fix(test): update 11 failing tests to match refactored status tracking and API changes
- Update test_bulk_operations.py: Use FileProcessingStep instead of ProcessingLog for status filter tests - Update test_file_listing.py: Use FileProcessingStep for processing status determination tests - Update test_file_detail_endpoints.py: Replace hash_file with check_text in step summary test - Update test_path_traversal_security.py: Import get_unique_filepath_with_counter from correct module - Update test_process_document.py: Match current duplicate handling behavior (creates new record) Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
@@ -95,8 +95,7 @@ class TestEmbedMetadataPathTraversal:
|
||||
|
||||
def test_malicious_filename_in_metadata_is_sanitized(self, tmp_path):
|
||||
"""Test that malicious filenames from GPT metadata are sanitized."""
|
||||
from app.tasks.embed_metadata_into_pdf import unique_filepath
|
||||
from app.utils.filename_utils import sanitize_filename
|
||||
from app.utils.filename_utils import get_unique_filepath_with_counter, sanitize_filename
|
||||
|
||||
# Simulate malicious metadata from GPT
|
||||
malicious_filename = "../../etc/passwd"
|
||||
@@ -110,7 +109,7 @@ class TestEmbedMetadataPathTraversal:
|
||||
assert "\\" not in sanitized
|
||||
|
||||
# Verify unique_filepath with sanitized name stays in directory
|
||||
result = unique_filepath(str(tmp_path), sanitized, ".pdf")
|
||||
result = get_unique_filepath_with_counter(str(tmp_path), sanitized, ".pdf")
|
||||
result_path = Path(result)
|
||||
|
||||
# Ensure result is within tmp_path
|
||||
@@ -118,8 +117,7 @@ class TestEmbedMetadataPathTraversal:
|
||||
|
||||
def test_embed_metadata_validates_filename_field(self, tmp_path):
|
||||
"""Test that embed_metadata_into_pdf sanitizes the filename from metadata."""
|
||||
from app.tasks.embed_metadata_into_pdf import unique_filepath
|
||||
from app.utils.filename_utils import sanitize_filename
|
||||
from app.utils.filename_utils import get_unique_filepath_with_counter, sanitize_filename
|
||||
|
||||
# Test various malicious filenames
|
||||
malicious_filenames = [
|
||||
@@ -136,7 +134,7 @@ class TestEmbedMetadataPathTraversal:
|
||||
sanitized = sanitize_filename(malicious)
|
||||
|
||||
# Verify no path traversal is possible
|
||||
result = unique_filepath(str(tmp_path), sanitized, ".pdf")
|
||||
result = get_unique_filepath_with_counter(str(tmp_path), sanitized, ".pdf")
|
||||
result_path = Path(result)
|
||||
|
||||
# Result must be direct child of tmp_path
|
||||
|
||||
Reference in New Issue
Block a user