test(domain): malware is reported infected even when the file is not a PDF (refs #192)

clamd matches EICAR only at the start of a file, so a %PDF- check ahead of the
scan made the infected path unreachable for the EICAR test file.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-10-02 09:53:23 +02:00
co-authored by Claude Opus 5.5
parent 38026879c7
commit c245182c87
@@ -113,24 +113,38 @@ public class ProvideDocumentsTests
}
[Fact]
public async Task A_file_that_is_not_a_pdf_is_refused_without_being_scanned()
public async Task A_clean_file_that_is_not_a_pdf_is_refused()
{
var store = new FakeRegistrationStore();
var registration = Submitted();
store.Seed(registration);
var workflow = new FakeWorkflowClient();
var acl = new FakeAclClient();
var scanner = new FakeDocumentScanner();
var handler = new ProvideDocuments(store, workflow, acl, scanner);
var handler = new ProvideDocuments(store, workflow, acl, new FakeDocumentScanner());
var outcome = await handler.HandleAsync(Command(registration.Id, content: "MZ not a pdf"u8.ToArray()));
Assert.Equal(ProvideDocumentsOutcome.NotAPdf, outcome);
Assert.Null(scanner.Scanned);
Assert.Null(acl.StoredDiploma);
Assert.Null(workflow.CompletedDocumentWaitFor);
}
[Fact]
public async Task Malware_is_reported_as_infected_even_when_it_is_not_a_pdf()
{
// Scan first: clamd matches EICAR (and much real malware) only at the start of a file, so a file
// that fails the PDF check must still be scanned, and the citizen told it is infected.
var store = new FakeRegistrationStore();
var registration = Submitted();
store.Seed(registration);
var handler = new ProvideDocuments(store, new FakeWorkflowClient(), new FakeAclClient(),
new FakeDocumentScanner(ScanVerdict.Infected));
var outcome = await handler.HandleAsync(Command(registration.Id, content: "X5O!P not a pdf"u8.ToArray()));
Assert.Equal(ProvideDocumentsOutcome.Infected, outcome);
}
[Fact]
public async Task A_clean_pdf_is_scanned_before_it_is_stored()
{