Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions tests/cli/__init__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
"""Tests for quickxss.cli module."""
229 changes: 229 additions & 0 deletions tests/cli/test_cli.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,229 @@
"""Unit tests for quickxss.cli module."""

from __future__ import annotations

from importlib import import_module
from pathlib import Path

import pytest
from typer.testing import CliRunner

from quickxss.models.scan import ScanResult
from quickxss.models.setup import SetupReport
from quickxss.scan.errors import DependencyError, ToolError, ValidationError

app_module = import_module("quickxss.cli.app")
scan_module = import_module("quickxss.cli.scan")
setup_cli_module = import_module("quickxss.cli.setup")
setup_runner = import_module("quickxss.setup.runner")


@pytest.fixture
def cli_runner():
"""Create a CLI runner."""
return CliRunner()


def test_cli_requires_domain(cli_runner) -> None:
"""Scan without domain should fail."""
result = cli_runner.invoke(app_module.app, ["scan"])
assert result.exit_code != 0


def test_cli_success(monkeypatch, cli_runner) -> None:
"""Successful scan should show summary."""

def fake_run_scan(config, logger):
return ScanResult(
total_urls=1,
candidate_urls=1,
findings=0,
results_file=Path("/tmp/results.txt"),
)

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(app_module.app, ["scan", "-d", "example.com"])
assert result.exit_code == 0
assert "Summary" in result.stdout


def test_cli_displays_banner(monkeypatch, cli_runner) -> None:
"""Scan should display banner unless quiet."""

def fake_run_scan(config, logger):
return ScanResult(
total_urls=1,
candidate_urls=1,
findings=0,
results_file=Path("/tmp/results.txt"),
)

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(app_module.app, ["scan", "-d", "example.com"])
assert result.exit_code == 0
assert "XSS" in result.stdout or "___" in result.stdout


def test_cli_quiet_suppresses_output(monkeypatch, cli_runner) -> None:
"""Scan with --quiet should suppress output."""

def fake_run_scan(config, logger):
return ScanResult(
total_urls=1,
candidate_urls=1,
findings=0,
results_file=Path("/tmp/results.txt"),
)

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(
app_module.app, ["scan", "-d", "example.com", "--quiet"]
)
assert result.exit_code == 0
assert result.stdout == ""


def test_cli_validation_error_exit_code_2(monkeypatch, cli_runner) -> None:
"""Validation error should exit with code 2."""

def fake_run_scan(config, logger):
raise ValidationError("Invalid domain")

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(app_module.app, ["scan", "-d", "example.com"])
assert result.exit_code == 2


def test_cli_dependency_error_exit_code_3(monkeypatch, cli_runner) -> None:
"""Dependency error should exit with code 3."""

def fake_run_scan(config, logger):
raise DependencyError("Missing gf")

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(app_module.app, ["scan", "-d", "example.com"])
assert result.exit_code == 3


def test_cli_tool_error_exit_code_4(monkeypatch, cli_runner) -> None:
"""Tool error should exit with code 4."""

def fake_run_scan(config, logger):
raise ToolError("dalfox failed")

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(app_module.app, ["scan", "-d", "example.com"])
assert result.exit_code == 4


def test_cli_unexpected_error_exit_code_1(monkeypatch, cli_runner) -> None:
"""Unexpected error should exit with code 1."""

def fake_run_scan(config, logger):
raise RuntimeError("Unexpected error")

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(app_module.app, ["scan", "-d", "example.com"])
assert result.exit_code == 1


def test_cli_with_blind_payload(monkeypatch, cli_runner) -> None:
"""Scan with blind payload should pass it to config."""
captured_config = {}

def fake_run_scan(config, logger):
captured_config["blind"] = config.blind_payload
return ScanResult(
total_urls=1,
candidate_urls=1,
findings=0,
results_file=Path("/tmp/results.txt"),
)

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(
app_module.app,
["scan", "-d", "example.com", "-b", "https://callback.com"],
)
assert result.exit_code == 0
assert captured_config["blind"] == "https://callback.com"


def test_cli_with_custom_output(monkeypatch, cli_runner) -> None:
"""Scan with custom output name should use it."""
captured_config = {}

def fake_run_scan(config, logger):
captured_config["output"] = config.output_name
return ScanResult(
total_urls=1,
candidate_urls=1,
findings=0,
results_file=Path("/tmp/results.txt"),
)

monkeypatch.setattr(scan_module, "run_scan", fake_run_scan)
with cli_runner.isolated_filesystem():
result = cli_runner.invoke(
app_module.app,
["scan", "-d", "example.com", "-o", "custom_output.txt"],
)
assert result.exit_code == 0
assert captured_config["output"] == "custom_output.txt"


