feat(deploy): 自动初始化画布协作认证密钥
This commit is contained in:
@@ -0,0 +1,86 @@
|
||||
#Requires -Version 5.1
|
||||
|
||||
$ErrorActionPreference = "Stop"
|
||||
$scriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path
|
||||
. (Join-Path $scriptDir "Initialize-SecurityEnv.ps1")
|
||||
|
||||
$tempDir = Join-Path ([System.IO.Path]::GetTempPath()) ("easyai-security-env-" + [Guid]::NewGuid())
|
||||
[System.IO.Directory]::CreateDirectory($tempDir) | Out-Null
|
||||
|
||||
function Write-TestEnv {
|
||||
param([string]$Name, [string[]]$Lines)
|
||||
$path = Join-Path $tempDir $Name
|
||||
[System.IO.File]::WriteAllText($path, ($Lines -join "`r`n") + "`r`n", [System.Text.UTF8Encoding]::new($false))
|
||||
return $path
|
||||
}
|
||||
|
||||
function Assert-MinLength {
|
||||
param([string]$Content, [string]$Key, [int]$Minimum)
|
||||
$value = Get-EnvValue $Content $Key
|
||||
if ($value.Length -lt $Minimum) { throw "$Key must contain at least $Minimum characters" }
|
||||
}
|
||||
|
||||
function Assert-Value {
|
||||
param([string]$Content, [string]$Key, [string]$Expected)
|
||||
$actual = Get-EnvValue $Content $Key
|
||||
if ($actual -ne $Expected) { throw "$Key expected '$Expected', got '$actual'" }
|
||||
}
|
||||
|
||||
try {
|
||||
$upgrade = Write-TestEnv "upgrade.env" @(
|
||||
"CONFIG_JWT_SECRET='this is a very secret secret'",
|
||||
"CONFIG_SECURITY_CONFIG_ENCRYPTION_KEY=",
|
||||
"WS_AUTH_WS_TICKET_SECRET=",
|
||||
"WS_AUTH_METHODS=none,bearer"
|
||||
)
|
||||
Initialize-SecurityEnv -Path $upgrade -Mode upgrade
|
||||
$upgradeContent = Get-Content $upgrade -Raw -Encoding UTF8
|
||||
Assert-MinLength $upgradeContent "CONFIG_JWT_SECRET" 32
|
||||
Assert-MinLength $upgradeContent "WS_AUTH_WS_TICKET_SECRET" 32
|
||||
Assert-Value $upgradeContent "CONFIG_SECURITY_CONFIG_ENCRYPTION_KEY" ""
|
||||
Assert-Value $upgradeContent "WS_AUTH_METHODS" "none,bearer,ws_ticket"
|
||||
$upgradeBeforeRepeat = $upgradeContent
|
||||
Initialize-SecurityEnv -Path $upgrade -Mode upgrade
|
||||
$upgradeAfterRepeat = Get-Content $upgrade -Raw -Encoding UTF8
|
||||
if ($upgradeAfterRepeat -cne $upgradeBeforeRepeat) { throw "Repeated upgrade must preserve generated values byte-for-byte" }
|
||||
|
||||
$preservedSecret = "existing-ws-ticket-secret-that-is-long-enough"
|
||||
$preserved = Write-TestEnv "preserved.env" @(
|
||||
"CONFIG_JWT_SECRET=existing-jwt-secret-that-is-long-enough",
|
||||
"WS_AUTH_WS_TICKET_SECRET=$preservedSecret",
|
||||
"WS_AUTH_METHODS=bearer,ws_ticket"
|
||||
)
|
||||
Initialize-SecurityEnv -Path $preserved -Mode upgrade
|
||||
$preservedContent = Get-Content $preserved -Raw -Encoding UTF8
|
||||
Assert-Value $preservedContent "WS_AUTH_WS_TICKET_SECRET" $preservedSecret
|
||||
Assert-Value $preservedContent "WS_AUTH_METHODS" "bearer,ws_ticket"
|
||||
|
||||
$fresh = Write-TestEnv "new.env" @(
|
||||
"CONFIG_JWT_SECRET=",
|
||||
"CONFIG_SECURITY_CONFIG_ENCRYPTION_KEY=",
|
||||
"CONFIG_OTP_HASH_SECRET=",
|
||||
"CONFIG_AUDIT_HASH_PEPPER=",
|
||||
"CONFIG_AUDIT_INTEGRITY_KEY=",
|
||||
"CONFIG_INITIAL_ADMIN_PASSWORD=",
|
||||
"WS_AUTH_WS_TICKET_SECRET=",
|
||||
"WS_AUTH_METHODS="
|
||||
)
|
||||
Initialize-SecurityEnv -Path $fresh -Mode new
|
||||
$freshContent = Get-Content $fresh -Raw -Encoding UTF8
|
||||
foreach ($key in @(
|
||||
"CONFIG_JWT_SECRET",
|
||||
"CONFIG_SECURITY_CONFIG_ENCRYPTION_KEY",
|
||||
"CONFIG_OTP_HASH_SECRET",
|
||||
"CONFIG_AUDIT_HASH_PEPPER",
|
||||
"CONFIG_AUDIT_INTEGRITY_KEY",
|
||||
"WS_AUTH_WS_TICKET_SECRET"
|
||||
)) {
|
||||
Assert-MinLength $freshContent $key 32
|
||||
}
|
||||
Assert-MinLength $freshContent "CONFIG_INITIAL_ADMIN_PASSWORD" 12
|
||||
Assert-Value $freshContent "WS_AUTH_METHODS" "none,bearer,ws_ticket"
|
||||
|
||||
Write-Host "Security environment PowerShell tests passed" -ForegroundColor Green
|
||||
} finally {
|
||||
Remove-Item $tempDir -Recurse -Force -ErrorAction SilentlyContinue
|
||||
}
|
||||
Reference in New Issue
Block a user