fix(auth): harden unified diagnostic execution
This commit is contained in:
@@ -250,6 +250,29 @@ test("renders one authentication section with configured-group errors and no unm
|
||||
expect(within(section).queryByText(/unmapped/i)).not.toBeInTheDocument();
|
||||
});
|
||||
|
||||
test("never renders a hostile authentication field rejected by the API decoder", async () => {
|
||||
const user = userEvent.setup();
|
||||
const attacker = "attacker-field-SENTINEL";
|
||||
server.use(http.post("/api/workspaces/validate", () => HttpResponse.json({
|
||||
workspace,
|
||||
contract: {},
|
||||
activatable: false,
|
||||
diagnostics: [],
|
||||
authentication: {
|
||||
ready: false,
|
||||
mode: "oidc",
|
||||
checks: [{ level: "error", code: "oidc_secret_missing", message: "failure", field: attacker }],
|
||||
},
|
||||
})));
|
||||
renderManager();
|
||||
await user.click(await screen.findByRole("button", { name: "PSD Clinical" }));
|
||||
|
||||
await user.click(screen.getByRole("button", { name: "Validate workspace source" }));
|
||||
|
||||
expect(await screen.findByRole("alert")).toBeVisible();
|
||||
expect(screen.queryByText(new RegExp(attacker))).not.toBeInTheDocument();
|
||||
});
|
||||
|
||||
test("renders binding_ok as a green connection success", async () => {
|
||||
const user = userEvent.setup();
|
||||
server.use(
|
||||
|
||||
Reference in New Issue
Block a user