feat(server): activate projected authentication safely
This commit is contained in:
@@ -20,6 +20,7 @@ import { stringify } from "yaml";
|
||||
import { afterEach, expect, test, vi } from "vitest";
|
||||
import { createProjectedAuthenticationConfigProvider } from "../src/auth/runtime-projection.js";
|
||||
import { createCurrentLocalUserRegistryResolver } from "../src/auth/local-registry.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
|
||||
const fsHook = vi.hoisted(() => ({
|
||||
path: undefined as string | undefined,
|
||||
@@ -308,6 +309,35 @@ test("loads a complete OIDC projection without a users snapshot", () => {
|
||||
});
|
||||
});
|
||||
|
||||
test("loadConfig selects an immutable projected local provider and its in-memory registry", async () => {
|
||||
const root = projectionRoot();
|
||||
writeReadyProjection(root, localProjectionFixture("projected-user", passwordHash));
|
||||
|
||||
const config = loadConfig({
|
||||
THT_AUTH_RUNTIME_PROJECTION_ROOT: root,
|
||||
THT_AUTH_STATE_ROOT: "/state/auth",
|
||||
});
|
||||
const loaded = config.authentication?.current();
|
||||
expect(loaded).toMatchObject({ value: { mode: "local" }, runtimeProjection: expect.any(Object) });
|
||||
const registry = createCurrentLocalUserRegistryResolver().resolve(loaded!);
|
||||
expect(await registry?.findByUsername("PROJECTED-USER")).toMatchObject({ username: "projected-user" });
|
||||
});
|
||||
|
||||
test("loadConfig selects an immutable projected OIDC provider without direct-file fallback", () => {
|
||||
const root = projectionRoot();
|
||||
writeReadyOidcProjection(root);
|
||||
|
||||
const config = loadConfig({
|
||||
THT_AUTH_RUNTIME_PROJECTION_ROOT: root,
|
||||
THT_AUTH_CONFIG_FILE: "/run/thothii-auth/auth.yaml",
|
||||
THT_AUTH_STATE_ROOT: "/state/auth",
|
||||
});
|
||||
expect(config.authentication?.current()).toMatchObject({
|
||||
value: { mode: "oidc" },
|
||||
runtimeProjection: expect.any(Object),
|
||||
});
|
||||
});
|
||||
|
||||
test("rejects a trailing-slash runtime root", () => {
|
||||
const root = projectionRoot();
|
||||
writeReadyProjection(
|
||||
|
||||
Reference in New Issue
Block a user