"""Threat/suspicious-pattern scanner tests (Chapter 07/12).""" from __future__ import annotations from datetime import datetime from app.services import threat_scanner from app.services.log_parser import ParsedEntry def _entry(path="/", user_agent="Mozilla/5.0"): return ParsedEntry( timestamp=datetime(2026, 7, 1), ip="203.0.113.1", method="GET", path=path, status_code=200, bytes_sent=100, referrer=None, user_agent=user_agent, ) def test_scan_detects_sensitive_path(): match = threat_scanner.scan(_entry(path="/.env")) assert match is not None assert match.rule_matched.startswith("sensitive_path:") def test_scan_detects_injection_marker(): match = threat_scanner.scan(_entry(path="/search?q=' OR '1'='1")) assert match is not None assert match.rule_matched.startswith("injection:") def test_scan_detects_scanner_user_agent(): match = threat_scanner.scan(_entry(path="/", user_agent="sqlmap/1.7")) assert match is not None assert match.rule_matched.startswith("scanner_ua:") def test_scan_returns_none_for_benign_request(): assert threat_scanner.scan(_entry(path="/about")) is None