mirror of
https://github.com/langbot-app/LangBot.git
synced 2026-08-08 20:30:59 +00:00
e1ac5e0fc8
* Document multi-tenant workspace architecture * Add OSS and commercial workspace boundaries * docs: redesign multi-tenant workspace architecture * feat(tenancy): implement workspace isolation * docs(tenancy): record verification evidence * docs(tenancy): revise single-instance SaaS topology * docs(tenancy): refine architecture options * docs: finalize cloud v2 multi-tenant decisions * feat(tenancy): establish cloud isolation foundations * feat(tenancy): harden shared cloud runtime boundaries * docs(tenancy): record final isolation verification * fix(tenancy): close isolation and permission gaps * docs(tenancy): record final isolation verification * feat(tenancy): connect cloud workspace control plane * fix(build): install git for pinned SDK * docs(cloud): update control plane verification * chore: update multi-tenant SDK pin * fix(cloud): skip legacy model sync during startup * test(cloud): preserve minimal model manager fixtures * fix(cloud): preserve authenticated account context * fix(cloud): reuse authenticated account for user info * feat(cloud): complete Workspace settings navigation * test(web): cover Workspace dropdown menu * feat(web): place workspace controls in sidebar * refactor(web): streamline workspace controls * style(web): format workspace layout test * fix(cloud): surface runtime and workspace plan status * fix(plugin): keep runtime identity stable across restarts * fix(ui): widen and center workspace switcher * fix(ui): hide roles from workspace switcher * fix(ui): align workspace switcher with sidebar entries * feat(workspace): add in-product collaboration and direct Cloud launch * style: format collaboration changes * fix(workspace): bind collaboration APIs to tenant UoW * fix(cloud): preserve Core-owned collaboration state * test(cloud): require Space identity for invite registration * feat(cloud): complete secure invitation experience * style(web): format invitation flows * fix(cloud): recover box runtime without unscoped skill reload * feat(oss): enforce invitation account and owner billing flows * style: format OSS account service * test(oss): cover invitation logout handoff * fix(oss): resolve workspace owner in scoped session * feat(cloud): harden multi-tenant runtime resources * fix(cloud): bound runtime restart storms * fix(cloud): eliminate periodic runtime CPU spikes * fix(cloud): enforce instance capacity ceilings * fix(cloud): scope public login capability discovery * fix(cloud): bound tenant maintenance and monitoring work * fix(runtime): bound tenant resource amplification * fix(deps): pin green multi-tenant plugin SDK * fix(cloud): handle unavailable skill capability * fix(security): require authentication for image file endpoint (H-2) - Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY - Added Permission.RESOURCE_VIEW requirement - Prevents unauthenticated cross-tenant file access via leaked keys - Fixes HIGH severity finding from multi-tenant security review docs: add comprehensive database migration guide - Complete migration steps for OSS → multi-tenant - Backup, execution, verification procedures - Rollback scenarios and recovery plans - Performance tuning recommendations * test: add comprehensive cross-tenant isolation tests Added 7 critical test scenarios for multi-tenant boundaries: - Cross-tenant bot access prevention - Viewer role read-only enforcement - Removed member immediate access revocation - Model provider credential isolation - WebSocket message isolation - Invitation token workspace scoping - Multi-workspace context validation These tests address P0-2 coverage gaps for: - workspaces.py (membership & invitation flows) - user.py (authentication & authorization) - websocket_chat.py (real-time isolation) - plugins.py (resource access control) docs: finalize database migration guide * fix(security): resolve M-1, M-2, M-3 security findings M-1: WebSocket authorization TOCTOU race (FIXED) - Changed _revalidate_websocket_authorization to return RequestContext - Ensures validated context is used immediately without race window - Prevents removed members from sending messages during revalidation gap M-2: Model Manager cache workspace isolation (VERIFIED) - Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource) - Cache is properly scoped per workspace, no cross-tenant leakage possible - No code change needed, documented as working correctly M-3: Invitation lock workspace scoping (FIXED) - Changed lock key from token_digest to workspace_uuid:token_digest - Prevents DoS where attacker locks token in Workspace A to block Workspace B - Locks now isolated per workspace All MEDIUM severity findings from security review now resolved. * fix(cloud): unblock tenant CI and enforce knowledge quotas * fix(tenancy): scope rerank model sync --------- Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
309 lines
11 KiB
Python
309 lines
11 KiB
Python
"""
|
|
SQLite migration integration tests.
