fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 16:39:54 +02:00
parent 3ed00ff086
commit 30ee9433dc
20 changed files with 1034 additions and 57 deletions
+20
View File
@@ -250,6 +250,26 @@ test("aggregates one static and one live authentication report without reorderin
expect(authDiagnoser.inspect).toHaveBeenNthCalledWith(2, { live: true });
});
test("fails closed without reflecting a hostile authentication report", async () => {
const attacker = "attacker-field-SENTINEL";
const authDiagnoser: AuthDiagnoser = { inspect: vi.fn(async () => ({
ready: false,
mode: "oidc",
checks: [{
level: "error", code: "oidc_secret_missing", message: "failure", field: attacker,
}],
} as AuthDiagnostics)) };
const app = appFor(registryFake(), undefined, testSecretStore(), {}, authDiagnoser);
const response = await app.inject({
method: "POST", url: "/workspaces/validate", payload: { workspace },
});
expect(response.statusCode).toBe(400);
expect(response.json()).toEqual({ code: "workspace_invalid", message: "Workspace request is invalid." });
expect(response.body).not.toContain(attacker);
});
test.each([1, 2])("rejects schema v%s at the validation boundary with a sanitized error", async (version) => {
const legacy = {
...workspace,