feat(auth): centralize ThothII permission enforcement

This commit is contained in:
2026-08-16 17:52:03 +02:00
parent 23ac75ce1d
commit 2e0489ce22
20 changed files with 330 additions and 93 deletions
+23
View File
@@ -5,6 +5,13 @@ import { join } from "node:path";
import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
const userHeaders = {
"x-thoth-principal-issuer": "portal",
"x-thoth-principal-subject": "alice",
"x-thoth-is-admin": "0",
};
const adminHeaders = { ...userHeaders, "x-thoth-principal-subject": "admin", "x-thoth-is-admin": "1" };
function appWithTmpSettings(extraEnv: Record<string, string> = {}, deps = {}) {
const dir = mkdtempSync(join(tmpdir(), "tht-set-route-"));
const app = buildApp(
@@ -62,6 +69,22 @@ test("PUT /settings does not persist personal workspace or LLM choices", async (
}
});
test("PUT /settings requires settings.manage", async () => {
const { app, dir } = appWithTmpSettings({ AUTH_MODE: "upstream" }, { listModels: async () => [] });
try {
const body = { workspace: "psd", provider: "zai", model: "glm-5.2", thinking: "high" };
const denied = await app.inject({ method: "PUT", url: "/settings", headers: userHeaders, payload: body });
const allowed = await app.inject({ method: "PUT", url: "/settings", headers: adminHeaders, payload: body });
expect(denied.statusCode).toBe(403);
expect(denied.json()).toEqual({ code: "auth_forbidden", error: "This operation is not permitted" });
expect(allowed.statusCode).toBe(200);
} finally {
await app.close();
rmSync(dir, { recursive: true, force: true });
}
});
test("settings no longer read or write principal-specific preferences", async () => {
const preferences = new Map<string, any>();
const runner = {