 digest (63 hex chars instead of required 64) causing: 'failed to parse stage name: invalid checksum digest length' 2. Line 11 was a second 'FROM ... AS builder' — duplicate stage names caused a DuplicateStageName warning and build abort Fix: Remove the broken digest line entirely. Keep a single FROM with python:3.11-slim and actionable comments explaining how to pin a real digest via 'docker inspect' when needed for production hardening.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes all 4 failing assertions in the Newman API Integration Tests CI step.
No application code was changed — all fixes are in the Postman collection.
Root Causes & Fixes
🔴 Bug 1 — Missing
X-API-KeyHeader (Critical)The CI workflow correctly passes
--env-var "api_key=${CI_API_KEY}"to Newman,but the Postman collection never referenced
{{api_key}}in any request header.Every
/validate-chartcall received a 401 Unauthorized response, whose bodycontains no
status,score, orissuesfields — causing all downstreamassertions to fail with
expected undefined to deeply equal ....Fix: Added
X-API-Key: {{api_key}}header to bothValidate Chartrequests.🔴 Bug 2 — Negative Test Body Scored Above the "Invalid" Threshold
The negative test sent:
{ "chart_type": "bar", "title": "Empty Data Chart", "labels": [], "data": [], "objective": "..." }