test(auth): harden Task 15 OIDC smoke evidence

This commit is contained in:
2026-08-18 06:33:48 +02:00
parent 8a3fa5031d
commit 2b618c5a0f
5 changed files with 758 additions and 82 deletions
+27
View File
@@ -25,6 +25,33 @@ test("the loopback fixture exposes signed OIDC discovery, device authorization,
});
});
test("the production OIDC client rejects a wrong registration and wrong mounted client secret", async ({ page }) => {
await stack.useOidcMode("ordinary", "wrong-client-id");
await page.goto(stack.publicUrl);
await signInWithOidc(page);
await expect(page.locator("body")).toContainText("invalid_request");
await expect(page.getByTestId("app-shell")).toHaveCount(0);
await stack.useOidcMode("ordinary", "wrong-client-secret");
await page.goto(stack.publicUrl);
await signInWithOidc(page);
await expectOidcCallbackDenied(page);
});
test("production diagnostics reject a wrong group token and pass with the correct mounted secrets", async () => {
await stack.useOidcMode("ordinary", "wrong-api-token");
await expect(stack.authDiagnostics()).resolves.toMatchObject({
status: 1,
report: { ready: false, checks: [{ code: "oidc_group_catalog_unauthorized" }] },
});
await stack.useOidcMode("ordinary", "correct");
await expect(stack.authDiagnostics()).resolves.toMatchObject({
status: 0,
report: { ready: true, checks: [{ code: "auth_ready" }] },
});
});
async function expectShell(page: Page): Promise<void> {
await expect(page.getByTestId("app-shell")).toBeVisible({ timeout: 30_000 });
}