fix(auth): complete Task 13 deployment review

This commit is contained in:
2026-08-17 22:15:41 +02:00
parent 7e52df2702
commit 0d0c15b4b8
11 changed files with 228 additions and 50 deletions
+9 -24
View File
@@ -8,33 +8,18 @@ import { expandLocalHome, localPrincipal, upstreamPrincipal } from "../src/auth/
import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
test("server smoke trusted claims transform through nginx to a non-admin principal", () => {
test("server smoke rejects retired trusted claims under OIDC authentication", () => {
const smoke = readFileSync("../scripts/unified-deployment-smoke.sh", "utf8");
const nginx = readFileSync("../docker/nginx.conf.template", "utf8");
const helper = smoke.match(/task13_server_auth_headers\(\) \{([\s\S]*?)\n\}/)?.[1] ?? "";
const trusted = Object.fromEntries(
[...helper.matchAll(/-H '([^:']+): ([^']+)'/g)].map((match) => [match[1].toLowerCase(), match[2]]),
);
const normalized: Record<string, string> = {};
for (const [header, suffix] of [
["x-thoth-principal-issuer", "principal_issuer"],
["x-thoth-principal-subject", "principal_subject"],
["x-thoth-principal-display-name", "principal_display_name"],
["x-thoth-is-admin", "is_admin"],
for (const header of [
"x-thoth-trusted-principal-issuer",
"x-thoth-trusted-principal-subject",
"x-thoth-trusted-principal-display-name",
"x-thoth-trusted-is-admin",
]) {
expect(nginx).toContain(`$http_x_thoth_trusted_${suffix}`);
const value = trusted[`x-thoth-trusted-${header.slice("x-thoth-".length)}`];
if (value !== undefined) normalized[header] = value;
expect(smoke).toContain(`-H '${header}:`);
}
expect(upstreamPrincipal(normalized)).toEqual({
issuer: "task13-proxy",
subject: "task13-user",
displayName: "Task 13 User",
roles: ["user"],
permissions: ["session.use"],
isAdmin: false,
});
expect(smoke).toContain('[[ "$trusted_header_status" == 401 ]]');
expect(smoke).toContain("server accepted retired trusted identity headers");
});
test("local mode resolves a stable local principal", async () => {