Files
Aegis/backend/tests/test_evidence_file_validation.py
T
kitos 99e8feff48
Aegis CI / lint-and-test (push) Has been cancelled
Snyk Security Scan / Python vulnerabilities (backend) (push) Has been cancelled
Snyk Security Scan / npm vulnerabilities (frontend) (push) Has been cancelled
Snyk Security Scan / Docker image vulnerabilities (backend) (push) Has been cancelled
feat(evidence): allow .exe uploads for Red-team artifacts shared with Blue
The evidence upload extension whitelist blocked .exe entirely, but sharing
a Red team payload binary with Blue for detection analysis is a normal
part of this platform's workflow.
2026-07-27 14:40:45 +02:00

29 lines
846 B
Python

"""Evidence upload file-type validation — Red team artifacts (e.g. .exe
payloads) must be shareable with Blue for detection analysis."""
import pytest
from app.domain.errors import BusinessRuleViolation
from app.services.evidence_service import validate_file
def test_exe_files_are_allowed():
validate_file("payload.exe", 1024)
def test_allowed_extensions_still_pass():
for name in ("screenshot.png", "notes.pdf", "capture.pcap", "archive.zip"):
validate_file(name, 1024)
def test_disallowed_extension_still_rejected():
with pytest.raises(BusinessRuleViolation):
validate_file("script.sh", 1024)
def test_oversized_file_still_rejected():
from app.services.evidence_service import MAX_UPLOAD_SIZE
with pytest.raises(BusinessRuleViolation):
validate_file("payload.exe", MAX_UPLOAD_SIZE + 1)