From ef5d5325bb9111f70b33436ae59442eb6d9426d2 Mon Sep 17 00:00:00 2001 From: Alejandro Estringana Ruiz Date: Thu, 1 Oct 2026 12:53:36 +0200 Subject: [PATCH 1/3] Unify wordpress --- .../php/integration/WordPressTests.groovy | 12 ++++---- .../src/test/www/wordpress/docker-init.sh | 19 ------------- .../src/test/www/wordpress/public/index.php | 12 -------- .../test/www/wordpress/public/wp-config.php | 28 ------------------- .../WordPress/Version_6_1}/.htaccess | 0 .../Version_6_1}/behind_auth_trigger.php | 0 .../WordPress/Version_6_1/docker-init.sh | 17 +++++++++++ .../WordPress/Version_6_1}/hello.php | 0 .../WordPress/Version_6_1/index.php | 4 ++- .../WordPress/Version_6_1}/login_trigger.php | 0 .../WordPress/Version_6_1}/signup_trigger.php | 0 .../WordPress/Version_6_1/wp-config.php | 4 ++- 12 files changed, 29 insertions(+), 67 deletions(-) delete mode 100755 appsec/tests/integration/src/test/www/wordpress/docker-init.sh delete mode 100644 appsec/tests/integration/src/test/www/wordpress/public/index.php delete mode 100644 appsec/tests/integration/src/test/www/wordpress/public/wp-config.php rename {appsec/tests/integration/src/test/www/wordpress/public => tests/Frameworks/WordPress/Version_6_1}/.htaccess (100%) rename {appsec/tests/integration/src/test/www/wordpress/public => tests/Frameworks/WordPress/Version_6_1}/behind_auth_trigger.php (100%) create mode 100755 tests/Frameworks/WordPress/Version_6_1/docker-init.sh rename {appsec/tests/integration/src/test/www/wordpress/public => tests/Frameworks/WordPress/Version_6_1}/hello.php (100%) rename {appsec/tests/integration/src/test/www/wordpress/public => tests/Frameworks/WordPress/Version_6_1}/login_trigger.php (100%) rename {appsec/tests/integration/src/test/www/wordpress/public => tests/Frameworks/WordPress/Version_6_1}/signup_trigger.php (100%) diff --git a/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy b/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy index 5ab05fc5d7..e53151fda4 100644 --- a/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy +++ b/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy @@ -37,11 +37,11 @@ class WordPressTests { private static MySQLContainer MYSQL = new MySQLContainer( DockerImageName.parse("${System.getProperty('DOCKER_MIRROR') ?: 'docker.io'}/library/mysql:8.0") .asCompatibleSubstituteFor('mysql')) - .withDatabaseName('wordpress') - .withUsername('root') + .withDatabaseName('wp61') + .withUsername('test') .withPassword('test') .withNetwork(network) - .withNetworkAliases('mysql') + .withNetworkAliases('mysql-integration') .waitingFor(Wait.forLogMessage(".*ready for connections.*", 1)) as MySQLContainer @Container @@ -52,7 +52,7 @@ class WordPressTests { baseTag: 'apache2-fpm-php', phpVersion: phpVersion, phpVariant: variant, - www: 'wordpress', + www: '../../../tests/Frameworks/WordPress/Version_6_1', ).withNetwork(network) as AppSecContainer static void main(String[] args) { @@ -63,14 +63,14 @@ class WordPressTests { static void installWordPress() { def mysqlInfo = MYSQL.containerInfo def mysqlIp = mysqlInfo.networkSettings.networks.values().find { - it.aliases?.contains('mysql') + it.aliases?.contains('mysql-integration') }?.ipAddress assert mysqlIp != null : "Could not determine MySQL container IP" log.info("MySQL IP: {}", mysqlIp) def res = CONTAINER.execInContainer('bash', '-c', - "sed -i \"s/'mysql'/'${mysqlIp}'/\" /var/www/public/wp-config.php") + "sed -i \"s/'mysql-integration'/'${mysqlIp}'/\" /var/www/public/wp-config.php") assert res.exitCode == 0 : "Failed to update wp-config.php: ${res.stderr}" // Run wp-cli with tracing and AppSec disabled so these CLI processes diff --git a/appsec/tests/integration/src/test/www/wordpress/docker-init.sh b/appsec/tests/integration/src/test/www/wordpress/docker-init.sh deleted file mode 100755 index 7ba2e9e499..0000000000 --- a/appsec/tests/integration/src/test/www/wordpress/docker-init.sh +++ /dev/null @@ -1,19 +0,0 @@ -#!