fix(auth): complete Task 13 deployment review
This commit is contained in:
@@ -8,33 +8,18 @@ import { expandLocalHome, localPrincipal, upstreamPrincipal } from "../src/auth/
|
||||
import { buildApp } from "../src/app.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
|
||||
test("server smoke trusted claims transform through nginx to a non-admin principal", () => {
|
||||
test("server smoke rejects retired trusted claims under OIDC authentication", () => {
|
||||
const smoke = readFileSync("../scripts/unified-deployment-smoke.sh", "utf8");
|
||||
const nginx = readFileSync("../docker/nginx.conf.template", "utf8");
|
||||
const helper = smoke.match(/task13_server_auth_headers\(\) \{([\s\S]*?)\n\}/)?.[1] ?? "";
|
||||
const trusted = Object.fromEntries(
|
||||
[...helper.matchAll(/-H '([^:']+): ([^']+)'/g)].map((match) => [match[1].toLowerCase(), match[2]]),
|
||||
);
|
||||
const normalized: Record<string, string> = {};
|
||||
for (const [header, suffix] of [
|
||||
["x-thoth-principal-issuer", "principal_issuer"],
|
||||
["x-thoth-principal-subject", "principal_subject"],
|
||||
["x-thoth-principal-display-name", "principal_display_name"],
|
||||
["x-thoth-is-admin", "is_admin"],
|
||||
for (const header of [
|
||||
"x-thoth-trusted-principal-issuer",
|
||||
"x-thoth-trusted-principal-subject",
|
||||
"x-thoth-trusted-principal-display-name",
|
||||
"x-thoth-trusted-is-admin",
|
||||
]) {
|
||||
expect(nginx).toContain(`$http_x_thoth_trusted_${suffix}`);
|
||||
const value = trusted[`x-thoth-trusted-${header.slice("x-thoth-".length)}`];
|
||||
if (value !== undefined) normalized[header] = value;
|
||||
expect(smoke).toContain(`-H '${header}:`);
|
||||
}
|
||||
|
||||
expect(upstreamPrincipal(normalized)).toEqual({
|
||||
issuer: "task13-proxy",
|
||||
subject: "task13-user",
|
||||
displayName: "Task 13 User",
|
||||
roles: ["user"],
|
||||
permissions: ["session.use"],
|
||||
isAdmin: false,
|
||||
});
|
||||
expect(smoke).toContain('[[ "$trusted_header_status" == 401 ]]');
|
||||
expect(smoke).toContain("server accepted retired trusted identity headers");
|
||||
});
|
||||
|
||||
test("local mode resolves a stable local principal", async () => {
|
||||
|
||||
Reference in New Issue
Block a user