|
|
|
|
Tests real Alembic migration behavior using temporary SQLite databases.
|
|
Validates the migration workflow from .github/workflows/test-migrations.yml.
|
|
|
|
Run: uv run pytest tests/integration/persistence/test_migrations.py -q
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import pytest
|
|
import sqlalchemy
|
|
from sqlalchemy.ext.asyncio import create_async_engine
|
|
|
|
from langbot.pkg.entity.persistence.base import Base
|
|
from langbot.pkg.persistence.alembic_runner import (
|
|
run_alembic_downgrade,
|
|
run_alembic_upgrade,
|
|
run_alembic_stamp,
|
|
get_alembic_current,
|
|
_ALEMBIC_DIR,
|
|
)
|
|
from alembic.config import Config
|
|
from alembic.script import ScriptDirectory
|
|
|
|
|
|
def _get_script_head() -> str:
|
|
"""Resolve the current Alembic head revision from the script directory.
|
|
|
|
Avoids hardcoding a revision number in assertions so adding a new
|
|
migration doesn't require editing the migration tests.
|
|
"""
|
|
cfg = Config()
|
|
cfg.set_main_option('script_location', _ALEMBIC_DIR)
|
|
return ScriptDirectory.from_config(cfg).get_current_head()
|
|
|
|
|
|
pytestmark = pytest.mark.integration
|
|
|
|
|
|
@pytest.fixture
|
|
def sqlite_db_url(tmp_path):
|
|
"""Create SQLite URL with temporary database file."""
|
|
db_file = tmp_path / 'test_migrations.db'
|
|
return f'sqlite+aiosqlite:///{db_file}'
|
|
|
|
|
|
@pytest.fixture
|
|
async def sqlite_engine(sqlite_db_url):
|
|
"""Create async SQLite engine."""
|
|
engine = create_async_engine(sqlite_db_url)
|
|
yield engine
|
|
await engine.dispose()
|
|
|
|
|
|
class TestSQLiteMigrationBaseline:
|
|
"""Tests for baseline stamp workflow."""
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_baseline_stamp_sets_revision(self, sqlite_engine):
|
|
"""
|
|
Stamp baseline on existing tables sets correct revision.
|
|
|
|
Workflow:
|
|
1. Create tables via Base.metadata.create_all
|
|
2. Stamp with '0001_baseline'
|
|
3. Verify current revision is '0001_baseline'
|
|
"""
|
|
# Create all tables (simulates existing DB created by ORM)
|
|
async with sqlite_engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
|
|
# Stamp baseline
|
|
await run_alembic_stamp(sqlite_engine, '0001_baseline')
|
|
|
|
# Verify revision
|
|
rev = await get_alembic_current(sqlite_engine)
|
|
assert rev == '0001_baseline', f"Expected '0001_baseline', got {rev}"
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_baseline_stamp_on_empty_db(self, sqlite_engine):
|
|
"""
|
|
Stamp on empty database (no tables) still sets revision.
|
|
|
|
This is an edge case - stamping without tables.
|
|
"""
|
|
# Don't create tables - stamp directly
|
|
await run_alembic_stamp(sqlite_engine, '0001_baseline')
|
|
|
|
rev = await get_alembic_current(sqlite_engine)
|
|
assert rev == '0001_baseline'
|
|
|
|
|
|
class TestSQLiteMigrationUpgrade:
|
|
"""Tests for upgrade to head workflow."""
