feat(server): activate projected authentication safely
This commit is contained in:
@@ -175,6 +175,23 @@ func TestCreateReferencesAuthFilesByDefaultAndArchivesThemOnlyWithSecretCustody(
|
||||
}
|
||||
prepareBackupFixturePrivatePaths(t, []string{authDirectory}, []string{authPath, usersPath})
|
||||
fixture.installation.Authentication.ConfigDirectory = authDirectory
|
||||
runtimeRoot := filepath.Join(filepath.Dir(fixture.installation.Path), "auth-runtime")
|
||||
if err := os.Mkdir(runtimeRoot, 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
runtimeSentinel := []byte("runtime-projection-must-not-be-archived")
|
||||
runtimeFiles := []string{
|
||||
filepath.Join(runtimeRoot, "CURRENT"), filepath.Join(runtimeRoot, "manifest.json"),
|
||||
filepath.Join(runtimeRoot, ".stage-test"), filepath.Join(runtimeRoot, ".current-test.tmp"),
|
||||
filepath.Join(runtimeRoot, ".auth-transaction.lock"), filepath.Join(runtimeRoot, ".auth.lock"),
|
||||
}
|
||||
for _, path := range runtimeFiles {
|
||||
if err := os.WriteFile(path, runtimeSentinel, 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
prepareBackupFixturePrivatePaths(t, []string{runtimeRoot}, runtimeFiles)
|
||||
fixture.installation.Authentication.RuntimeProjection = &config.RuntimeProjection{Directory: runtimeRoot, UID: 10001, GID: 10001}
|
||||
|
||||
defaultOutput := filepath.Join(t.TempDir(), "default.zip")
|
||||
defaultResult, err := createWithDependencies(context.Background(), fixture.installation, CreateRequest{Output: defaultOutput}, testDependencies(t, newBackupRunner(fixture.installation, false)))
|
||||
@@ -204,6 +221,16 @@ func TestCreateReferencesAuthFilesByDefaultAndArchivesThemOnlyWithSecretCustody(
|
||||
t.Fatalf("secret backup warning = %q, want custody guidance", secretResult.Warning)
|
||||
}
|
||||
secretArchive := readFixtureArchive(t, secretOutput)
|
||||
for path, contents := range secretArchive.files {
|
||||
if bytes.Contains(contents, runtimeSentinel) {
|
||||
t.Fatalf("backup payload includes runtime projection data at %q", path)
|
||||
}
|
||||
}
|
||||
for _, entry := range secretArchive.manifest.Entries {
|
||||
if strings.HasPrefix(entry.SourcePath, runtimeRoot+string(filepath.Separator)) || strings.Contains(entry.Path, "auth-runtime") {
|
||||
t.Fatalf("backup manifest references runtime projection entry %#v", entry)
|
||||
}
|
||||
}
|
||||
for _, path := range []string{authPath, usersPath} {
|
||||
if !manifestHasArchivedSecret(secretArchive.manifest, path) {
|
||||
t.Fatalf("secret backup did not archive authentication file %q", path)
|
||||
|
||||
Reference in New Issue
Block a user