fix: reject invalid readiness user payload (#77)
All checks were successful
CI / lint (pull_request) Successful in 7s
CI / build-frontend (pull_request) Successful in 4s

This commit is contained in:
timmy 2026-08-06 05:47:38 +00:00
parent b2f8eaf89a
commit 090a059c17
2 changed files with 19 additions and 0 deletions

View File

@ -43,6 +43,8 @@ async def readiness():
user = await asyncio.wait_for(
current_user(), timeout=READINESS_TIMEOUT_SECONDS
)
if not isinstance(user, dict) or not user.get("login"):
raise ValueError("Gitea current-user response did not include a login")
except Exception as exc:
timed_out = isinstance(exc, TimeoutError)
error_message = (

View File

@ -42,6 +42,23 @@ async def test_readiness_endpoint_returns_503_when_gitea_is_unavailable(monkeypa
assert b'"error":"connection refused"' in response.body
@pytest.mark.anyio
async def test_readiness_endpoint_returns_503_for_null_current_user_payload(monkeypatch):
async def null_user():
return None
monkeypatch.setattr(main, "current_user", null_user)
response = await main.readiness()
assert response.status_code == 503
assert json.loads(response.body) == {
"status": "not_ready",
"service": "stackchain-dashboard",
"error": "Gitea current-user response did not include a login",
}
@pytest.mark.anyio
async def test_readiness_endpoint_times_out_and_cancels_stalled_gitea_check(monkeypatch):
cancelled = asyncio.Event()