From bac4a609b11b33e26566b3ed17cc0ca7e9cdd422 Mon Sep 17 00:00:00 2001 From: oliver Date: Fri, 5 Jun 2026 10:59:32 +0800 Subject: [PATCH] docs(managed-ne): use placeholder IPs in bastion hop examples Replace real site addresses with 1.1.1.1/2.2.2.2 and generic usernames in i18n hints and tests. Co-authored-by: Cursor --- netx_api/ne_session_factory.py | 2 +- tests/test_bastion_hop.py | 22 +++++++++++----------- web/src/i18n/en.ts | 4 ++-- web/src/i18n/zh.ts | 4 ++-- 4 files changed, 16 insertions(+), 16 deletions(-) diff --git a/netx_api/ne_session_factory.py b/netx_api/ne_session_factory.py index dc252c8..03cb683 100644 --- a/netx_api/ne_session_factory.py +++ b/netx_api/ne_session_factory.py @@ -54,7 +54,7 @@ def default_huawei_hop_template(protocol: str, vrf: str = "") -> str: def default_bastion_username_template() -> str: - """SSH bastion composite username (JumpServer/CBH/ZTE-TSM style).""" + """SSH bastion composite username (JumpServer/CBH/generic protocol-proxy style).""" return "{hop_user}@{target_user}@{target_ip}@{hop_host}" diff --git a/tests/test_bastion_hop.py b/tests/test_bastion_hop.py index f931860..51b0312 100644 --- a/tests/test_bastion_hop.py +++ b/tests/test_bastion_hop.py @@ -20,15 +20,15 @@ class BastionTemplateTests(unittest.TestCase): def test_render_bastion_composite_username(self) -> None: creds = { "hop_vendor": "bastion", - "hop_username": "ZTE-TSM", - "hop_host": "10.34.145.27", - "username": "ca-oper", - "ip_address": "114.0.44.11", + "hop_username": "bastion-user", + "hop_host": "1.1.1.1", + "username": "target-user", + "ip_address": "2.2.2.2", "hop_protocol": "ssh", "hop_vrf": "", } out = render_hop_command("", creds) - self.assertEqual(out, "ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27") + self.assertEqual(out, "bastion-user@target-user@2.2.2.2@1.1.1.1") def test_render_custom_bastion_template(self) -> None: creds = { @@ -73,14 +73,14 @@ class BastionConnectImplTests(unittest.TestCase): conn = MagicMock() connect_handler.return_value = conn creds = { - "hop_host": "10.34.145.27", - "hop_username": "ZTE-TSM", + "hop_host": "1.1.1.1", + "hop_username": "bastion-user", "hop_password": "vault-pass", "hop_port": 22, "device_type": "zte_zxros", "protocol": "ssh", - "username": "ca-oper", - "ip_address": "114.0.44.11", + "username": "target-user", + "ip_address": "2.2.2.2", "password": "", "hop_target_auth_mode": "bastion_managed", "hop_vendor": "bastion", @@ -89,8 +89,8 @@ class BastionConnectImplTests(unittest.TestCase): } _connect_via_bastion(creds) kwargs = connect_handler.call_args.kwargs - self.assertEqual(kwargs["host"], "10.34.145.27") - self.assertEqual(kwargs["username"], "ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27") + self.assertEqual(kwargs["host"], "1.1.1.1") + self.assertEqual(kwargs["username"], "bastion-user@target-user@2.2.2.2@1.1.1.1") self.assertEqual(kwargs["password"], "vault-pass") conn.disconnect.assert_not_called() diff --git a/web/src/i18n/en.ts b/web/src/i18n/en.ts index c5d04c9..bc48be5 100644 --- a/web/src/i18n/en.ts +++ b/web/src/i18n/en.ts @@ -202,14 +202,14 @@ const en = { ciscoHint: "Run Cisco ssh -vrf / telnet /vrf jump commands; target credentials use secondary auth.", linuxHint: "SSH to the Linux bastion, then direct-tcpip tunnel to target IP:port (ProxyJump-style).", bastionHint: - "SSH with composite username via bastion protocol proxy. Example: user@account@target_ip@bastion_host; password is the bastion/Vault password. JumpServer/CBH often use port 2222.", + "SSH with composite username via bastion protocol proxy. Example: bastion-user@target-user@2.2.2.2@1.1.1.1; password is the bastion/Vault password. JumpServer/CBH often use port 2222.", targetAuthMode: "Target credentials", targetAuthBastionManaged: "Bastion-managed (target password optional)", targetAuthManual: "Manual (secondary auth after connect)", targetAuthHint: "Bastion-managed needs only bastion password; manual mode requires target NE password.", usernameTemplate: "SSH username template", templateHintBastion: - "Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank.", + "Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank. Example: bastion-user@target-user@2.2.2.2@1.1.1.1.", host: "Jump host", port: "Jump port", protocol: "Jump protocol", diff --git a/web/src/i18n/zh.ts b/web/src/i18n/zh.ts index 028db37..a25d477 100644 --- a/web/src/i18n/zh.ts +++ b/web/src/i18n/zh.ts @@ -200,14 +200,14 @@ const zh = { ciscoHint: "在思科设备上执行 ssh -vrf / telnet /vrf 跳登,目标账号由二次认证输入。", linuxHint: "先 SSH 登录 Linux 跳板,经 direct-tcpip 隧道连接目标 IP:端口(等同 ProxyJump)。", bastionHint: - "SSH 复合用户名直连堡垒机,由堡垒机协议代理到目标。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27;密码为 Vault/堡垒机密码。JumpServer/CBH 常用端口 2222。", + "SSH 复合用户名直连堡垒机,由堡垒机协议代理到目标。示例:bastion-user@target-user@2.2.2.2@1.1.1.1;密码为 Vault/堡垒机密码。JumpServer/CBH 常用端口 2222。", targetAuthMode: "目标凭据", targetAuthBastionManaged: "堡垒机托管(目标密码可留空)", targetAuthManual: "手动输入(连接后二次认证)", targetAuthHint: "堡垒机托管时仅需堡垒机密码;手动模式需填写目标网元密码。", usernameTemplate: "SSH 用户名模板", templateHintBastion: - "默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27。", + "默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:bastion-user@target-user@2.2.2.2@1.1.1.1。", host: "跳板地址", port: "跳板端口", protocol: "跳板协议",