feat(auth): add local login and CSRF-protected sessions

This commit is contained in:
2026-08-16 23:23:55 +02:00
parent 8477a69a29
commit 29bfb41363
10 changed files with 1062 additions and 35 deletions
+11 -3
View File
@@ -6,7 +6,7 @@ import { stringify } from "yaml";
import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
test("configured OIDC fails app startup until an OIDC handler is installed", () => {
test("configured OIDC starts with provider-neutral protocol placeholders that fail closed", async () => {
const directory = mkdtempSync(join(tmpdir(), "thothii-app-oidc-mode-"));
const file = join(directory, "auth.yaml");
writeFileSync(file, stringify({
@@ -19,8 +19,16 @@ test("configured OIDC fails app startup until an OIDC handler is installed", ()
authorization: { groupRoles: { "TOT Users": ["user"], "TOT Admin": ["admin"] } },
}), "utf8");
try {
expect(() => buildApp(loadConfig({ THT_AUTH_CONFIG_FILE: file })))
.toThrow("configured authentication mode is not implemented");
const app = buildApp(loadConfig({ THT_AUTH_CONFIG_FILE: file, THT_AUTH_STATE_ROOT: join(directory, "auth-state") }));
try {
expect((await app.inject({ method: "GET", url: "/auth/config" })).json())
.toEqual({ mode: "oidc", localLogin: false, oidcLogin: false });
const placeholder = await app.inject({ method: "GET", url: "/auth/oidc/login" });
expect(placeholder.statusCode).toBe(501);
expect(placeholder.json()).toEqual({ code: "auth_not_implemented", error: "OIDC login is not implemented" });
} finally {
await app.close();
}
} finally {
rmSync(directory, { recursive: true, force: true });
}