infrasynth-backend-kit/tests/test_files/test_scanner.py
jcv-dev 551b42eab5 feat: production-hardening pass across the kit
Close the gaps between the documented contract (API-STANDARD, TENANCY,
ENTITLEMENTS) and the implementation, and remove committed build artifacts.

Security:
- verify + process inbound webhooks (HMAC/handler verify, size limit,
  timestamp tolerance, idempotency via InboundEvent.external_id)
- real 2FA login flow (pre-auth challenge; tokens only after verify/recovery)
- wire HybridPermission into security/audit views; add API-key rotate and
  users/<id>/permissions|roles endpoints
- tenant-scoped throttling on by default; webhook replay protection
- verify MercadoPago webhook signatures
- login brute-force guard, configurable password policy, real ALTCHA PoW

Correctness:
- apply verified billing webhooks idempotently (subscription/entitlement/
  invoice/PaymentTransaction); scheduled payment lifecycle jobs
- capture audit update diffs automatically; add audit retention purge
- working notification retries, per-channel rate limits, log retention
- pluggable virus scanner, upload-size limit, pipeline toggle
- feature rollout %/environment targeting; settings-driven registrations
- workflow guards (instance cap, route depth, self-assignment, clone on re-entry)
- wire every previously-dead INFRASYNTH_* setting; drop truly dead ones

Delivery:
- README + CHANGELOG; CI format check + coverage gate
- keep test media out of the tree; untrack .coverage, __pycache__,
  egg-info, docs/ and invoice artifacts
2026-09-24 10:41:21 -05:00

34 lines
1.1 KiB
Python

import pytest
from django.core.exceptions import ImproperlyConfigured
from infrasynth.files.scanner import NoOpScanner, get_scanner
class TestScanner:
def test_default_is_noop_and_clean(self):
scanner = get_scanner()
assert isinstance(scanner, NoOpScanner)
assert scanner.scan(b"hello").clean is True
def test_require_scan_without_scanner_raises(self, settings):
settings.INFRASYNTH_FILES = {
**settings.INFRASYNTH_FILES,
"VIRUS_SCANNER": "noop",
"REQUIRE_VIRUS_SCAN": True,
}
with pytest.raises(ImproperlyConfigured):
NoOpScanner().scan(b"hello")
def test_custom_scanner_path(self, settings):
settings.INFRASYNTH_FILES = {
**settings.INFRASYNTH_FILES,
"VIRUS_SCANNER": "tests.test_files.test_scanner.AlwaysCleanScanner",
}
assert get_scanner().scan(b"x").clean is True
class AlwaysCleanScanner:
def scan(self, data):
from infrasynth.files.scanner import ScanResult
return ScanResult(clean=True, scanner="custom")