한 커밋인 이유: src/build.gradle 안에서 ca.testkit-publisher 플러그인 제거와
게이트 수정이 얽혀 있다. 플러그인 적용부만 빼면 web·websocket·persistence-jpa·
persistence-mongo·app-bootstrap 이 사라진 testkitPublisher() 와 *Testkit
컨피규레이션을 계속 참조해 설정 단계에서 빌드가 죽는다. 파일 단위로 나눌 수 없다.
1) testkit 소스셋 → Gradle 표준 java-test-fixtures 이관
web, websocket, persistence-jpa, persistence-mongo, httpclient, graphql 과
이들의 testkit 컨피규레이션을 소비하던 app-bootstrap.
자체 제작 ca.testkit-publisher.gradle 77줄이 사라진다.
2) 실행되지 않거나 실패할 수 없던 빌드 게이트 정상화 (E등급)
- strict-test-lane 의 실행 카운터가 skip 을 실행으로 세던 것 수정.
전부 skip 인 레인은 이제 실패한다 (회귀 테스트 2건 추가)
- public-path 스냅샷이 gitignore 된 src/.env 를 읽던 것을
config/security.yml 의 바인딩 기본값으로 교체
- verifyEnvKeys 가 build/ 산출물을 소스로 읽어 삭제된 키를 사용 중으로
오판하던 것 수정 (입력 4,637 → 4,630 파일)
- jpa-evidence 가 git 실패를 "워크트리 깨끗함"으로 읽던 것을 fail-closed 로
- notification-evidence 의 Grade 열 탐지를 헤더 기준으로 교체 +
표 부재 시 fail-closed
- spring70CompatibilityTest 가 레인을 복제하며 잃은 fail-closed 복구
(태스크명 유지 — 워크플로 3곳과 gate-matrix 린트 무손상)
- 메시징 R2 스켈레톤 주변의 도달 불가 검증 45줄을 MSG-015 명시적 실패로 교체
3) git 에 없던 빌드 필수 파일 추적
- src/gradle/libs.versions.toml — src/build.gradle 이 9곳에서 참조하는데
추적되지 않아 깨끗한 체크아웃에서 설정이 실패했다
- app-bootstrap config/*.yml 15개 — application.yml 이 전부 import 한다.
하드코딩된 시크릿은 없고 값은 secret://environment/APP_* 참조다
4) 진행 중이던 구현 작업 반영 (redis/idempotency 구성, startup 검증,
아키텍처 테스트 클래스, notification 콜백 레지스트리 등)
검증:
- 깨끗한 체크아웃에서 ./gradlew help 통과
- :app-bootstrap:test --tests 'dev.caskeleton.bootstrap.architecture.*'
→ 20개 클래스 174 tests, 실패 0, 스킵 0 (이전에는 0개 실행)
미해결: verifyOneTypePerFile 은 손대지 않았다(Checkstyle 로 교체 권고).
B/C/D 등급 100여 건과 CI 단계 분리는 별도 작업 —
docs/superpowers/plans/2026-09-16-ci-stage-separation.md 참고.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
151 lines
7.5 KiB
Groovy
151 lines
7.5 KiB
Groovy
// The snapshot's input is the COMMITTED binding default in config/security.yml, not src/.env.
|
|
//
|
|
// It used to read rootProject.file('.env'). /.gitignore:7 excludes `src/.env*` (allowing only the
|
|
// two *.example files), so `git ls-files src/.env` is empty and the file does not exist in a CI
|
|
// checkout — a gate whose expected value comes from an untracked file is not reproducible, and the
|
|
// first line of this closure turned that into a hard failure on any clean machine. Locally it was
|
|
// worse than a failure: it passed against one developer's file. The committed snapshot recorded
|
|
// `/api/healthcheck`, taken from that local .env, while the shipped default in
|
|
// app-bootstrap/src/main/resources/config/security.yml binds
|
|
// public-paths: ${SECURITY_PUBLIC_PATHS:${PRESENTATION_API_BASE_PATH:/v1}/healthcheck}
|
|
// = /v1/healthcheck. The reviewed snapshot therefore described a surface no deployment had.
|
|
//
|
|
// What the snapshot now pins is the permitAll surface a deployment gets when no operator override
|
|
// is set — the thing a reviewer must see change. An operator's own SECURITY_PUBLIC_PATHS at run
|
|
// time is outside the repository and outside any build gate; the default is the part this
|
|
// repository is accountable for.
|
|
Closure<String> renderPublicPathSnapshot = { File securityConfigFile ->
|
|
if (!securityConfigFile.isFile()) {
|
|
throw new GradleException(
|
|
"missing public-path security configuration ${securityConfigFile}")
|
|
}
|
|
|
|
def bindingPattern = ~/^\s*public-paths:\s*(\S.*?)\s*$/
|
|
List<String> bindings = securityConfigFile.readLines('UTF-8').findResults { String line ->
|
|
def matcher = bindingPattern.matcher(line)
|
|
matcher.matches() ? matcher.group(1) : null
|
|
}
|
|
if (bindings.size() != 1) {
|
|
throw new GradleException(
|
|
"expected exactly one 'public-paths:' binding in ${securityConfigFile}, " +
|
|
"found ${bindings.size()} — the snapshot cannot say which surface it pins")
|
|
}
|
|
|
|
// Resolve Spring placeholders to their defaults, innermost first:
|
|
// ${A:${B:/v1}/healthcheck} -> ${A:/v1/healthcheck} -> /v1/healthcheck.
|
|
// `[^{}]*` only ever matches the innermost placeholder, so one substitution per pass unwinds
|
|
// the nesting from the inside out without any replacement-string escaping.
