Add audit maintenance, verified recovery and reproducible verification

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
tegwick 2026-09-28 11:48:01 +02:00
parent 820f0ff7b5
commit 3166da1d2e
13 changed files with 413 additions and 5 deletions

View file

@ -55,3 +55,18 @@ class ServiceTests(unittest.TestCase):
response, _ = call('/ack/logout', 'POST', session_cookie, query='', body=form)
self.assertEqual(response['status'], '200 OK')
self.assertIsNone(login.session(session_cookie.split('=', 1)[1]))
def test_private_metrics_route_without_identity_or_event_labels(self):
with tempfile.TemporaryDirectory() as tmp:
token=Path(tmp)/'token';token.write_text('w'*32)
store=Store(Path(tmp)/'state.db')
router=Router({'origin':'https://telemetry.example','webhook_token_file':str(token)},
store,login=object(),policy=lambda *args: None)
router.last_drain=123
result={}
output=b''.join(router({'PATH_INFO':'/metrics','REQUEST_METHOD':'GET'},
lambda status,headers:result.update(status=status,headers=dict(headers))))
self.assertEqual(result['status'],'200 OK')
self.assertIn('version=0.0.4',result['headers']['Content-Type'])
self.assertIn(b'{status="blocked"} 0',output)
self.assertIn(b'timestamp_seconds 123.0',output)