7a0da7932b
OSV-Scanner (Scheduled) / scan-scheduled (push) Failing after 0s
Create Release / test-gate (push) Has been cancelled
Create Release / release-gate (push) Has been cancelled
Create Release / ci-gate (push) Has been cancelled
Create Release / version-check (push) Has been cancelled
Create Release / e2e-test-gate (push) Has been cancelled
Create Release / responsive-test-gate (push) Has been cancelled
Create Release / compat-test-gate (push) Has been cancelled
Create Release / compose-integration-gate (push) Has been cancelled
Create Release / vulture-gate (push) Has been cancelled
Create Release / build (push) Has been cancelled
Create Release / provenance (push) Has been cancelled
Create Release / prerelease-docker (push) Has been cancelled
Create Release / publish-docker (push) Has been cancelled
Create Release / create-release (push) Has been cancelled
Create Release / cleanup-changelog (push) Has been cancelled
Create Release / trigger-pypi (push) Has been cancelled
Create Release / monitor-pypi (push) Has been cancelled
Create Release / Clean up orphan prerelease tags and signatures (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-form] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-metrics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [research-workflow] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-core] (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [history-news] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [library] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [link-analytics] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-core] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [chat-lifecycle] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [error-benchmark] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [settings-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) (push) Has been cancelled
Docker Tests (Consolidated) / Accessibility Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Unit Tests (push) Has been cancelled
Docker Tests (Consolidated) / LLM Example Tests (push) Has been cancelled
Docker Tests (Consolidated) / Production Image Smoke Test (push) Has been cancelled
Docker Tests (Consolidated) / Infrastructure Tests (push) Has been cancelled
OSSF Scorecard / OSSF Security Scorecard Analysis (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [mobile] (push) Has been cancelled
Backwards Compatibility / Verify Encryption Constants (push) Has been cancelled
Backwards Compatibility / PyPI Version Compatibility (push) Has been cancelled
Backwards Compatibility / Database Migration Tests (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Docker Tests (Consolidated) / detect-changes (push) Has been cancelled
Docker Tests (Consolidated) / Build Test Image (push) Has been cancelled
Docker Tests (Consolidated) / All Pytest Tests + Coverage (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [accessibility] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [api-crud] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-login] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-pages] (push) Has been cancelled
Docker Tests (Consolidated) / UI Tests (Puppeteer) [auth-register] (push) Has been cancelled
70 lines
2.3 KiB
Python
70 lines
2.3 KiB
Python
"""Tests for filename sanitization."""
|
|
|
|
import pytest
|
|
|
|
from local_deep_research.security.filename_sanitizer import (
|
|
UnsafeFilenameError,
|
|
sanitize_filename,
|
|
)
|
|
|
|
|
|
class TestSanitizeFilename:
|
|
"""Tests for sanitize_filename()."""
|
|
|
|
def test_normal_filename(self):
|
|
assert sanitize_filename("report.pdf") == "report.pdf"
|
|
|
|
def test_path_traversal(self):
|
|
result = sanitize_filename("../../etc/passwd.pdf")
|
|
assert ".." not in result
|
|
assert result == "etc_passwd.pdf"
|
|
|
|
def test_null_bytes_stripped(self):
|
|
result = sanitize_filename("file\x00name.pdf")
|
|
assert "\x00" not in result
|
|
assert result == "filename.pdf"
|
|
|
|
def test_empty_filename_raises(self):
|
|
with pytest.raises(UnsafeFilenameError, match="No filename"):
|
|
sanitize_filename("")
|
|
|
|
def test_none_filename_raises(self):
|
|
with pytest.raises(UnsafeFilenameError, match="No filename"):
|
|
sanitize_filename(None)
|
|
|
|
def test_sanitizes_to_empty_raises(self):
|
|
with pytest.raises(UnsafeFilenameError, match="no safe characters"):
|
|
sanitize_filename("../../../")
|
|
|
|
def test_allowed_extensions_pass(self):
|
|
result = sanitize_filename("doc.pdf", allowed_extensions={".pdf"})
|
|
assert result == "doc.pdf"
|
|
|
|
def test_disallowed_extension_raises(self):
|
|
with pytest.raises(UnsafeFilenameError, match="not allowed"):
|
|
sanitize_filename("script.exe", allowed_extensions={".pdf", ".txt"})
|
|
|
|
def test_extension_check_case_insensitive(self):
|
|
result = sanitize_filename("doc.PDF", allowed_extensions={".pdf"})
|
|
assert result == "doc.PDF"
|
|
|
|
def test_max_length_truncates(self):
|
|
long_name = "a" * 300 + ".pdf"
|
|
result = sanitize_filename(long_name, max_length=50)
|
|
assert len(result) <= 50
|
|
assert result.endswith(".pdf")
|
|
|
|
def test_max_length_no_extension(self):
|
|
long_name = "a" * 300
|
|
result = sanitize_filename(long_name, max_length=50)
|
|
assert len(result) <= 50
|
|
|
|
def test_spaces_in_filename(self):
|
|
result = sanitize_filename("my report file.pdf")
|
|
assert result == "my_report_file.pdf"
|
|
|
|
def test_special_characters(self):
|
|
result = sanitize_filename("file@#$%.pdf")
|
|
assert result # should not be empty
|
|
assert ".." not in result
|