fix(auth): complete Task 13 deployment review

This commit is contained in:
2026-08-17 22:15:41 +02:00
parent 7e52df2702
commit 0d0c15b4b8
11 changed files with 228 additions and 50 deletions
+5 -2
View File
@@ -477,7 +477,8 @@ func setMaintenance(ctx context.Context, runner Runner, enabled bool) error {
if enabled {
path = "activate"
}
args := []string{"exec", "-T", "core", "curl", "-fsS", "-X", "POST", "http://127.0.0.1:8787/internal/maintenance/" + path}
args := append([]string{"exec", "-T", "core", "curl", "-fsS"}, internalIdentityHeaders...)
args = append(args, "-X", "POST", "http://127.0.0.1:8787/internal/maintenance/"+path)
result, err := runCompose(ctx, runner, args...)
status, valid := parseMaintenanceStatus(result.Stdout)
if err == nil && valid && status.Active == enabled && status.Admissions == 0 && !status.RecoveryRequired {
@@ -517,7 +518,9 @@ func parseMaintenanceStatus(value string) (MaintenanceState, bool) {
}
func MaintenanceStatus(ctx context.Context, runner Runner) (MaintenanceState, error) {
result, err := runCompose(ctx, runner, "exec", "-T", "core", "curl", "-fsS", "http://127.0.0.1:8787/internal/maintenance/status")
args := append([]string{"exec", "-T", "core", "curl", "-fsS"}, internalIdentityHeaders...)
args = append(args, "http://127.0.0.1:8787/internal/maintenance/status")
result, err := runCompose(ctx, runner, args...)
if err != nil {
return MaintenanceState{}, commandError("maintenance status check", result, err)
}
+33
View File
@@ -779,6 +779,39 @@ func TestUpdateRequiresConfirmationAndDrainsActiveSessions(t *testing.T) {
assertCalled(t, fake.calls, "/internal/maintenance/deactivate")
}
func TestMaintenanceControlUsesExactLoopbackOperatorIdentity(t *testing.T) {
fake := newFakeRunner()
if err := setMaintenance(context.Background(), fake, true); err != nil {
t.Fatal(err)
}
fake.maintenance = true
if _, err := MaintenanceStatus(context.Background(), fake); err != nil {
t.Fatal(err)
}
for _, path := range []string{"/internal/maintenance/activate", "/internal/maintenance/status"} {
found := false
for _, call := range fake.calls {
if !strings.Contains(call, path) {
continue
}
found = true
for _, header := range []string{
"x-thoth-principal-issuer: tht",
"x-thoth-principal-subject: tht-maintenance",
"x-thoth-principal-display-name: Tht maintenance",
"x-thoth-is-admin: 1",
} {
if !strings.Contains(call, header) {
t.Fatalf("maintenance call %q lacks %q", call, header)
}
}
}
if !found {
t.Fatalf("maintenance call %q was not made", path)
}
}
}
func TestRollbackRestoresInterruptedOrPreviouslyRecordedState(t *testing.T) {
fake := newFakeRunner()
statePath := filepath.Join(t.TempDir(), "state.json")