#!/bin/bash # WAVE 74 AGENT 3: Authentication Validation Script # # This script validates that authentication is properly enabled in trading_service # by examining the source code and configuration. set -e echo "==================================================" echo "WAVE 74 AGENT 3: Authentication Validation" echo "==================================================" echo "" # Colors for output GREEN='\033[0;32m' RED='\033[0;31m' YELLOW='\033[1;33m' NC='\033[0m' # No Color MAIN_RS="services/trading_service/src/main.rs" AUTH_RS="services/trading_service/src/auth_interceptor.rs" echo "1. Checking authentication interceptor initialization..." if grep -q "TonicAuthInterceptor::new(auth_config)" "$MAIN_RS"; then echo -e "${GREEN}✅ Authentication interceptor initialized${NC}" else echo -e "${RED}❌ Authentication interceptor NOT initialized${NC}" exit 1 fi echo "" echo "2. Checking TradingService authentication..." if grep -A 3 "TradingServiceServer::with_interceptor" "$MAIN_RS" | grep -q "auth_interceptor.clone()"; then echo -e "${GREEN}✅ TradingService protected with authentication${NC}" else echo -e "${RED}❌ TradingService NOT protected${NC}" exit 1 fi echo "" echo "3. Checking RiskService authentication..." if grep -A 3 "RiskServiceServer::with_interceptor" "$MAIN_RS" | grep -q "auth_interceptor.clone()"; then echo -e "${GREEN}✅ RiskService protected with authentication${NC}" else echo -e "${RED}❌ RiskService NOT protected${NC}" exit 1 fi echo "" echo "4. Checking MLService authentication..." if grep -A 3 "MlServiceServer::with_interceptor" "$MAIN_RS" | grep -q "auth_interceptor.clone()"; then echo -e "${GREEN}✅ MLService protected with authentication${NC}" else echo -e "${RED}❌ MLService NOT protected${NC}" exit 1 fi echo "" echo "5. Checking MonitoringService authentication..." if grep -A 3 "MonitoringServiceServer::with_interceptor" "$MAIN_RS" | grep -q "auth_interceptor.clone()"; then echo -e "${GREEN}✅ MonitoringService protected with authentication${NC}" else echo -e "${RED}❌ MonitoringService NOT protected${NC}" exit 1 fi echo "" echo "6. Checking JWT revocation support..." if grep -q "is_revoked" "$AUTH_RS"; then echo -e "${GREEN}✅ JWT revocation checking enabled${NC}" else echo -e "${YELLOW}⚠️ JWT revocation not found (may be optional)${NC}" fi echo "" echo "7. Checking rate limiting..." if grep -q "is_rate_limited" "$AUTH_RS"; then echo -e "${GREEN}✅ Rate limiting enabled${NC}" else echo -e "${RED}❌ Rate limiting NOT enabled${NC}" exit 1 fi echo "" echo "8. Checking audit logging..." if grep -q "log_auth_success" "$AUTH_RS" && grep -q "log_auth_failure" "$AUTH_RS"; then echo -e "${GREEN}✅ Audit logging enabled${NC}" else echo -e "${RED}❌ Audit logging NOT enabled${NC}" exit 1 fi echo "" echo "9. Checking JWT secret validation..." if grep -q "validate_jwt_secret" "$AUTH_RS"; then echo -e "${GREEN}✅ JWT secret strength validation enabled${NC}" else echo -e "${YELLOW}⚠️ JWT secret validation not found${NC}" fi echo "" echo "10. Checking for insecure Default implementation..." # Look for panic!() in Default implementation (safe) or actual default values (unsafe) if grep -A 5 "impl Default for AuthConfig" "$AUTH_RS" | grep -q "panic!"; then echo -e "${GREEN}✅ Default implementation safely panics (Wave 69 fix applied)${NC}" elif grep -q "impl Default for AuthConfig" "$AUTH_RS"; then echo -e "${RED}❌ CRITICAL: Active Default implementation found${NC}" exit 1 else echo -e "${GREEN}✅ No Default implementation found${NC}" fi echo "" echo "11. Checking compilation status..." if cargo check -p trading_service 2>&1 | grep -q "error:"; then echo -e "${RED}❌ Compilation errors found${NC}" cargo check -p trading_service 2>&1 | grep "error:" exit 1 else echo -e "${GREEN}✅ trading_service compiles successfully${NC}" fi echo "" echo "==================================================" echo -e "${GREEN}✅ ALL AUTHENTICATION CHECKS PASSED${NC}" echo "==================================================" echo "" echo "Summary:" echo " - Authentication interceptor: ENABLED" echo " - All 4 gRPC services: PROTECTED" echo " - JWT revocation: SUPPORTED" echo " - Rate limiting: ENABLED" echo " - Audit logging: ENABLED" echo " - Security hardening: APPLIED" echo " - Compilation: SUCCESS" echo "" echo "Authentication is properly enabled and configured." echo ""