feat(server): activate projected authentication safely
This commit is contained in:
@@ -117,6 +117,31 @@ test("loadConfig makes an existing auth.yaml authoritative and rejects AUTH_MODE
|
||||
}
|
||||
});
|
||||
|
||||
test.each([
|
||||
["relative root", { THT_AUTH_RUNTIME_PROJECTION_ROOT: "relative" }],
|
||||
["conflicting direct file", {
|
||||
THT_AUTH_RUNTIME_PROJECTION_ROOT: "/run/thothii-auth",
|
||||
THT_AUTH_CONFIG_FILE: "/different/auth.yaml",
|
||||
}],
|
||||
])("rejects projected authentication configuration: %s", (_name, env) => {
|
||||
expect(() => loadConfig(env)).toThrow("authentication configuration is invalid");
|
||||
});
|
||||
|
||||
test("keeps the direct auth-file provider when the runtime projection environment is absent", () => {
|
||||
const { directory, file } = authFile(oidcAuthConfig());
|
||||
try {
|
||||
const loaded = loadConfig({ THT_AUTH_CONFIG_FILE: file, THT_AUTH_STATE_ROOT: "/state/auth" });
|
||||
const current = loaded.authentication?.current();
|
||||
expect(current).toMatchObject({
|
||||
sourcePath: file,
|
||||
value: { mode: "oidc" },
|
||||
});
|
||||
expect(current?.runtimeProjection).toBeUndefined();
|
||||
} finally {
|
||||
rmSync(directory, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("loadConfig rejects an auth config path that exists but is not a regular file", () => {
|
||||
const directory = mkdtempSync(join(realpathSync(tmpdir()), "thothii-app-auth-config-directory-"));
|
||||
try {
|
||||
|
||||
Reference in New Issue
Block a user