|
|
def defaultedPlaceholder = ~/\$\{[A-Za-z0-9_.]+:([^{}]*)\}/
|
|
String raw = bindings.first()
|
|
for (int guard = 0; guard < 16; guard++) {
|
|
def matcher = defaultedPlaceholder.matcher(raw)
|
|
if (!matcher.find()) {
|
|
break
|
|
}
|
|
raw = raw.substring(0, matcher.start()) + matcher.group(1) + raw.substring(matcher.end())
|
|
}
|
|
if (raw.contains('${')) {
|
|
throw new GradleException(
|
|
"'public-paths' in ${securityConfigFile} resolves to '${raw}', which still holds a " +
|
|
'placeholder with no default — the deployed public path surface is not ' +
|
|
'determined by the repository and cannot be snapshotted')
|
|
}
|
|
List<String> publicPaths = raw.split(',')
|
|
.collect { String value -> value.trim() }
|
|
.findAll { String value -> !value.isEmpty() }
|
|
.toSorted()
|
|
|
|
String header =
|
|
"# feature-security-operational-baseline D5 — deny-by-default public path snapshot.\n" +
|
|
"# SSOT: ca-skeleton.security.public-paths default in " +
|
|
"app-bootstrap/src/main/resources/config/security.yml\n" +
|
|
"# -> SecurityConfig permitAll(); anyRequest authenticated. An operator's own " +
|
|
"SECURITY_PUBLIC_PATHS\n" +
|
|
"# overrides it at run time and is outside this snapshot.\n" +
|
|
"# Update only after review with: ./gradlew updatePublicPathSnapshot " +
|
|
"-PapprovePublicPathChange\n"
|
|
header + (publicPaths.isEmpty() ? '' : publicPaths.join('\n') + '\n')
|
|
}
|
|
|
|
File publicPathSourceFile =
|
|
rootProject.file('app-bootstrap/src/main/resources/config/security.yml')
|
|
File publicPathSnapshotFile =
|
|
rootProject.file('../docs/security/public-paths-snapshot.txt')
|
|
boolean publicPathUpdateApproved = project.hasProperty('approvePublicPathChange')
|
|
def existingPublicPathSource = providers.provider {
|
|
publicPathSourceFile.isFile() ? publicPathSourceFile : null
|
|
}
|
|
def existingPublicPathSnapshot = providers.provider {
|
|
publicPathSnapshotFile.isFile() ? publicPathSnapshotFile : null
|
|
}
|
|
|
|
tasks.register('verifyPublicPathSnapshot') {
|
|
group = 'verification'
|
|
description = 'Fails without mutation when the committed deny-by-default public path baseline drifts.'
|
|
inputs.file(existingPublicPathSource).optional()
|
|
inputs.file(existingPublicPathSnapshot).optional()
|
|
inputs.property('updateApprovalRequested', publicPathUpdateApproved)
|
|
|
|
doLast {
|
|
if (publicPathUpdateApproved) {
|
|
throw new GradleException(
|
|
'verifyPublicPathSnapshot is read-only; use updatePublicPathSnapshot ' +
|
|
'-PapprovePublicPathChange for an intentional update.')
|
|
}
|
|
String canonical
|
|
try {
|
|
canonical = renderPublicPathSnapshot(publicPathSourceFile)
|
|
} catch (GradleException exception) {
|
|
throw new GradleException(
|
|
"verifyPublicPathSnapshot: ${exception.message}", exception)
|
|
}
|
|
if (!publicPathSnapshotFile.isFile()) {
|
|
throw new GradleException(
|
|
"verifyPublicPathSnapshot: missing committed baseline ${publicPathSnapshotFile}")
|
|
}
|
|
|
|
String existing = publicPathSnapshotFile.getText('UTF-8')
|
|
if (existing != canonical) {
|
|
throw new GradleException(
|
|
"verifyPublicPathSnapshot: the deny-by-default public path surface changed.\n" +
|
|
" expected (snapshot):\n${existing}\n" +
|
|
" actual (security.yml public-paths default):\n${canonical}\n" +
|
|
'A protected endpoint may now be public. Review the change, then run:\n' +
|
|
' ./gradlew updatePublicPathSnapshot -PapprovePublicPathChange')
|
|
}
|
|
logger.lifecycle(
|
|
'verifyPublicPathSnapshot: OK — committed public paths are unchanged.')
|
|
}
|
|
}
|
|
|
|
tasks.register('updatePublicPathSnapshot') {
|
|
group = 'build setup'
|
|
description = 'Explicitly updates the committed public path baseline after security review.'
|
|
inputs.file(existingPublicPathSource).optional()
|
|
inputs.property('approved', publicPathUpdateApproved)
|
|
outputs.file(publicPathSnapshotFile)
|
|
outputs.upToDateWhen { false }
|
|
|
|
doLast {
|
|
if (!publicPathUpdateApproved) {
|
|
throw new GradleException(
|
|
'updatePublicPathSnapshot requires -PapprovePublicPathChange')
|
|
}
|
|
String canonical
|
|
try {
|
|
canonical = renderPublicPathSnapshot(publicPathSourceFile)
|
|
} catch (GradleException exception) {
|
|
throw new GradleException(
|
|
"updatePublicPathSnapshot: ${exception.message}", exception)
|
|
}
|
|
if (!publicPathSnapshotFile.parentFile.isDirectory()
|
|
&& !publicPathSnapshotFile.parentFile.mkdirs()) {
|
|
throw new GradleException(
|
|
"updatePublicPathSnapshot: failed to create ${publicPathSnapshotFile.parentFile}")
|
|
}
|
|
publicPathSnapshotFile.setText(canonical, 'UTF-8')
|
|
logger.lifecycle(
|
|
"updatePublicPathSnapshot: wrote reviewed baseline ${publicPathSnapshotFile}")
|
|
}
|
|
}
|