fix(login): atomic credential write and respect server poll_interval
Write credentials via a 0600 temp file + os.replace() so the token file never appears at its final path with world-readable permissions, even if the process is interrupted between write and chmod. Parse poll_interval from the authorization response (clamped to 1–60 s, falling back to _POLL_SLEEP) so aggressive polling can't trigger console rate limits. Tests: add atomicity spy asserting the temp file is 0600 before replace; patch time.sleep instead of _POLL_SLEEP; add explicit interval-passthrough assertion.
This commit is contained in:
+17
-3
@@ -18,6 +18,7 @@ import json
|
|||||||
import os
|
import os
|
||||||
import socket
|
import socket
|
||||||
import sys
|
import sys
|
||||||
|
import tempfile
|
||||||
import time
|
import time
|
||||||
import urllib.error
|
import urllib.error
|
||||||
import urllib.request
|
import urllib.request
|
||||||
@@ -71,7 +72,7 @@ def _save_credentials(
|
|||||||
) -> Path:
|
) -> Path:
|
||||||
path = bot_bottle_root() / "console.json"
|
path = bot_bottle_root() / "console.json"
|
||||||
path.parent.mkdir(parents=True, exist_ok=True)
|
path.parent.mkdir(parents=True, exist_ok=True)
|
||||||
path.write_text(
|
content = (
|
||||||
json.dumps(
|
json.dumps(
|
||||||
{
|
{
|
||||||
"url": console_url,
|
"url": console_url,
|
||||||
@@ -83,7 +84,19 @@ def _save_credentials(
|
|||||||
)
|
)
|
||||||
+ "\n"
|
+ "\n"
|
||||||
)
|
)
|
||||||
path.chmod(0o600)
|
fd, tmp_path_str = tempfile.mkstemp(dir=path.parent, prefix=".console-")
|
||||||
|
tmp = Path(tmp_path_str)
|
||||||
|
try:
|
||||||
|
tmp.chmod(0o600)
|
||||||
|
with os.fdopen(fd, "w") as f:
|
||||||
|
f.write(content)
|
||||||
|
os.replace(tmp, path)
|
||||||
|
except Exception:
|
||||||
|
try:
|
||||||
|
tmp.unlink()
|
||||||
|
except OSError:
|
||||||
|
pass
|
||||||
|
raise
|
||||||
return path
|
return path
|
||||||
|
|
||||||
|
|
||||||
@@ -111,6 +124,7 @@ def cmd_login(argv: list[str]) -> int:
|
|||||||
device_code = resp["device_code"]
|
device_code = resp["device_code"]
|
||||||
user_code = resp["user_code"]
|
user_code = resp["user_code"]
|
||||||
expires_in = resp.get("expires_in", 300)
|
expires_in = resp.get("expires_in", 300)
|
||||||
|
poll_sleep = max(1, min(int(resp.get("poll_interval", _POLL_SLEEP)), 60))
|
||||||
|
|
||||||
sys.stderr.write(
|
sys.stderr.write(
|
||||||
f"\nOpen this URL in your browser to authorize this host:\n\n"
|
f"\nOpen this URL in your browser to authorize this host:\n\n"
|
||||||
@@ -122,7 +136,7 @@ def cmd_login(argv: list[str]) -> int:
|
|||||||
while time.monotonic() < deadline:
|
while time.monotonic() < deadline:
|
||||||
sys.stderr.write(".")
|
sys.stderr.write(".")
|
||||||
sys.stderr.flush()
|
sys.stderr.flush()
|
||||||
time.sleep(_POLL_SLEEP)
|
time.sleep(poll_sleep)
|
||||||
|
|
||||||
try:
|
try:
|
||||||
code, result = _get(
|
code, result = _get(
|
||||||
|
|||||||
@@ -42,6 +42,26 @@ class TestSaveCredentials(unittest.TestCase):
|
|||||||
self.assertEqual(data["refresh_token"], "rt")
|
self.assertEqual(data["refresh_token"], "rt")
|
||||||
self.assertEqual(oct(path.stat().st_mode & 0o777), oct(0o600))
|
self.assertEqual(oct(path.stat().st_mode & 0o777), oct(0o600))
|
||||||
|
|
||||||
|
def test_temp_file_is_private_before_replace(self) -> None:
|
||||||
|
"""Temp file must be 0600 at the moment os.replace is called."""
