- 1
//! Target verification runs in the broker worker, never in the server - 2
//! (docs/design/72-openxml-documents.md, F4), and fails closed. - 3
- 4
#![allow(clippy::unwrap_used, clippy::expect_used)] - 5
- 6
use std::path::Path; - 7
- 8
use vak_ooxml::fixtures; - 9
use vak_sandbox::TargetCheckPlan; - 10
- 11
fn worker() -> &'static Path { - 12
Path::new(env!("CARGO_BIN_EXE_vak-tool-worker")) - 13
} - 14
- 15
fn plan(path: &str) -> TargetCheckPlan { - 16
TargetCheckPlan { - 17
verifier: "format.openxml".into(), - 18
path: path.into(), - 19
} - 20
} - 21
- 22
#[tokio::test] - 23
async fn office_candidates_are_verified_in_the_worker() { - 24
let root = tempfile::tempdir().unwrap(); - 25
std::fs::write(root.path().join("deck.pptx"), fixtures::pptx()).unwrap(); - 26
std::fs::write( - 27
root.path().join("invoice.docx"), - 28
fixtures::word_with( - 29
"application/vnd.ms-word.document.macroEnabled.main+xml", - 30
fixtures::MINIMAL_WORD_BODY, - 31
&[], - 32
&[], - 33
&[], - 34
&[], - 35
), - 36
) - 37
.unwrap(); - 38
let results = vak_tools::broker::verify_targets( - 39
worker(), - 40
root.path(), - 41
&[plan("deck.pptx"), plan("invoice.docx")], - 42
) - 43
.await; - 44
assert_eq!(results.len(), 2); - 45
assert_eq!(results[0].status, "passed", "{}", results[0].evidence); - 46
assert!( - 47
results[0].evidence.contains("2 slides"), - 48
"{}", - 49
results[0].evidence - 50
); - 51
assert_eq!(results[1].status, "failed"); - 52
assert!( - 53
results[1].evidence.contains("but is named .docx"), - 54
"{}", - 55
results[1].evidence - 56
); - 57
} - 58
- 59
#[tokio::test] - 60
async fn verification_fails_closed_when_the_worker_cannot_run() { - 61
let root = tempfile::tempdir().unwrap(); - 62
std::fs::write(root.path().join("book.xlsx"), fixtures::xlsx()).unwrap(); - 63
let results = vak_tools::broker::verify_targets( - 64
Path::new("/nonexistent/vak-tool-worker"), - 65
root.path(), - 66
&[plan("book.xlsx")], - 67
) - 68
.await; - 69
assert_eq!(results.len(), 1); - 70
assert_eq!(results[0].status, "failed"); - 71
assert!(results[0].evidence.starts_with("verification did not run")); - 72
} - 73
- 74
#[tokio::test] - 75
async fn checks_outside_the_root_are_refused_by_the_worker() { - 76
let root = tempfile::tempdir().unwrap(); - 77
let results = - 78
vak_tools::broker::verify_targets(worker(), root.path(), &[plan("../escape.docx")]).await; - 79
assert_eq!(results[0].status, "failed", "{}", results[0].evidence); - 80
} - 81
Indexing the workspace…
Vakyartha documentation is discovering safe artifacts, anchors, and source references.