"""Perform the OLT's pinned, read-only SSH authentication check."""
import asyncio
import os

from dotenv import load_dotenv

load_dotenv()

from app.core.database import AsyncSessionLocal
from app.core.ssh_identity import test_pinned_ssh_identity
from app.models.models import DeviceCredential, OLTDevice


async def main() -> None:
    async with AsyncSessionLocal() as db:
        olt = await db.get(OLTDevice, 1)
        if olt is None or olt.credential_id is None:
            raise RuntimeError("assigned OLT credential unavailable")
        credential = await db.get(DeviceCredential, olt.credential_id)
        if credential is None:
            raise RuntimeError("credential unavailable")
        result = await asyncio.to_thread(
            test_pinned_ssh_identity,
            host=olt.host,
            port=olt.api_port,
            username=credential.username,
            encrypted_secret=credential.encrypted_secret,
            expected_host_key_fingerprint=os.getenv("OLT_1_SSH_HOST_KEY_SHA256"),
        )
    print("ssh_identity=" + ("verified" if result.ok else "failed"))
    print("commands_executed=no")


asyncio.run(main())
