827f215115
---ci--- project: orca phase: 10 milestone: v0.12 status: execute ---/ci--- Migration 0008: add prev_hash + entry_hash columns + append-only triggers (UPDATE/DELETE blocked with ABORT). audit_repo.go: Append computes hash chain (sha256(prev_hash || timestamp || actor || action || resource || result || error || metadata)). VerifyChain recomputes from first entry, detects tampering. 2 new tests: VerifyChain (5-entry chain verifies), TamperDetection (UPDATE + DELETE blocked by trigger). All store tests pass.
38 lines
908 B
Go
38 lines
908 B
Go
package store
|
|
|
|
import (
|
|
"context"
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
func TestMigrationVersion(t *testing.T) {
|
|
dir := t.TempDir()
|
|
db, err := Open(filepath.Join(dir, "test.db"))
|
|
if err != nil {
|
|
t.Fatalf("open db: %v", err)
|
|
}
|
|
defer db.Close()
|
|
|
|
ctx := context.Background()
|
|
version, err := MigrationVersion(ctx, db)
|
|
if err != nil {
|
|
t.Fatalf("migration version: %v", err)
|
|
}
|
|
if version != "0008_audit_tamper_evidence.sql" {
|
|
t.Errorf("MigrationVersion = %q, want 0008_audit_tamper_evidence.sql", version)
|
|
}
|
|
|
|
// Empty the migrations table → should return ("", nil).
|
|
if _, err := db.ExecContext(ctx, "DELETE FROM schema_migrations"); err != nil {
|
|
t.Fatalf("clear migrations: %v", err)
|
|
}
|
|
version, err = MigrationVersion(ctx, db)
|
|
if err != nil {
|
|
t.Fatalf("migration version after clear: %v", err)
|
|
}
|
|
if version != "" {
|
|
t.Errorf("MigrationVersion after clear = %q, want empty", version)
|
|
}
|
|
}
|