def test_setup_check_success(monkeypatch, cli_runner, all_tools_ok_report) -> None:
"""Setup check should pass when all requirements met."""
monkeypatch.setattr(setup_runner, "build_report", lambda: all_tools_ok_report)

result = cli_runner.invoke(app_module.app, ["setup"])
assert result.exit_code == 0
assert "ok" in result.stdout.lower()


def test_setup_check_missing_tools(monkeypatch, cli_runner) -> None:
"""Setup check should fail when tools missing."""
report = SetupReport(
tools={"gf": False, "dalfox": True, "waybackurls": True, "gau": True},
gf_pattern=True,
os_name="linux",
install_supported=True,
)
monkeypatch.setattr(setup_runner, "build_report", lambda: report)

result = cli_runner.invoke(app_module.app, ["setup"])
assert result.exit_code == 3
assert "missing" in result.stdout.lower()


def test_setup_displays_os(monkeypatch, cli_runner) -> None:
"""Setup should display detected OS."""
report = SetupReport(
tools={"gf": True, "dalfox": True, "waybackurls": True, "gau": True},
gf_pattern=True,
os_name="darwin",
install_supported=True,
)
monkeypatch.setattr(setup_runner, "build_report", lambda: report)

result = cli_runner.invoke(app_module.app, ["setup"])
assert "darwin" in result.stdout.lower()


def test_setup_quiet_suppresses_output(
monkeypatch, cli_runner, all_tools_ok_report
) -> None:
"""Setup with --quiet should suppress output."""
monkeypatch.setattr(setup_runner, "build_report", lambda: all_tools_ok_report)

result = cli_runner.invoke(app_module.app, ["setup", "--quiet"])
assert result.exit_code == 0
assert result.stdout.strip() == ""
98 changes: 98 additions & 0 deletions tests/conftest.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
"""Pytest configuration and shared fixtures."""

from __future__ import annotations

from pathlib import Path
from types import SimpleNamespace
from unittest.mock import MagicMock

import pytest

from quickxss.models.scan import ScanConfig, ScanResult
from quickxss.models.setup import SetupReport
from quickxss.utils.log import Logger


@pytest.fixture
def quiet_logger() -> Logger:
"""Create a quiet logger for testing."""
return Logger(verbose=False, quiet=True)


@pytest.fixture
def verbose_logger() -> Logger:
"""Create a verbose logger for testing."""
return Logger(verbose=True, quiet=False)


@pytest.fixture
def mock_logger() -> MagicMock:
"""Create a mock logger."""
return MagicMock(spec=Logger)


@pytest.fixture
def sample_scan_config(tmp_path: Path) -> ScanConfig:
"""Create a sample scan configuration."""
return ScanConfig(
domain="example.com",
results_dir=tmp_path,
output_name="results.txt",
overwrite=False,
use_wayback=True,
use_gau=True,
gf_pattern="xss",
blind_payload=None,
dalfox_args=[],
keep_temp=True,
verbose=False,
quiet=False,
)


@pytest.fixture
def sample_scan_result(tmp_path: Path) -> ScanResult:
"""Create a sample scan result."""
return ScanResult(
total_urls=100,
candidate_urls=50,
findings=5,
results_file=tmp_path / "results.txt",
)


@pytest.fixture
def all_tools_ok_report() -> SetupReport:
"""Create a setup report with all tools installed."""
return SetupReport(
tools={"gf": True, "dalfox": True, "waybackurls": True, "gau": True},
gf_pattern=True,
os_name="linux",
install_supported=True,
)


@pytest.fixture
def missing_tools_report() -> SetupReport:
"""Create a setup report with missing tools."""
return SetupReport(
tools={"gf": False, "dalfox": False, "waybackurls": False, "gau": False},
gf_pattern=False,
os_name="linux",
install_supported=True,
)


@pytest.fixture
def gf_home(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> Path:
"""Create a temporary home directory with .gf folder."""
monkeypatch.setenv("HOME", str(tmp_path))
gf_dir = tmp_path / ".gf"
gf_dir.mkdir()
return gf_dir


@pytest.fixture
def fake_subprocess_success() -> SimpleNamespace:
"""Create a fake successful subprocess result."""
return SimpleNamespace(stdout="", stderr="", returncode=0)
1 change: 1 addition & 0 deletions tests/integration/__init__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
"""Integration tests for QuickXSS."""
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
"""Integration tests for QuickXSS."""

from __future__ import annotations

import os
Expand Down
1 change: 1 addition & 0 deletions tests/models/__init__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
"""Tests for quickxss.models module."""
Loading
Loading