* implement analyzer interface for shopify * fixed shopify analyzer according to new code and generated permissions * shopify analyzer test added * [chore] - key validations - linked analyzer with detectors * [chore] - moved redundant initialize to global. * [chore] moved expected output of test in json file to neat the code. * [Fixes] - Fixed permission and category resource issue in shopify analyzer - corrected test for shopify analyzer --------- Co-authored-by: Abdul Basit <[email protected]>
89 lines
2.4 KiB
Go
89 lines
2.4 KiB
Go
package shopify
|
|
|
|
import (
|
|
_ "embed"
|
|
"encoding/json"
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/analyzer/analyzers"
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/analyzer/config"
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
|
"github.com/trufflesecurity/trufflehog/v3/pkg/context"
|
|
)
|
|
|
|
//go:embed expected_output.json
|
|
var expectedOutput []byte
|
|
|
|
func TestAnalyzer_Analyze(t *testing.T) {
|
|
ctx, cancel := context.WithTimeout(context.Background(), time.Second*5)
|
|
defer cancel()
|
|
testSecrets, err := common.GetSecret(ctx, "trufflehog-testing", "detectors4")
|
|
if err != nil {
|
|
t.Fatalf("could not get test secrets from GCP: %s", err)
|
|
}
|
|
|
|
secret := testSecrets.MustGetField("SHOPIFY_ADMIN_SECRET")
|
|
domain := testSecrets.MustGetField("SHOPIFY_DOMAIN")
|
|
|
|
tests := []struct {
|
|
name string
|
|
key string
|
|
storeUrl string
|
|
want string
|
|
wantErr bool
|
|
}{
|
|
{
|
|
name: "valid Shopify key",
|
|
key: secret,
|
|
storeUrl: domain,
|
|
want: string(expectedOutput),
|
|
wantErr: false,
|
|
},
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
a := Analyzer{Cfg: &config.Config{}}
|
|
got, err := a.Analyze(ctx, map[string]string{"key": tt.key, "store_url": tt.storeUrl})
|
|
if (err != nil) != tt.wantErr {
|
|
t.Errorf("Analyzer.Analyze() error = %v, wantErr %v", err, tt.wantErr)
|
|
return
|
|
}
|
|
|
|
// Marshal the actual result to JSON
|
|
gotJSON, err := json.Marshal(got)
|
|
if err != nil {
|
|
t.Fatalf("could not marshal got to JSON: %s", err)
|
|
}
|
|
|
|
// Parse the expected JSON string
|
|
var wantObj analyzers.AnalyzerResult
|
|
if err := json.Unmarshal([]byte(tt.want), &wantObj); err != nil {
|
|
t.Fatalf("could not unmarshal want JSON string: %s", err)
|
|
}
|
|
|
|
// Marshal the expected result to JSON (to normalize)
|
|
wantJSON, err := json.Marshal(wantObj)
|
|
if err != nil {
|
|
t.Fatalf("could not marshal want to JSON: %s", err)
|
|
}
|
|
|
|
// Compare the JSON strings
|
|
if string(gotJSON) != string(wantJSON) {
|
|
// Pretty-print both JSON strings for easier comparison
|
|
var gotIndented, wantIndented []byte
|
|
gotIndented, err = json.MarshalIndent(got, "", " ")
|
|
if err != nil {
|
|
t.Fatalf("could not marshal got to indented JSON: %s", err)
|
|
}
|
|
wantIndented, err = json.MarshalIndent(wantObj, "", " ")
|
|
if err != nil {
|
|
t.Fatalf("could not marshal want to indented JSON: %s", err)
|
|
}
|
|
t.Errorf("Analyzer.Analyze() = %s, want %s", gotIndented, wantIndented)
|
|
}
|
|
})
|
|
}
|
|
}
|