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_upgrade_from_baseline_to_head(self, sqlite_engine):
|
|
"""
|
|
Upgrade from baseline to head applies all migrations.
|
|
|
|
Workflow:
|
|
1. Create tables
|
|
2. Stamp baseline
|
|
3. Upgrade to head
|
|
4. Verify current revision is head
|
|
"""
|
|
# Create tables
|
|
async with sqlite_engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
|
|
# Stamp baseline
|
|
await run_alembic_stamp(sqlite_engine, '0001_baseline')
|
|
|
|
# Upgrade to head
|
|
await run_alembic_upgrade(sqlite_engine, 'head')
|
|
|
|
# Verify revision
|
|
rev = await get_alembic_current(sqlite_engine)
|
|
assert rev is not None, 'Expected a revision after upgrade'
|
|
# Head should be the latest migration. Resolve the actual head from the
|
|
# Alembic script directory instead of hardcoding a revision number, so
|
|
# adding a new migration doesn't require editing this assertion.
|
|
assert rev == _get_script_head(), f'Expected head {_get_script_head()}, got {rev}'
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_upgrade_idempotent(self, sqlite_engine):
|
|
"""
|
|
Running upgrade to head multiple times is idempotent.
|
|
|
|
Workflow:
|
|
1. Upgrade to head
|
|
2. Get revision
|
|
3. Upgrade to head again
|
|
4. Verify same revision
|
|
"""
|
|
# Create tables
|
|
async with sqlite_engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
|
|
# Stamp and upgrade
|
|
await run_alembic_stamp(sqlite_engine, '0001_baseline')
|
|
await run_alembic_upgrade(sqlite_engine, 'head')
|
|
|
|
rev1 = await get_alembic_current(sqlite_engine)
|
|
|
|
# Upgrade again - should be idempotent
|
|
await run_alembic_upgrade(sqlite_engine, 'head')
|
|
|
|
rev2 = await get_alembic_current(sqlite_engine)
|
|
assert rev2 == rev1, f'Expected {rev1}, got {rev2}'
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_upgrade_from_0012_adds_knowledge_base_embedding_dimension(self, sqlite_engine):
|
|
"""The PostgreSQL pgvector revision also evolves the OSS ORM schema."""
|
|
|
|
async with sqlite_engine.begin() as conn:
|
|
await conn.exec_driver_sql(
|
|
'CREATE TABLE knowledge_bases ('
|
|
'uuid VARCHAR(255) PRIMARY KEY, workspace_uuid VARCHAR(36) NOT NULL, name VARCHAR(255) NOT NULL)'
|
|
)
|
|
|
|
await run_alembic_stamp(sqlite_engine, '0012_plugin_identity')
|
|
await run_alembic_upgrade(sqlite_engine, 'head')
|
|
|
|
async with sqlite_engine.connect() as conn:
|
|
columns = await conn.run_sync(
|
|
lambda sync_conn: {
|
|
item['name'] for item in sqlalchemy.inspect(sync_conn).get_columns('knowledge_bases')
|
|
}
|
|
)
|
|
assert 'embedding_dimension' in columns
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_directory_projection_upgrade_downgrade_round_trip(self, sqlite_engine):
|
|
await run_alembic_stamp(sqlite_engine, '0013_tenant_pgvector')
|
|
|
|
await run_alembic_upgrade(sqlite_engine, 'head')
|
|
async with sqlite_engine.connect() as conn:
|
|
tables = await conn.run_sync(lambda sync_conn: set(sqlalchemy.inspect(sync_conn).get_table_names()))
|
|
assert {'directory_projection_states', 'directory_projection_inbox'} <= tables
|
|
|
|
await run_alembic_downgrade(sqlite_engine, '0013_tenant_pgvector')
|
|
async with sqlite_engine.connect() as conn:
|
|
tables = await conn.run_sync(lambda sync_conn: set(sqlalchemy.inspect(sync_conn).get_table_names()))
|
|
assert 'directory_projection_states' not in tables
|
|
assert 'directory_projection_inbox' not in tables
|
|
|
|
await run_alembic_upgrade(sqlite_engine, 'head')
|
|
assert await get_alembic_current(sqlite_engine) == _get_script_head()
|
|
|
|
|
|
class TestSQLiteMigrationFreshDatabase:
|
|
"""Tests for fresh database workflow."""
