feat(auth): centralize ThothII permission enforcement
This commit is contained in:
@@ -131,19 +131,24 @@ test("run omits ambient THT_DATA_ROOT when config does not provide one", async (
|
||||
test("principal-bound tht child replaces stale principal env and omits an absent display name", async () => {
|
||||
const saved = Object.fromEntries([
|
||||
"THT_PRINCIPAL_ISSUER", "THT_PRINCIPAL_SUBJECT", "THT_PRINCIPAL_DISPLAY_NAME", "THT_PRINCIPAL_IS_ADMIN",
|
||||
"THT_PRINCIPAL_PERMISSIONS",
|
||||
].map((key) => [key, process.env[key]]));
|
||||
Object.assign(process.env, {
|
||||
THT_PRINCIPAL_ISSUER: "stale-issuer", THT_PRINCIPAL_SUBJECT: "stale-subject",
|
||||
THT_PRINCIPAL_DISPLAY_NAME: "Stale Name", THT_PRINCIPAL_IS_ADMIN: "true",
|
||||
THT_PRINCIPAL_PERMISSIONS: "pi.manage,unknown.permission",
|
||||
});
|
||||
try {
|
||||
(spawn as any).mockClear();
|
||||
const runner = new ThtRunner({ thtBin: "tht", harnessDir: "/h", configPath: "config/tht.yaml" })
|
||||
.withPrincipal({ issuer: "portal", subject: "42", isAdmin: false });
|
||||
.withPrincipal({
|
||||
issuer: "portal", subject: "42", roles: ["user"], permissions: ["session.use"], isAdmin: false,
|
||||
});
|
||||
await runner.run(["session", "list", "--json"]);
|
||||
const env = (spawn as any).mock.calls[0][2].env;
|
||||
expect(env).toMatchObject({
|
||||
THT_PRINCIPAL_ISSUER: "portal", THT_PRINCIPAL_SUBJECT: "42", THT_PRINCIPAL_IS_ADMIN: "false",
|
||||
THT_PRINCIPAL_PERMISSIONS: "session.use",
|
||||
});
|
||||
expect(env).not.toHaveProperty("THT_PRINCIPAL_DISPLAY_NAME");
|
||||
} finally {
|
||||
|
||||
Reference in New Issue
Block a user