Skip to content

refactor: extract intropage_device_scope() and add a coverage harness - #378

Closed
somethingwithproof wants to merge 1 commit into
Cacti:developfrom
somethingwithproof:refactor/device-scope-helper
Closed

somethingwithproof wants to merge 1 commit into
Cacti:developfrom
somethingwithproof:refactor/device-scope-helper

Conversation

@somethingwithproof

@somethingwithproof somethingwithproof commented Aug 30, 2026 •

Copy link
Copy Markdown
Member

First increment of the panel de-duplication, plus the test infrastructure it needs.

Helper

The device-permission preamble (get_simple_device_perms then, for non-simple users, intropage_get_allowed_devices) is copied ~39 times across the panels. This adds one documented intropage_device_scope($user_id) returning {simple, allowed} and adopts it in the two alert.php panels (an 8-line block becomes 4, behaviour identical). It returns only the uniform parts: the IN() clause is left to the caller because the column and any AND prefix differ between panels (for example alert.php uses AND host.id IN (...)).

Coverage harness

The plugin had no coverage configuration, and its tests/Security/* are source-pattern scans rather than behavioural tests. This adds a phpunit.xml with a coverage source list so coverage is measurable, plus tests/Unit/DeviceScopeTest.php and permission-chain stubs in tests/bootstrap.php. The test drives every branch of the helper (all pass under PHP 8.4).

Note: five tests/Security/* cases already fail on develop (verified by stashing this change); they are pre-existing and untouched here.

This is deliberately one family. The remaining ~37 sites want per-site verification of each IN()-clause variant, done family by family, not a blind sweep.

Closes #384

Extract the repeated get_simple_device_perms + intropage_get_allowed_devices
preamble into one documented helper returning the user's device scope, and adopt
it in alert.php's two panels. Add a phpunit.xml coverage source config and a
behavioural Pest test (with permission-chain stubs) that exercises every branch
of the helper, since the plugin previously had only source-scan tests and no
coverage config.

Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
@somethingwithproof

Copy link
Copy Markdown
Member Author

Folded into #379, which already contains this commit — the two are stacked, not siblings (git merge-base --is-ancestor confirms #379 contains this branch in full).

Reviewing them separately means reviewing the helper twice. #379 carries both commits: adding intropage_device_scope() and adopting it across the busiest panels.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

extract intropage_device_scope() and add a coverage harness

1 participant