fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 16:39:54 +02:00
parent 3ed00ff086
commit 30ee9433dc
20 changed files with 1034 additions and 57 deletions
+23
View File
@@ -136,3 +136,26 @@ test("decodes the shared authentication diagnostics on static validation and liv
authentication,
});
});
test.each([
["ready with error", { ready: true, mode: "oidc", checks: [{ level: "error", code: "oidc_secret_missing", message: "failure" }] }],
["failed with ready", { ready: false, mode: "oidc", checks: [{ level: "info", code: "auth_ready", message: "ready" }] }],
["failed without error", { ready: false, mode: "oidc", checks: [{ level: "info", code: "auth_config_invalid", message: "info" }] }],
["duplicate", { ready: false, mode: "oidc", checks: [
{ level: "error", code: "oidc_secret_missing", message: "one" },
{ level: "error", code: "oidc_secret_missing", message: "two" },
] }],
["attacker field", { ready: false, mode: "oidc", checks: [{ level: "error", code: "oidc_secret_missing", message: "failure", field: "attacker-field-SENTINEL" }] }],
["control", { ready: false, mode: "oidc", checks: [{ level: "error", code: "oidc_mapped_group_missing", message: "failure", field: "bad\u0085field" }] }],
["unexpected property", { ready: false, mode: "oidc", checks: [{ level: "error", code: "oidc_secret_missing", message: "failure", attacker: "field" }] }],
])("rejects hostile authentication diagnostics: %s", async (_name, authentication) => {
server.use(http.post("/api/workspaces/validate", () => HttpResponse.json({
workspace,
contract: {},
activatable: false,
diagnostics: [],
authentication,
})));
await expect(validateWorkspace(workspace)).rejects.toThrow("invalid authentication diagnostics");
});