|
||||||
|
from bot_bottle.cli.login import _save_credentials
|
||||||
|
from pathlib import Path as _Path
|
||||||
|
|
||||||
|
tmp_perms_at_replace: list[int] = []
|
||||||
|
real_replace = os.replace
|
||||||
|
|
||||||
|
def _spy_replace(src: "str | os.PathLike", dst: "str | os.PathLike") -> None:
|
||||||
|
tmp_perms_at_replace.append(_Path(src).stat().st_mode & 0o777)
|
||||||
|
real_replace(src, dst)
|
||||||
|
|
||||||
|
with tempfile.TemporaryDirectory() as tmp:
|
||||||
|
with patch.dict(os.environ, {"BOT_BOTTLE_ROOT": tmp}):
|
||||||
|
with patch("os.replace", side_effect=_spy_replace):
|
||||||
|
path = _save_credentials("http://c", "hid", "at", "rt")
|
||||||
|
self.assertEqual(len(tmp_perms_at_replace), 1)
|
||||||
|
self.assertEqual(oct(tmp_perms_at_replace[0]), oct(0o600))
|
||||||
|
self.assertEqual(oct(path.stat().st_mode & 0o777), oct(0o600))
|
||||||
|
|
||||||
|
|
||||||
class TestCmdLoginMissingUrl(unittest.TestCase):
|
class TestCmdLoginMissingUrl(unittest.TestCase):
|
||||||
def test_returns_1_without_url(self) -> None:
|
def test_returns_1_without_url(self) -> None:
|
||||||
@@ -91,7 +111,7 @@ class TestCmdLoginFlow(unittest.TestCase):
|
|||||||
with patch.dict(os.environ, {"BOT_BOTTLE_ROOT": tmp}):
|
with patch.dict(os.environ, {"BOT_BOTTLE_ROOT": tmp}):
|
||||||
with patch("bot_bottle.cli.login._post", side_effect=_fake_post):
|
with patch("bot_bottle.cli.login._post", side_effect=_fake_post):
|
||||||
with patch("bot_bottle.cli.login._get", side_effect=_fake_get):
|
with patch("bot_bottle.cli.login._get", side_effect=_fake_get):
|
||||||
with patch("bot_bottle.cli.login._POLL_SLEEP", 0):
|
with patch("time.sleep"):
|
||||||
return cmd_login(["--console-url", "http://console"])
|
return cmd_login(["--console-url", "http://console"])
|
||||||
|
|
||||||
def test_approved_flow_returns_0(self) -> None:
|
def test_approved_flow_returns_0(self) -> None:
|
||||||
@@ -121,17 +141,47 @@ class TestCmdLoginFlow(unittest.TestCase):
|
|||||||
start_resp = {
|
start_resp = {
|
||||||
"device_code": "dc",
|
"device_code": "dc",
|
||||||
"user_code": "ZZZ-ZZZ",
|
"user_code": "ZZZ-ZZZ",
|
||||||
"expires_in": 0, # already expired
|
"expires_in": 0, # already expired; loop never runs
|
||||||
"poll_interval": 0,
|
"poll_interval": 2,
|
||||||
}
|
}
|
||||||
|
|
||||||
with tempfile.TemporaryDirectory() as tmp:
|
with tempfile.TemporaryDirectory() as tmp:
|
||||||
with patch.dict(os.environ, {"BOT_BOTTLE_ROOT": tmp}):
|
with patch.dict(os.environ, {"BOT_BOTTLE_ROOT": tmp}):
|
||||||
with patch("bot_bottle.cli.login._post", return_value=start_resp):
|
with patch("bot_bottle.cli.login._post", return_value=start_resp):
|
||||||
with patch("bot_bottle.cli.login._POLL_SLEEP", 0):
|
result = cmd_login(["--console-url", "http://console"])
|
||||||
result = cmd_login(["--console-url", "http://console"])
|
|
||||||
self.assertEqual(result, 1)
|
self.assertEqual(result, 1)
|
||||||
|
|
||||||
|
def test_poll_interval_from_server_is_used(self) -> None:
|
||||||
|
"""time.sleep must be called with the server-provided poll_interval."""
|
||||||
|
from bot_bottle.cli.login import cmd_login
|
||||||
|
|
||||||
|
server_interval = 7
|
||||||
|
start_resp = {
|
||||||
|
"device_code": "dc",
|
||||||
|
"user_code": "ABC-DEF",
|
||||||
|
"expires_in": 300,
|
||||||
|
"poll_interval": server_interval,
|
||||||
|
}
|
||||||
|
approved = {
|
||||||
|
"status": "approved",
|
||||||
|
"host_id": "hid",
|
||||||
|
"access_token": "at",
|
||||||
|
"refresh_token": "rt",
|
||||||
|
}
|
||||||
|
poll_iter = iter([{"status": "pending"}, approved])
|
||||||
|
|
||||||
|
with tempfile.TemporaryDirectory() as tmp:
|
||||||
|
with patch.dict(os.environ, {"BOT_BOTTLE_ROOT": tmp}):
|
||||||
|
with patch("bot_bottle.cli.login._post", return_value=start_resp):
|
||||||
|
with patch("bot_bottle.cli.login._get", side_effect=lambda u: (200, next(poll_iter))):
|
||||||
|
with patch("time.sleep") as mock_sleep:
|
||||||
|
result = cmd_login(["--console-url", "http://console"])
|
||||||
|
|
||||||
|
self.assertEqual(result, 0)
|
||||||
|
self.assertTrue(mock_sleep.called)
|
||||||
|
for call in mock_sleep.call_args_list:
|
||||||
|
self.assertEqual(call.args[0], server_interval)
|
||||||
|
|
||||||
|
|
||||||
class TestDispatcherRegistration(unittest.TestCase):
|
class TestDispatcherRegistration(unittest.TestCase):
|
||||||
def test_login_in_commands(self) -> None:
|
def test_login_in_commands(self) -> None:
|
||||||
|
|||||||
Reference in New Issue
Block a user