test(auth): harden Task 15 OIDC smoke evidence
This commit is contained in:
@@ -25,6 +25,33 @@ test("the loopback fixture exposes signed OIDC discovery, device authorization,
|
||||
});
|
||||
});
|
||||
|
||||
test("the production OIDC client rejects a wrong registration and wrong mounted client secret", async ({ page }) => {
|
||||
await stack.useOidcMode("ordinary", "wrong-client-id");
|
||||
await page.goto(stack.publicUrl);
|
||||
await signInWithOidc(page);
|
||||
await expect(page.locator("body")).toContainText("invalid_request");
|
||||
await expect(page.getByTestId("app-shell")).toHaveCount(0);
|
||||
|
||||
await stack.useOidcMode("ordinary", "wrong-client-secret");
|
||||
await page.goto(stack.publicUrl);
|
||||
await signInWithOidc(page);
|
||||
await expectOidcCallbackDenied(page);
|
||||
});
|
||||
|
||||
test("production diagnostics reject a wrong group token and pass with the correct mounted secrets", async () => {
|
||||
await stack.useOidcMode("ordinary", "wrong-api-token");
|
||||
await expect(stack.authDiagnostics()).resolves.toMatchObject({
|
||||
status: 1,
|
||||
report: { ready: false, checks: [{ code: "oidc_group_catalog_unauthorized" }] },
|
||||
});
|
||||
|
||||
await stack.useOidcMode("ordinary", "correct");
|
||||
await expect(stack.authDiagnostics()).resolves.toMatchObject({
|
||||
status: 0,
|
||||
report: { ready: true, checks: [{ code: "auth_ready" }] },
|
||||
});
|
||||
});
|
||||
|
||||
async function expectShell(page: Page): Promise<void> {
|
||||
await expect(page.getByTestId("app-shell")).toBeVisible({ timeout: 30_000 });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user