"""The agent's token guard. The agent has no users and no roles: one shared ``AGENT_TOKEN`` is the whole access-control model, declared per route as ``dependencies=[Depends(verify_token)]``. That makes a forgotten decorator argument the entire failure mode — one route without it hands anonymous full Docker control of that host, and nothing in review would show it. So the invariant is asserted here rather than assumed across 50 decorators. """ from __future__ import annotations import pytest #: The only agent routes that may answer without a token — the liveness probe #: the container's HEALTHCHECK calls, which returns nothing but a version. UNAUTHENTICATED = {"GET /agent/health"} @pytest.fixture(scope="module") def agent_app(): import agent_app as module return module.app def _routes(app): from fastapi.routing import APIRoute out = [] for route in app.routes: if not isinstance(route, APIRoute): continue for method in sorted(route.methods - {"HEAD", "OPTIONS"}): out.append((f"{method} {route.path}", route)) return sorted(out, key=lambda r: r[0]) def _has_token_guard(route) -> bool: from agent_app import verify_token found = [False] def walk(dependant): for sub in dependant.dependencies: if sub.call is verify_token: found[0] = True walk(sub) walk(route.dependant) return found[0] def test_every_agent_route_requires_the_token(agent_app): unguarded = { key for key, route in _routes(agent_app) if not _has_token_guard(route) and not key.startswith("GET /agent/health") } assert not unguarded, ( "These agent routes answer without AGENT_TOKEN, which is full Docker " f"access to the host: {sorted(unguarded)}" ) def test_only_the_health_probe_is_unauthenticated(agent_app): open_routes = {key for key, route in _routes(agent_app) if not _has_token_guard(route)} assert open_routes == UNAUTHENTICATED def test_a_wrong_token_is_rejected(agent_app, monkeypatch): from starlette.testclient import TestClient from config import settings monkeypatch.setattr(settings, "AGENT_TOKEN", "the-real-token", raising=False) client = TestClient(agent_app, raise_server_exceptions=False) assert client.get("/agent/ping").status_code == 401 assert client.get( "/agent/ping", headers={"Authorization": "Bearer wrong"} ).status_code == 401 # The health probe stays open so the container's HEALTHCHECK works. assert client.get("/agent/health").status_code == 200 def test_an_unset_token_refuses_everything(agent_app, monkeypatch): """An agent started without AGENT_TOKEN must not be wide open.""" from starlette.testclient import TestClient from config import settings monkeypatch.setattr(settings, "AGENT_TOKEN", "", raising=False) client = TestClient(agent_app, raise_server_exceptions=False) response = client.get("/agent/ping", headers={"Authorization": "Bearer anything"}) assert response.status_code == 503