feat(auth): centralize ThothII permission enforcement
This commit is contained in:
@@ -5,6 +5,13 @@ import { join } from "node:path";
|
||||
import { buildApp } from "../src/app.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
|
||||
const userHeaders = {
|
||||
"x-thoth-principal-issuer": "portal",
|
||||
"x-thoth-principal-subject": "alice",
|
||||
"x-thoth-is-admin": "0",
|
||||
};
|
||||
const adminHeaders = { ...userHeaders, "x-thoth-principal-subject": "admin", "x-thoth-is-admin": "1" };
|
||||
|
||||
function appWithTmpSettings(extraEnv: Record<string, string> = {}, deps = {}) {
|
||||
const dir = mkdtempSync(join(tmpdir(), "tht-set-route-"));
|
||||
const app = buildApp(
|
||||
@@ -62,6 +69,22 @@ test("PUT /settings does not persist personal workspace or LLM choices", async (
|
||||
}
|
||||
});
|
||||
|
||||
test("PUT /settings requires settings.manage", async () => {
|
||||
const { app, dir } = appWithTmpSettings({ AUTH_MODE: "upstream" }, { listModels: async () => [] });
|
||||
try {
|
||||
const body = { workspace: "psd", provider: "zai", model: "glm-5.2", thinking: "high" };
|
||||
const denied = await app.inject({ method: "PUT", url: "/settings", headers: userHeaders, payload: body });
|
||||
const allowed = await app.inject({ method: "PUT", url: "/settings", headers: adminHeaders, payload: body });
|
||||
|
||||
expect(denied.statusCode).toBe(403);
|
||||
expect(denied.json()).toEqual({ code: "auth_forbidden", error: "This operation is not permitted" });
|
||||
expect(allowed.statusCode).toBe(200);
|
||||
} finally {
|
||||
await app.close();
|
||||
rmSync(dir, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("settings no longer read or write principal-specific preferences", async () => {
|
||||
const preferences = new Map<string, any>();
|
||||
const runner = {
|
||||
|
||||
Reference in New Issue
Block a user