Files
NotoriousRebel ea5db87915 Merge master into dev to resolve PR #2607 conflicts
Preserve provider outcome release notes alongside the HTTP proxy wording. Keep the dev domain glossary and carry the master HTTP-only proxy policy into its relocated architecture guide. Retain RocketReach cancellation coverage while removing the obsolete global dependency stub.

Align provider lifecycle regressions with the master session-construction boundary: construction ValueError is normalized to transport-error, while cancellation, lifecycle RuntimeError, and teardown ValueError still propagate.
2026-09-09 21:41:46 -04:00

95 lines
4.5 KiB
YAML

name: HarvestView container smoke
on:
workflow_call:
workflow_dispatch:
pull_request:
paths:
- '.dockerignore'
- '.github/workflows/harvestview-container.yml'
- 'Dockerfile'
- 'LICENSE'
- 'docker-compose.yml'
- 'pyproject.toml'
- 'theHarvester/lib/api/**'
- 'tests/test_docker.py'
- 'uv.lock'
permissions:
contents: read
jobs:
container-smoke:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Harden runner
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Prepare operator secret
run: |
install -d -m 0700 .secrets
printf '%s\n' 'harvestview-container-smoke-key' > .secrets/operator-api-key
chmod 0444 .secrets/operator-api-key
- name: Build and start container
env:
THEHARVESTER_PORT: '8769'
run: |
docker compose -p harvestview-container-smoke build theharvester.svc.local
docker compose -p harvestview-container-smoke up -d --no-build
- name: Verify routes, Chromium, and restart persistence
env:
THEHARVESTER_PORT: '8769'
run: |
for attempt in $(seq 1 60); do
if curl --fail --silent --show-error http://127.0.0.1:8769/ > /tmp/harvestview.html; then
break
fi
sleep 1
done
grep --fixed-strings '<title>HarvestView</title>' /tmp/harvestview.html
test "$(curl --silent --output /dev/null --write-out '%{http_code}' http://127.0.0.1:8769/app)" = '404'
test "$(curl --silent --output /dev/null --write-out '%{http_code}' http://127.0.0.1:8769/api/v1/runs)" = '401'
curl --fail --silent --show-error \
--header 'X-API-Key: harvestview-container-smoke-key' \
http://127.0.0.1:8769/api/v1/runs > /dev/null
printf '%s\n' \
'{"completed_at":"2026-08-08T01:01:00Z","counts":{"hostname":1,"ip":1},"evidence_status":"complete","result_count":2,"run_id":"9f9b4383-6cc4-4f3f-80a4-c8d21930dc2d","started_at":"2026-08-08T01:00:00Z","target":"example.test","type":"summary"}' \
'{"type":"hostname","value":"www.example.test"}' \
'{"type":"ip","value":"192.0.2.10"}' > /tmp/smoke.jsonl
curl --fail --silent --show-error \
--request POST \
--header 'Content-Type: application/x-ndjson' \
--header 'X-API-Key: harvestview-container-smoke-key' \
--data-binary @/tmp/smoke.jsonl \
'http://127.0.0.1:8769/api/v1/runs/import?filename=smoke.jsonl' > /tmp/imported-run.json
run_id="$(python3 -c "import json; print(json.load(open('/tmp/imported-run.json', encoding='utf-8'))['run_id'])")"
curl --fail --silent --show-error \
--header 'X-API-Key: harvestview-container-smoke-key' \
"http://127.0.0.1:8769/api/v1/runs/${run_id}/export" \
| python3 -c "import json, sys; rows = [json.loads(line) for line in sys.stdin if line.strip()]; assert rows[0]['type'] == 'summary'; assert any(row.get('type') == 'ip' for row in rows[1:]); assert len(rows) == 3"
docker compose -p harvestview-container-smoke exec -T theharvester.svc.local \
python -c "from playwright.sync_api import sync_playwright; p = sync_playwright().start(); browser = p.chromium.launch(headless=True); browser.close(); p.stop()"
test "$(sha256sum LICENSE | cut -d ' ' -f 1)" = \
"$(docker compose -p harvestview-container-smoke exec -T theharvester.svc.local sha256sum /usr/share/licenses/theharvester/LICENSE | cut -d ' ' -f 1)"
docker compose -p harvestview-container-smoke restart theharvester.svc.local
curl --retry 30 --retry-all-errors --retry-delay 1 --fail --silent --show-error \
--header 'X-API-Key: harvestview-container-smoke-key' \
"http://127.0.0.1:8769/api/v1/runs/${run_id}" > /tmp/persisted-run.json
python3 -c "import json; data = json.load(open('/tmp/persisted-run.json', encoding='utf-8')); assert data['status'] == 'completed'; assert len(data['results']) == 2"
- name: Stop container
if: ${{ always() }}
env:
THEHARVESTER_PORT: '8769'
run: docker compose -p harvestview-container-smoke down --volumes