mirror of
https://github.com/laramies/theHarvester.git
synced 2026-09-30 13:34:54 +02:00
Preserve provider outcome release notes alongside the HTTP proxy wording. Keep the dev domain glossary and carry the master HTTP-only proxy policy into its relocated architecture guide. Retain RocketReach cancellation coverage while removing the obsolete global dependency stub. Align provider lifecycle regressions with the master session-construction boundary: construction ValueError is normalized to transport-error, while cancellation, lifecycle RuntimeError, and teardown ValueError still propagate.
95 lines
4.5 KiB
YAML
95 lines
4.5 KiB
YAML
name: HarvestView container smoke
|
|
|
|
on:
|
|
workflow_call:
|
|
workflow_dispatch:
|
|
pull_request:
|
|
paths:
|
|
- '.dockerignore'
|
|
- '.github/workflows/harvestview-container.yml'
|
|
- 'Dockerfile'
|
|
- 'LICENSE'
|
|
- 'docker-compose.yml'
|
|
- 'pyproject.toml'
|
|
- 'theHarvester/lib/api/**'
|
|
- 'tests/test_docker.py'
|
|
- 'uv.lock'
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
container-smoke:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
steps:
|
|
- name: Harden runner
|
|
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Check out repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Prepare operator secret
|
|
run: |
|
|
install -d -m 0700 .secrets
|
|
printf '%s\n' 'harvestview-container-smoke-key' > .secrets/operator-api-key
|
|
chmod 0444 .secrets/operator-api-key
|
|
|
|
- name: Build and start container
|
|
env:
|
|
THEHARVESTER_PORT: '8769'
|
|
run: |
|
|
docker compose -p harvestview-container-smoke build theharvester.svc.local
|
|
docker compose -p harvestview-container-smoke up -d --no-build
|
|
|
|
- name: Verify routes, Chromium, and restart persistence
|
|
env:
|
|
THEHARVESTER_PORT: '8769'
|
|
run: |
|
|
for attempt in $(seq 1 60); do
|
|
if curl --fail --silent --show-error http://127.0.0.1:8769/ > /tmp/harvestview.html; then
|
|
break
|
|
fi
|
|
sleep 1
|
|
done
|
|
grep --fixed-strings '<title>HarvestView</title>' /tmp/harvestview.html
|
|
test "$(curl --silent --output /dev/null --write-out '%{http_code}' http://127.0.0.1:8769/app)" = '404'
|
|
test "$(curl --silent --output /dev/null --write-out '%{http_code}' http://127.0.0.1:8769/api/v1/runs)" = '401'
|
|
curl --fail --silent --show-error \
|
|
--header 'X-API-Key: harvestview-container-smoke-key' \
|
|
http://127.0.0.1:8769/api/v1/runs > /dev/null
|
|
printf '%s\n' \
|
|
'{"completed_at":"2026-08-08T01:01:00Z","counts":{"hostname":1,"ip":1},"evidence_status":"complete","result_count":2,"run_id":"9f9b4383-6cc4-4f3f-80a4-c8d21930dc2d","started_at":"2026-08-08T01:00:00Z","target":"example.test","type":"summary"}' \
|
|
'{"type":"hostname","value":"www.example.test"}' \
|
|
'{"type":"ip","value":"192.0.2.10"}' > /tmp/smoke.jsonl
|
|
curl --fail --silent --show-error \
|
|
--request POST \
|
|
--header 'Content-Type: application/x-ndjson' \
|
|
--header 'X-API-Key: harvestview-container-smoke-key' \
|
|
--data-binary @/tmp/smoke.jsonl \
|
|
'http://127.0.0.1:8769/api/v1/runs/import?filename=smoke.jsonl' > /tmp/imported-run.json
|
|
run_id="$(python3 -c "import json; print(json.load(open('/tmp/imported-run.json', encoding='utf-8'))['run_id'])")"
|
|
curl --fail --silent --show-error \
|
|
--header 'X-API-Key: harvestview-container-smoke-key' \
|
|
"http://127.0.0.1:8769/api/v1/runs/${run_id}/export" \
|
|
| python3 -c "import json, sys; rows = [json.loads(line) for line in sys.stdin if line.strip()]; assert rows[0]['type'] == 'summary'; assert any(row.get('type') == 'ip' for row in rows[1:]); assert len(rows) == 3"
|
|
docker compose -p harvestview-container-smoke exec -T theharvester.svc.local \
|
|
python -c "from playwright.sync_api import sync_playwright; p = sync_playwright().start(); browser = p.chromium.launch(headless=True); browser.close(); p.stop()"
|
|
test "$(sha256sum LICENSE | cut -d ' ' -f 1)" = \
|
|
"$(docker compose -p harvestview-container-smoke exec -T theharvester.svc.local sha256sum /usr/share/licenses/theharvester/LICENSE | cut -d ' ' -f 1)"
|
|
docker compose -p harvestview-container-smoke restart theharvester.svc.local
|
|
curl --retry 30 --retry-all-errors --retry-delay 1 --fail --silent --show-error \
|
|
--header 'X-API-Key: harvestview-container-smoke-key' \
|
|
"http://127.0.0.1:8769/api/v1/runs/${run_id}" > /tmp/persisted-run.json
|
|
python3 -c "import json; data = json.load(open('/tmp/persisted-run.json', encoding='utf-8')); assert data['status'] == 'completed'; assert len(data['results']) == 2"
|
|
|
|
- name: Stop container
|
|
if: ${{ always() }}
|
|
env:
|
|
THEHARVESTER_PORT: '8769'
|
|
run: docker compose -p harvestview-container-smoke down --volumes
|