fix(auth): harden unified diagnostic execution
This commit is contained in:
@@ -250,6 +250,26 @@ test("aggregates one static and one live authentication report without reorderin
|
||||
expect(authDiagnoser.inspect).toHaveBeenNthCalledWith(2, { live: true });
|
||||
});
|
||||
|
||||
test("fails closed without reflecting a hostile authentication report", async () => {
|
||||
const attacker = "attacker-field-SENTINEL";
|
||||
const authDiagnoser: AuthDiagnoser = { inspect: vi.fn(async () => ({
|
||||
ready: false,
|
||||
mode: "oidc",
|
||||
checks: [{
|
||||
level: "error", code: "oidc_secret_missing", message: "failure", field: attacker,
|
||||
}],
|
||||
} as AuthDiagnostics)) };
|
||||
const app = appFor(registryFake(), undefined, testSecretStore(), {}, authDiagnoser);
|
||||
|
||||
const response = await app.inject({
|
||||
method: "POST", url: "/workspaces/validate", payload: { workspace },
|
||||
});
|
||||
|
||||
expect(response.statusCode).toBe(400);
|
||||
expect(response.json()).toEqual({ code: "workspace_invalid", message: "Workspace request is invalid." });
|
||||
expect(response.body).not.toContain(attacker);
|
||||
});
|
||||
|
||||
test.each([1, 2])("rejects schema v%s at the validation boundary with a sanitized error", async (version) => {
|
||||
const legacy = {
|
||||
...workspace,
|
||||
|
||||
Reference in New Issue
Block a user