feat(audit): P1 cross-tenant/RBAC tests, P3 test fixes, P2/P3 frontend fixes
Check Cross-Plugin Imports / check (push) Has been cancelled

- P1-Tests: 12 test files with new cross-tenant isolation + RBAC tests
- P3-Tests: 8 fixes (duplicate fixtures, sys.path.insert, unused imports, KeyError)
- P3-Frontend: LucideIcons → ICON_MAP (2 files), inline styles → Tailwind (2 files)
- P3-Frontend: DOMPurify for iframe XSS, redundant regex removed, console.log → console.debug
- P2-Frontend: 2 notification API TODOs retained (requires larger refactor)
- conftest.py: create_no_perm_user helper added
- pyproject.toml: pythonpath for scripts/ added
- All checks green: ruff 0, F821 0, tsc 0, app 495 routes, cross-plugin 0
This commit is contained in:
Agent Zero
2026-08-16 01:30:02 +02:00
parent abbe7a18fc
commit db97a39133
29 changed files with 618 additions and 52 deletions
+47
View File
@@ -162,3 +162,50 @@ class TestCustomFieldDefinition:
)
assert len(manifest.custom_fields) == 1
assert manifest.custom_fields[0].name == "score"
# ── Cross-tenant isolation test ──
@pytest.mark.asyncio
class TestCustomFieldsCrossTenant:
"""Custom fields must not leak across tenants."""
async def test_cross_tenant_isolation(self, client: AsyncClient, db_session):
"""Tenant B cannot access custom fields of tenant A's contact."""
from httpx import ASGITransport
from httpx import AsyncClient as AC
import app.main
await seed_tenant_and_users(db_session)
await login_client(client, "admin@tenanta.com")
# Create a contact in tenant A
create_resp = await client.post(
"/api/v1/contacts",
json={"type": "company", "name": "Tenant A Custom Corp", "displayname": "Tenant A Custom Corp"},
headers=ORIGIN_HEADER,
)
assert create_resp.status_code == 201
contact_id = create_resp.json()["id"]
# Tenant B admin must not access tenant A's contact custom fields
app_instance = app.main.app
async with AC(transport=ASGITransport(app=app_instance), base_url="http://test") as client_b:
await login_client(client_b, "admin@tenantb.com")
resp = await client_b.get(
f"/api/v1/contacts/{contact_id}/custom-fields",
headers=ORIGIN_HEADER,
)
assert resp.status_code == 404
async def test_rbac_no_permission(self, client: AsyncClient, db_session):
"""User without contacts:read permission gets 403 on GET custom fields."""
from tests.conftest import create_no_perm_user
seed = await seed_tenant_and_users(db_session)
await create_no_perm_user(db_session, seed)
await login_client(client, "noperm@tenanta.com")
resp = await client.get(
"/api/v1/contacts/00000000-0000-0000-0000-000000000000/custom-fields",
headers=ORIGIN_HEADER,
)
assert resp.status_code == 403