feat(server): activate projected authentication safely

This commit is contained in:
User
2026-08-22 01:01:36 +02:00
parent 903c0b4de5
commit 3d9a9f0675
32 changed files with 1837 additions and 38 deletions
+27
View File
@@ -175,6 +175,23 @@ func TestCreateReferencesAuthFilesByDefaultAndArchivesThemOnlyWithSecretCustody(
}
prepareBackupFixturePrivatePaths(t, []string{authDirectory}, []string{authPath, usersPath})
fixture.installation.Authentication.ConfigDirectory = authDirectory
runtimeRoot := filepath.Join(filepath.Dir(fixture.installation.Path), "auth-runtime")
if err := os.Mkdir(runtimeRoot, 0o700); err != nil {
t.Fatal(err)
}
runtimeSentinel := []byte("runtime-projection-must-not-be-archived")
runtimeFiles := []string{
filepath.Join(runtimeRoot, "CURRENT"), filepath.Join(runtimeRoot, "manifest.json"),
filepath.Join(runtimeRoot, ".stage-test"), filepath.Join(runtimeRoot, ".current-test.tmp"),
filepath.Join(runtimeRoot, ".auth-transaction.lock"), filepath.Join(runtimeRoot, ".auth.lock"),
}
for _, path := range runtimeFiles {
if err := os.WriteFile(path, runtimeSentinel, 0o600); err != nil {
t.Fatal(err)
}
}
prepareBackupFixturePrivatePaths(t, []string{runtimeRoot}, runtimeFiles)
fixture.installation.Authentication.RuntimeProjection = &config.RuntimeProjection{Directory: runtimeRoot, UID: 10001, GID: 10001}
defaultOutput := filepath.Join(t.TempDir(), "default.zip")
defaultResult, err := createWithDependencies(context.Background(), fixture.installation, CreateRequest{Output: defaultOutput}, testDependencies(t, newBackupRunner(fixture.installation, false)))
@@ -204,6 +221,16 @@ func TestCreateReferencesAuthFilesByDefaultAndArchivesThemOnlyWithSecretCustody(
t.Fatalf("secret backup warning = %q, want custody guidance", secretResult.Warning)
}
secretArchive := readFixtureArchive(t, secretOutput)
for path, contents := range secretArchive.files {
if bytes.Contains(contents, runtimeSentinel) {
t.Fatalf("backup payload includes runtime projection data at %q", path)
}
}
for _, entry := range secretArchive.manifest.Entries {
if strings.HasPrefix(entry.SourcePath, runtimeRoot+string(filepath.Separator)) || strings.Contains(entry.Path, "auth-runtime") {
t.Fatalf("backup manifest references runtime projection entry %#v", entry)
}
}
for _, path := range []string{authPath, usersPath} {
if !manifestHasArchivedSecret(secretArchive.manifest, path) {
t.Fatalf("secret backup did not archive authentication file %q", path)