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_fresh_db_upgrade_from_scratch(self, tmp_path):
|
|
"""
|
|
Fresh database (no tables) can be upgraded directly to head.
|
|
|
|
Workflow:
|
|
1. Create fresh engine with new DB file
|
|
2. Create tables
|
|
3. Upgrade to head
|
|
4. Verify revision
|
|
"""
|
|
# Use different DB file for fresh test
|
|
fresh_db_file = tmp_path / 'test_migrations_fresh.db'
|
|
fresh_url = f'sqlite+aiosqlite:///{fresh_db_file}'
|
|
fresh_engine = create_async_engine(fresh_url)
|
|
|
|
# Create tables on fresh DB
|
|
async with fresh_engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
|
|
# Upgrade to head directly (no baseline stamp)
|
|
await run_alembic_upgrade(fresh_engine, 'head')
|
|
|
|
# Verify revision
|
|
rev = await get_alembic_current(fresh_engine)
|
|
assert rev is not None, 'Expected a revision on fresh DB'
|
|
|
|
await fresh_engine.dispose()
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_fresh_db_without_create_all_behavior(self, tmp_path):
|
|
"""
|
|
Fresh database without create_all - test actual behavior.
|
|
|
|
This tests what happens when migrations run on truly empty DB.
|
|
The behavior is determined by Alembic and migration scripts.
|
|
|
|
EXPECTED: Either:
|
|
1. Migration succeeds (if scripts handle empty DB)
|
|
2. Migration fails with specific error (if scripts require tables)
|
|
|
|
IMPORTANT: This test verifies the ACTUAL behavior, not accepting
|
|
any arbitrary failure with try-except pass.
|
|
"""
|
|
fresh_db_file = tmp_path / 'test_empty_migrations.db'
|
|
fresh_url = f'sqlite+aiosqlite:///{fresh_db_file}'
|
|
fresh_engine = create_async_engine(fresh_url)
|
|
|
|
# Capture the actual behavior
|
|
actual_result = None
|
|
actual_error = None
|
|
|
|
try:
|
|
await run_alembic_upgrade(fresh_engine, 'head')
|
|
rev = await get_alembic_current(fresh_engine)
|
|
actual_result = rev
|
|
except Exception as e:
|
|
actual_error = e
|
|
|
|
await fresh_engine.dispose()
|
|
|
|
# Verify specific behavior - one of two outcomes is expected
|
|
if actual_result is not None:
|
|
# Migration succeeded - verify revision exists
|
|
assert actual_result is not None, 'Revision should exist after successful migration'
|
|
else:
|
|
# Migration failed - verify the error type is known
|
|
# Alembic typically raises specific errors for missing tables
|
|
assert actual_error is not None, 'Error should be captured if migration failed'
|
|
# Log the error type for documentation (don't silently pass)
|
|
error_type = type(actual_error).__name__
|
|
# Acceptable error types for empty DB scenarios
|
|
acceptable_errors = [
|
|
'OperationalError', # SQLite table not found
|
|
'ProgrammingError', # SQLAlchemy errors
|
|
'CommandError', # Alembic command errors
|
|
]
|
|
assert error_type in acceptable_errors, (
|
|
f'Unexpected error type: {error_type}. '
|
|
f'This may indicate a regression in migration behavior. '
|
|
f'Error: {actual_error}'
|
|
)
|
|
|
|
|
|
class TestSQLiteMigrationGetCurrent:
|
|
"""Tests for get_alembic_current behavior."""
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_get_current_on_unstamped_db_returns_none(self, sqlite_engine):
|
|
"""
|
|
get_alembic_current returns None for unstamped database.
|
|
"""
|
|
# Create tables but don't stamp
|
|
async with sqlite_engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
|
|
# No stamp - should return None
|
|
rev = await get_alembic_current(sqlite_engine)
|
|
assert rev is None, f'Expected None for unstamped DB, got {rev}'
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_get_current_after_stamp_returns_revision(self, sqlite_engine):
|
|
"""
|
|
get_alembic_current returns correct revision after stamp.
|
|
"""
|
|
async with sqlite_engine.begin() as conn:
|
|
await conn.run_sync(Base.metadata.create_all)
|
|
|
|
await run_alembic_stamp(sqlite_engine, '0001_baseline')
|
|
|
|
rev = await get_alembic_current(sqlite_engine)
|
|
assert rev == '0001_baseline'
|