fix(wecom): scope WECOM_WEBSOCKET_URL like its neighbours
Same class as #100627's WECOM_BOT_ID: the one remaining raw os.getenv in WeComAdapter.__init__ let a secondary multiplex profile pick up the default profile's bridged websocket URL. Route it through _get_scoped_secret; folded into the existing scoped-miss test.
This commit is contained in:
@@ -323,7 +323,7 @@ class WeComAdapter(BasePlatformAdapter):
|
||||
self._ws_url = str(
|
||||
extra.get("websocket_url")
|
||||
or extra.get("websocketUrl")
|
||||
or os.getenv("WECOM_WEBSOCKET_URL", DEFAULT_WS_URL)
|
||||
or _get_scoped_secret("WECOM_WEBSOCKET_URL", DEFAULT_WS_URL)
|
||||
).strip() or DEFAULT_WS_URL
|
||||
|
||||
self._dm_policy = str(extra.get("dm_policy") or _get_scoped_secret("WECOM_DM_POLICY", "pairing")).strip().lower()
|
||||
|
||||
@@ -98,15 +98,17 @@ class TestWeComAdapterAuthzScope:
|
||||
|
||||
def test_scoped_miss_does_not_leak_default_profiles_bot_id(self, multiplex_on, monkeypatch):
|
||||
from agent import secret_scope
|
||||
from plugins.platforms.wecom.adapter import WeComAdapter
|
||||
from plugins.platforms.wecom.adapter import DEFAULT_WS_URL, WeComAdapter
|
||||
|
||||
monkeypatch.setenv("WECOM_BOT_ID", "default-profile-bot-id")
|
||||
monkeypatch.setenv("WECOM_WEBSOCKET_URL", "wss://default-profile.example/ws")
|
||||
token = secret_scope.set_secret_scope({"SOMETHING_ELSE": "x"})
|
||||
try:
|
||||
adapter = WeComAdapter(PlatformConfig(enabled=True))
|
||||
finally:
|
||||
secret_scope.reset_secret_scope(token)
|
||||
assert adapter._bot_id == ""
|
||||
assert adapter._ws_url == DEFAULT_WS_URL
|
||||
|
||||
|
||||
class TestWeComConnect:
|
||||
|
||||
Reference in New Issue
Block a user