From aebb9c172112ef18cd889221a1f29df61030848e Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Fri, 2 Oct 2026 09:29:33 +0200 Subject: [PATCH] test(domain): malware is reported infected even when the file is not a PDF (refs #192) clamd matches EICAR only at the start of a file, so a %PDF- check ahead of the scan made the infected path unreachable for the EICAR test file. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../domain/Big.Tests/ProvideDocumentsTests.cs | 22 +++++++++++++++---- 1 file changed, 18 insertions(+), 4 deletions(-) diff --git a/services/domain/Big.Tests/ProvideDocumentsTests.cs b/services/domain/Big.Tests/ProvideDocumentsTests.cs index 3d2fd21..700854f 100644 --- a/services/domain/Big.Tests/ProvideDocumentsTests.cs +++ b/services/domain/Big.Tests/ProvideDocumentsTests.cs @@ -113,24 +113,38 @@ public class ProvideDocumentsTests } [Fact] - public async Task A_file_that_is_not_a_pdf_is_refused_without_being_scanned() + public async Task A_clean_file_that_is_not_a_pdf_is_refused() { var store = new FakeRegistrationStore(); var registration = Submitted(); store.Seed(registration); var workflow = new FakeWorkflowClient(); var acl = new FakeAclClient(); - var scanner = new FakeDocumentScanner(); - var handler = new ProvideDocuments(store, workflow, acl, scanner); + var handler = new ProvideDocuments(store, workflow, acl, new FakeDocumentScanner()); var outcome = await handler.HandleAsync(Command(registration.Id, content: "MZ not a pdf"u8.ToArray())); Assert.Equal(ProvideDocumentsOutcome.NotAPdf, outcome); - Assert.Null(scanner.Scanned); Assert.Null(acl.StoredDiploma); Assert.Null(workflow.CompletedDocumentWaitFor); } + [Fact] + public async Task Malware_is_reported_as_infected_even_when_it_is_not_a_pdf() + { + // Scan first: clamd matches EICAR (and much real malware) only at the start of a file, so a file + // that fails the PDF check must still be scanned, and the citizen told it is infected. + var store = new FakeRegistrationStore(); + var registration = Submitted(); + store.Seed(registration); + var handler = new ProvideDocuments(store, new FakeWorkflowClient(), new FakeAclClient(), + new FakeDocumentScanner(ScanVerdict.Infected)); + + var outcome = await handler.HandleAsync(Command(registration.Id, content: "X5O!P not a pdf"u8.ToArray())); + + Assert.Equal(ProvideDocumentsOutcome.Infected, outcome); + } + [Fact] public async Task A_clean_pdf_is_scanned_before_it_is_stored() {