R-CMD-check / R CMD check (pull_request) Successful in 3m53s
- Add test verifying .send_webhook() and .send_desktop_notify() use
system2() (not system()) to prevent command injection. This test
reads the function body and asserts system2 is present and
system("...") is absent, so the vulnerability cannot be
reintroduced by accident.
- Add test for beep(type='all') exercising both beep and notify paths.
57 lines
2.4 KiB
R
57 lines
2.4 KiB
R
# Test beep / notification function
|
|
|
|
context("Test beep() function")
|
|
|
|
test_that("beep() returns invisibly", {
|
|
expect_invisible(beep())
|
|
expect_invisible(beep("test", type = "beep"))
|
|
expect_invisible(beep("test", type = "all"))
|
|
})
|
|
|
|
test_that("beep() with quiet=TRUE produces no output", {
|
|
expect_silent(beep("test", type = "beep", quiet = TRUE))
|
|
})
|
|
|
|
test_that("beep() with type=notify is silent when no tools available", {
|
|
# When notify-send and osascript are both absent, should be silent
|
|
expect_silent(beep("test", type = "notify"))
|
|
})
|
|
|
|
test_that("beep() with type=webhook and no URL is silent", {
|
|
expect_silent(beep("test", type = "webhook"))
|
|
})
|
|
|
|
test_that("beep(type='all') exercises both beep and notify paths", {
|
|
# type="all" should trigger the terminal beep (unless quiet) and
|
|
# attempt a desktop notification. We verify by checking that the
|
|
# function returns invisibly and does not error when notify-send
|
|
# is absent (which is the case in CI).
|
|
expect_invisible(beep("all-test", type = "all"))
|
|
expect_invisible(beep("all-test", type = "all", quiet = TRUE))
|
|
})
|
|
|
|
test_that("notification helpers use system2() to prevent command injection", {
|
|
# Security regression: .send_webhook and .send_desktop_notify must
|
|
# use system2() with separate args, never system() with shell
|
|
# interpolation. system2() passes arguments directly to the
|
|
# executable without going through a shell, so shell metacharacters
|
|
# in msg, status, url, or payload are treated as literal data.
|
|
|
|
webhook_body <- deparse(body(.send_webhook))
|
|
notify_body <- deparse(body(.send_desktop_notify))
|
|
|
|
# Must use system2
|
|
expect_true(any(grepl("system2", webhook_body)),
|
|
info = ".send_webhook() must use system2() to avoid shell injection")
|
|
expect_true(any(grepl("system2", notify_body)),
|
|
info = ".send_desktop_notify() must use system2() to avoid shell injection")
|
|
|
|
# Must NOT use system( with string interpolation (system("curl ..."))
|
|
# We look for system( followed by a string literal (the old pattern).
|
|
# system2 calls look like system2("curl", args = ...) which is fine.
|
|
expect_false(any(grepl('system\\(\\s*"', webhook_body)),
|
|
info = ".send_webhook() must not use system() with interpolated strings")
|
|
expect_false(any(grepl('system\\(\\s*"', notify_body)),
|
|
info = ".send_desktop_notify() must not use system() with interpolated strings")
|
|
})
|