/bin/bash -ex - -cd /var/www/public - -export DD_TRACE_CLI_ENABLED=false - -# Copy WordPress source from the project mount -cp -a /project/tests/Frameworks/WordPress/Version_6_1/. . -# Restore our custom files (the cp above overwrites them in the overlay upper dir) -cp /test-resources/public/wp-config.php wp-config.php -cp /test-resources/public/index.php index.php -cp /test-resources/public/login_trigger.php login_trigger.php -cp /test-resources/public/hello.php hello.php - -# Download WP-CLI -curl -sf https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar -o /usr/local/bin/wp -chmod +x /usr/local/bin/wp - -chown -R www-data:www-data /var/www/public diff --git a/appsec/tests/integration/src/test/www/wordpress/public/index.php b/appsec/tests/integration/src/test/www/wordpress/public/index.php deleted file mode 100644 index 86ca28d0a7..0000000000 --- a/appsec/tests/integration/src/test/www/wordpress/public/index.php +++ /dev/null @@ -1,12 +0,0 @@ - Date: Thu, 1 Oct 2026 15:46:17 +0200 Subject: [PATCH 2/3] Avoid doing a copy --- .../appsec/php/integration/WordPressTests.groovy | 8 ++++---- .../WordPress/Version_6_1/docker-init.sh | 15 ++++++--------- 2 files changed, 10 insertions(+), 13 deletions(-) diff --git a/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy b/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy index e53151fda4..55169ed5d8 100644 --- a/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy +++ b/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy @@ -70,7 +70,7 @@ class WordPressTests { log.info("MySQL IP: {}", mysqlIp) def res = CONTAINER.execInContainer('bash', '-c', - "sed -i \"s/'mysql-integration'/'${mysqlIp}'/\" /var/www/public/wp-config.php") + "sed -i \"s/'mysql-integration'/'${mysqlIp}'/\" /var/www/wp-config.php") assert res.exitCode == 0 : "Failed to update wp-config.php: ${res.stderr}" // Run wp-cli with tracing and AppSec disabled so these CLI processes @@ -80,7 +80,7 @@ class WordPressTests { res = CONTAINER.execInContainer('bash', '-c', """export DD_TRACE_CLI_ENABLED=false DD_APPSEC_ENABLED=0 wp core install \\ - --path=/var/www/public \\ + --path=/var/www \\ --url=http://localhost \\ --title='Test Site' \\ --admin_user=admin \\ @@ -95,8 +95,8 @@ class WordPressTests { def port = CONTAINER.firstMappedPort res = CONTAINER.execInContainer('bash', '-c', """export DD_TRACE_CLI_ENABLED=false DD_APPSEC_ENABLED=0 - wp option update siteurl 'http://localhost:${port}' --path=/var/www/public --allow-root - wp option update home 'http://localhost:${port}' --path=/var/www/public --allow-root""") + wp option update siteurl 'http://localhost:${port}' --path=/var/www --allow-root + wp option update home 'http://localhost:${port}' --path=/var/www --allow-root""") assert res.exitCode == 0 : "Failed to update WordPress URLs: ${res.stderr}" CONTAINER.clearTraces() diff --git a/tests/Frameworks/WordPress/Version_6_1/docker-init.sh b/tests/Frameworks/WordPress/Version_6_1/docker-init.sh index 0323c67f53..4f5effafa6 100755 --- a/tests/Frameworks/WordPress/Version_6_1/docker-init.sh +++ b/tests/Frameworks/WordPress/Version_6_1/docker-init.sh @@ -1,17 +1,14 @@ #!/bin/bash -ex -cd /var/www - export DD_TRACE_CLI_ENABLED=false -# Apache in the appsec container serves /var/www/public, but the shared -# WordPress tree lays files at /var/www root. Mirror the tree into public/ -# so Apache can find it. OverlayFS avoids duplicating the lower-layer bytes. -mkdir -p /var/www/public -cp -a /test-resources/. /var/www/public/ +# Serve from /var/www directly instead of /var/www/public, since the shared +# WordPress tree is laid at /var/www root (not under a public/ subdir). This +# way edits in the host checkout are reflected immediately through the overlay +# mount, without re-running this init. +sed -i 's!