feat(firewall): complete rule-match audit context
Signed-off-by: Sebastian Krupinski <krupinski01@gmail.com>
This commit is contained in:
@@ -6,6 +6,7 @@ namespace KTXT\Unit\Service;
|
||||
|
||||
use KTXC\Context\TenantContextInterface;
|
||||
use KTXC\Models\Firewall\FirewallRuleObject;
|
||||
use KTXC\Models\Firewall\FirewallLogObject;
|
||||
use KTXC\Models\Tenant\TenantConfiguration;
|
||||
use KTXC\Service\FirewallService;
|
||||
use KTXC\Service\FirewallRuleCache;
|
||||
@@ -197,6 +198,64 @@ class FirewallServiceTest extends TestCase
|
||||
self::assertTrue($this->service->analyze('203.0.113.10')->isAllowed());
|
||||
}
|
||||
|
||||
#[TestDox('Tenant rule-match logs persist dedicated rule ID and scope fields')]
|
||||
public function testTenantRuleAuditContext(): void
|
||||
{
|
||||
$this->store->expects($this->once())
|
||||
->method('createLog')
|
||||
->with(self::callback(static function (FirewallLogObject $log): bool {
|
||||
return $log->getTenantId() === 'tenant-a'
|
||||
&& $log->getRuleId() === 'tenant-rule'
|
||||
&& $log->getRuleScope() === FirewallRuleObject::SCOPE_TENANT
|
||||
&& $log->getEventType() === FirewallLogObject::EVENT_RULE_MATCH;
|
||||
}))
|
||||
->willReturnArgument(0);
|
||||
$event = \KTXF\Event\SecurityEvent::accessDenied(
|
||||
'203.0.113.10',
|
||||
null,
|
||||
'tenant-rule',
|
||||
FirewallRuleObject::SCOPE_TENANT,
|
||||
'Tenant block'
|
||||
);
|
||||
$event->setTenantId('tenant-a');
|
||||
|
||||
$this->service->logSecurityEvent($event);
|
||||
}
|
||||
|
||||
#[TestDox('System rule matches are logged even when no tenant is resolved')]
|
||||
public function testSystemRuleAuditContext(): void
|
||||
{
|
||||
$this->currentTenant = null;
|
||||
$this->store->expects($this->once())
|
||||
->method('createLog')
|
||||
->with(self::callback(static function (FirewallLogObject $log): bool {
|
||||
return $log->getTenantId() === null
|
||||
&& $log->getRuleId() === 'system-rule'
|
||||
&& $log->getRuleScope() === FirewallRuleObject::SCOPE_SYSTEM;
|
||||
}))
|
||||
->willReturnArgument(0);
|
||||
$event = \KTXF\Event\SecurityEvent::accessDenied(
|
||||
'203.0.113.10',
|
||||
null,
|
||||
'system-rule',
|
||||
FirewallRuleObject::SCOPE_SYSTEM,
|
||||
'System block'
|
||||
);
|
||||
|
||||
$this->service->logSecurityEvent($event);
|
||||
}
|
||||
|
||||
#[TestDox('Tenantless security events without system rule context are ignored')]
|
||||
public function testTenantlessAuditBoundary(): void
|
||||
{
|
||||
$this->currentTenant = null;
|
||||
$this->store->expects($this->never())->method('createLog');
|
||||
|
||||
$this->service->logSecurityEvent(
|
||||
\KTXF\Event\SecurityEvent::authFailure('203.0.113.10')
|
||||
);
|
||||
}
|
||||
|
||||
#[TestDox('Typed tenant firewall settings drive brute-force thresholds')]
|
||||
public function testFirewallConfiguration(): void
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user