Public Access
Restructure into src/tests and add build foundation (M0)
Moves the scaffold to src/DodoSSH.Api and establishes the repo conventions the rest
of the milestones build on.
Structure:
- src/{Contracts,Crypto,Domain,Infrastructure,Api}, tests/{Contracts,Crypto,Domain}.Tests
- DodoSSH.slnx rewritten with src/ and tests/ solution folders
Build:
- Directory.Build.props centralises TFM, nullable, deterministic builds and
TreatWarningsAsErrors; Directory.Packages.props pins every version centrally
- packages.lock.json committed so CI restores in locked mode
- NuGet.config clears machine-level sources, which both fixes NU1507 under central
package management and makes restore reproducible off this machine
- Microsoft.OpenApi pinned to 2.11.0: ASP.NET Core 10.0.10 resolves 2.0.0, which is
covered by GHSA-v5pm-xwqc-g5wc (high, patched in 2.7.5)
Analyzers:
- AnalysisLevel is Recommended, not All. With warnings-as-errors, All turns opinionated
naming rules into build breaks and trains people to blanket-suppress.
- BannedSymbols.txt bans DateTime.UtcNow (TimeProvider), Guid.NewGuid (CreateVersion7),
sync-over-async, MD5/SHA1, PBKDF2 and SecureString
- CA1711/CA1724 disabled: both are .NET Framework CAS-era naming rules
- PublicApiAnalyzers on Contracts only, since that assembly is the client's real contract
API:
- weather-forecast template removed
- UseHttpsRedirection removed; TLS terminates at the reverse proxy and redirecting
behind one causes loops
- /healthz/{live,ready,startup}. Liveness deliberately checks no dependencies so a
transient database outage cannot restart the container and kill live SSH sessions.
Notes:
- No coverage collector yet. Microsoft.Testing.Extensions.CodeCoverage pulls an MTP 1.x
MSBuild extension that throws TypeLoadException against the MTP 2.3.x xunit.v3 brings.
Coverage gates are an M3 concern; revisit with an MTP 2.x-aligned version then.
Verified: dotnet build (0 warnings), 17 tests pass, format check clean, API serves
health and OpenAPI endpoints.
This commit is contained in:
@@ -0,0 +1,51 @@
|
||||
using DodoSSH.Domain.Authorization;
|
||||
|
||||
namespace DodoSSH.Domain.Tests.Authorization;
|
||||
|
||||
/// <summary>
|
||||
/// Permission algebra. This grows into the full effective-permission suite in M3; for now
|
||||
/// it pins the flag values, because they are persisted as an integer column and changing
|
||||
/// one silently reinterprets every stored ACL row.
|
||||
/// </summary>
|
||||
public sealed class PermissionFlagsTests
|
||||
{
|
||||
[Theory]
|
||||
[InlineData(PermissionFlags.None, 0)]
|
||||
[InlineData(PermissionFlags.Read, 1)]
|
||||
[InlineData(PermissionFlags.Write, 2)]
|
||||
[InlineData(PermissionFlags.Connect, 4)]
|
||||
[InlineData(PermissionFlags.Share, 8)]
|
||||
[InlineData(PermissionFlags.Admin, 16)]
|
||||
public void Flag_HasStableWireValue(PermissionFlags flag, int expected)
|
||||
{
|
||||
// These values are persisted; a change reinterprets existing ACL rows.
|
||||
((int)flag).ShouldBe(expected);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void Union_CombinesGrantsFromMultipleSubjects()
|
||||
{
|
||||
// Effective permissions are a union across direct and team-derived grants.
|
||||
var direct = PermissionFlags.Read;
|
||||
var viaTeam = PermissionFlags.Write | PermissionFlags.Connect;
|
||||
|
||||
var effective = direct | viaTeam;
|
||||
|
||||
effective.HasFlag(PermissionFlags.Read).ShouldBeTrue();
|
||||
effective.HasFlag(PermissionFlags.Write).ShouldBeTrue();
|
||||
effective.HasFlag(PermissionFlags.Connect).ShouldBeTrue();
|
||||
effective.HasFlag(PermissionFlags.Admin).ShouldBeFalse();
|
||||
effective.HasFlag(PermissionFlags.Share).ShouldBeFalse();
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void Union_IsMonotonic()
|
||||
{
|
||||
// The deliberate consequence of having no Deny rules: adding a grant can only
|
||||
// ever widen access, never narrow it. M3's evaluator relies on this.
|
||||
var before = PermissionFlags.Read;
|
||||
var after = before | PermissionFlags.Admin;
|
||||
|
||||
(after & before).ShouldBe(before);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user