/var/www/public!/var/www!g' /etc/apache2/sites-available/php-site.conf +service apache2 reload 2>/dev/null || service apache2 restart || true # Download WP-CLI for use by WordPressTests.groovy's @BeforeAll install step. curl -sf https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar -o /usr/local/bin/wp chmod +x /usr/local/bin/wp - -chown -R www-data:www-data /var/www/public From 0e34e1f9ee4c4dc07b6f0767159ead0b04a8a1d8 Mon Sep 17 00:00:00 2001 From: Alejandro Estringana Ruiz Date: Thu, 1 Oct 2026 18:04:31 +0200 Subject: [PATCH 3/3] Adapt copy --- .../appsec/php/integration/WordPressTests.groovy | 8 ++++---- .../Frameworks/WordPress/Version_6_1/docker-init.sh | 12 ++++++------ 2 files changed, 10 insertions(+), 10 deletions(-) diff --git a/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy b/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy index 55169ed5d8..e53151fda4 100644 --- a/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy +++ b/appsec/tests/integration/src/test/groovy/com/datadog/appsec/php/integration/WordPressTests.groovy @@ -70,7 +70,7 @@ class WordPressTests { log.info("MySQL IP: {}", mysqlIp) def res = CONTAINER.execInContainer('bash', '-c', - "sed -i \"s/'mysql-integration'/'${mysqlIp}'/\" /var/www/wp-config.php") + "sed -i \"s/'mysql-integration'/'${mysqlIp}'/\" /var/www/public/wp-config.php") assert res.exitCode == 0 : "Failed to update wp-config.php: ${res.stderr}" // Run wp-cli with tracing and AppSec disabled so these CLI processes @@ -80,7 +80,7 @@ class WordPressTests { res = CONTAINER.execInContainer('bash', '-c', """export DD_TRACE_CLI_ENABLED=false DD_APPSEC_ENABLED=0 wp core install \\ - --path=/var/www \\ + --path=/var/www/public \\ --url=http://localhost \\ --title='Test Site' \\ --admin_user=admin \\ @@ -95,8 +95,8 @@ class WordPressTests { def port = CONTAINER.firstMappedPort res = CONTAINER.execInContainer('bash', '-c', """export DD_TRACE_CLI_ENABLED=false DD_APPSEC_ENABLED=0 - wp option update siteurl 'http://localhost:${port}' --path=/var/www --allow-root - wp option update home 'http://localhost:${port}' --path=/var/www --allow-root""") + wp option update siteurl 'http://localhost:${port}' --path=/var/www/public --allow-root + wp option update home 'http://localhost:${port}' --path=/var/www/public --allow-root""") assert res.exitCode == 0 : "Failed to update WordPress URLs: ${res.stderr}" CONTAINER.clearTraces() diff --git a/tests/Frameworks/WordPress/Version_6_1/docker-init.sh b/tests/Frameworks/WordPress/Version_6_1/docker-init.sh index 4f5effafa6..9264c329fa 100755 --- a/tests/Frameworks/WordPress/Version_6_1/docker-init.sh +++ b/tests/Frameworks/WordPress/Version_6_1/docker-init.sh @@ -2,12 +2,12 @@ export DD_TRACE_CLI_ENABLED=false -# Serve from /var/www directly instead of /var/www/public, since the shared -# WordPress tree is laid at /var/www root (not under a public/ subdir). This -# way edits in the host checkout are reflected immediately through the overlay -# mount, without re-running this init. -sed -i 's!/var/www/public!/var/www!g' /etc/apache2/sites-available/php-site.conf -service apache2 reload 2>/dev/null || service apache2 restart || true +# Apache in the appsec container serves /var/www/public, but the shared +# WordPress tree is laid at /var/www root (no public/ subdir). Symlink +# public -> . so Apache finds the files without materializing a second copy; +# this lets edits in the host checkout be reflected immediately through the +# overlay mount. +ln -sfn . /var/www/public # Download WP-CLI for use by WordPressTests.groovy's @BeforeAll install step. curl -sf https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar -o /usr/local/bin/wp