mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-07-21 19:48:59 +02:00
A per-scenario end-to-end suite that boots real Traefik + Crowdsec containers and exercises the plugin loaded from a local path. Scenarios: stream / live / none modes, trusted IPs, custom ban page, captcha, and appsec. This suite is local-only (run with `make e2e`): it boots a real Crowdsec and, for appsec, downloads the OWASP CRS collections — heavier and less deterministic than CI needs. CI runs a separate, lighter binary + mock-LAPI suite instead (see the companion PR). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
41 lines
1.3 KiB
Bash
Executable File
41 lines
1.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
HERE="$(cd "$(dirname "$0")" && pwd)"
|
|
# shellcheck source=../../lib/common.sh
|
|
source "$HERE/../../lib/common.sh"
|
|
|
|
SCENARIO=appsec
|
|
PROJECT="e2e-${SCENARIO}"
|
|
COMPOSE_FILE="$HERE/docker-compose.yml"
|
|
LOG_FILE="/tmp/e2e-${SCENARIO}.log"
|
|
|
|
cleanup() {
|
|
local rc=$?
|
|
if (( rc != 0 )); then
|
|
dump_diagnostics "$PROJECT" "$COMPOSE_FILE" > "$LOG_FILE" 2>&1 || true
|
|
echo "Scenario failed. Logs written to $LOG_FILE"
|
|
fi
|
|
docker compose -p "$PROJECT" -f "$COMPOSE_FILE" down -v --remove-orphans >/dev/null 2>&1 || true
|
|
exit $rc
|
|
}
|
|
trap cleanup EXIT
|
|
|
|
echo "[$SCENARIO] starting stack (AppSec collections download — may take ~30s on first boot)..."
|
|
docker compose -p "$PROJECT" -f "$COMPOSE_FILE" up -d --wait
|
|
|
|
echo "[$SCENARIO] waiting for crowdsec readiness..."
|
|
wait_crowdsec_ready crowdsec 180
|
|
|
|
echo "[$SCENARIO] waiting for traefik readiness..."
|
|
wait_for_status http://localhost:8000/foo 200 30
|
|
|
|
echo "[$SCENARIO] benign request must pass"
|
|
assert_status http://localhost:8000/foo 200
|
|
|
|
echo "[$SCENARIO] SQL-injection-like query string must be blocked by OWASP CRS (inband)"
|
|
# Classic SQLi probe: ?id=1' OR '1'='1 — caught by CRS rule 942100/942130 (paranoia 1).
|
|
assert_status "http://localhost:8000/foo?id=1%27%20OR%20%271%27%3D%271" 403
|
|
|
|
echo "[$SCENARIO] OK"
|