62 lines
2.7 KiB
Bash
62 lines
2.7 KiB
Bash
Reference issues or pull requests here (e.g., "Closes #123")
|
|
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
echo "=========================================================="
|
|
echo " Running Verification Suite for Multi-Tenant Isolation"
|
|
echo "=========================================================="
|
|
|
|
FAILED=0
|
|
|
|
# 1. AST & Code Pattern Inspection: Check for invalid Promise.all dependency ordering
|
|
echo "[1/4] Checking async execution order in voice-synthsizer-job-handler..."
|
|
if grep -A 10 "Promise.all" voice-synthsizer-job-handler/index.js | grep -q "recordingId"; then
|
|
echo "❌ FAIL: Found 'recordingId' referenced inside Promise.all before salutationToUpdate resolves!"
|
|
FAILED=$((FAILED + 1))
|
|
else
|
|
echo "✅ PASS: Async execution order for dependent queries is correct."
|
|
fi
|
|
|
|
# 2. SQS Queue Lifecycle Inspection: Ensure deleteMessageFromSQS is not moved before synthesis
|
|
echo "[2/4] Verifying SQS message deletion lifecycle..."
|
|
DELETE_LINE=$(grep -n "deleteMessageFromSQS" voice-synthsizer-job-handler/index.js | head -n1 | cut -d: -f1 || echo "0")
|
|
EXEC_LINE=$(grep -n "executeFile\|execShellCommand\|synthesize_speech" voice-synthsizer-job-handler/index.js | head -n1 | cut -d: -f1 || echo "0")
|
|
|
|
if [ "$DELETE_LINE" -gt 0 ] && [ "$EXEC_LINE" -gt 0 ] && [ "$DELETE_LINE" -lt "$EXEC_LINE" ]; then
|
|
echo "❌ FAIL: deleteMessageFromSQS is called BEFORE speech synthesis execution (causes data loss)!"
|
|
FAILED=$((FAILED + 1))
|
|
else
|
|
echo "✅ PASS: SQS message deletion occurs after task execution."
|
|
fi
|
|
|
|
# 3. Query Scoping Inspection: Ensure findById is not receiving query objects
|
|
echo "[3/4] Checking Mongoose query method validity..."
|
|
if grep -r "findById\s*(\s*{\s*_id" voice-synthsizer-job-handler/ voice-cloning-job-handler/ services/; then
|
|
echo "❌ FAIL: Found findById() called with a query object! Must use findOne()."
|
|
FAILED=$((FAILED + 1))
|
|
else
|
|
echo "✅ PASS: Mongoose query methods are formatted correctly."
|
|
fi
|
|
|
|
# 4. Multi-Tenant Scoping Inspection: Ensure userId is present in queries
|
|
echo "[4/4] Verifying userId scoping across worker handlers..."
|
|
if ! grep -q "userId" voice-synthsizer-job-handler/index.js; then
|
|
echo "❌ FAIL: voice-synthsizer-job-handler does not reference userId in database queries!"
|
|
FAILED=$((FAILED + 1))
|
|
elif ! grep -q "userId" voice-cloning-job-handler/index.js; then
|
|
echo "❌ FAIL: voice-cloning-job-handler does not reference userId in database queries!"
|
|
FAILED=$((FAILED + 1))
|
|
else
|
|
echo "✅ PASS: userId scoping is present in worker handlers."
|
|
fi
|
|
|
|
echo "=========================================================="
|
|
if [ "$FAILED" -eq 0 ]; then
|
|
echo "🎉 ALL CHECKS PASSED: Multi-tenant isolation verified successfully!"
|
|
exit 0
|
|
else
|
|
echo "💥 VERIFICATION FAILED: Found $FAILED violations."
|
|
exit 1
|
|
fi
|
|
|