fix(auth): reject ill-formed local passwords
This commit is contained in:
@@ -2,7 +2,6 @@ import {
|
||||
chmodSync,
|
||||
existsSync,
|
||||
lstatSync,
|
||||
mkdirSync,
|
||||
renameSync,
|
||||
realpathSync,
|
||||
symlinkSync,
|
||||
@@ -128,6 +127,10 @@ describe("local user registry", () => {
|
||||
["duplicate normalized usernames", registryYaml(userYaml() + userYaml({ id: userId, username: "admin" }))],
|
||||
["duplicate IDs", registryYaml(userYaml() + userYaml({ username: "operator" }))],
|
||||
["unknown YAML fields", `${registryYaml(userYaml())}unexpected: true\n`],
|
||||
["no enabled admin", registryYaml(userYaml({ role: "user" }))],
|
||||
["duplicate roles", registryYaml(userYaml().replace(" - admin", " - admin\n - admin"))],
|
||||
["invalid password hash", registryYaml(userYaml().replace(passwordHash, "not-a-password-hash"))],
|
||||
["control character in display name", registryYaml(userYaml().replace("displayName: Admin", 'displayName: "Admin\\tUser"'))],
|
||||
])("rejects %s", async (_name, contents) => {
|
||||
const fixture = writeRegistry(contents);
|
||||
await expectInvalid(createLocalUserRegistry(fixture.path).findByUsername("admin"), ["admin", passwordHash, fixture.path]);
|
||||
|
||||
Reference in New Issue
Block a user