feat(server): activate projected authentication safely

This commit is contained in:
User
2026-08-22 01:01:36 +02:00
parent 903c0b4de5
commit 3d9a9f0675
32 changed files with 1837 additions and 38 deletions
+50
View File
@@ -27,6 +27,56 @@ func TestRunReportsUnavailableDockerWithoutReturningAnExecutionError(t *testing.
}
}
func TestRunReportsOneSanitizedRuntimeAuthProjectionFailureBeforeCompose(t *testing.T) {
installation := doctorInstallation(t, "")
installation.Profile = "server"
installation.Authentication.RuntimeProjection = &config.RuntimeProjection{
Directory: "/runtime-auth", UID: 10001, GID: 10001,
}
previous := requireRuntimeAuthProjectionReady
requireRuntimeAuthProjectionReady = func(config.Installation) error {
return errors.New("synthetic-runtime-projection-secret")
}
t.Cleanup(func() { requireRuntimeAuthProjectionReady = previous })
runner := &doctorRunner{services: healthyServices}
report, err := Run(context.Background(), installation, runner)
if err != nil {
t.Fatal(err)
}
failures := 0
for _, check := range report.Checks {
if check.Name != "auth-projection" {
continue
}
failures++
if check.Status != StatusFailed || check.Detail != "runtime authentication projection is unavailable" {
t.Fatalf("auth-projection check = %#v", check)
}
}
if failures != 1 {
t.Fatalf("auth-projection failures = %d, report = %#v", failures, report)
}
if strings.Contains(reportText(report), "synthetic-runtime-projection-secret") {
t.Fatalf("runtime projection report leaked internal detail: %#v", report)
}
if len(runner.calls) != 0 {
t.Fatalf("doctor reached Compose diagnostics after failed projection gate: %v", runner.calls)
}
}
func TestRunLeavesUnprojectedDoctorChecklistUnchanged(t *testing.T) {
report, err := Run(context.Background(), doctorInstallation(t, ""), &doctorRunner{services: healthyServices})
if err != nil {
t.Fatal(err)
}
for _, check := range report.Checks {
if check.Name == "auth-projection" {
t.Fatalf("unprojected report unexpectedly contains auth-projection: %#v", report)
}
}
}
func TestValidateVolumesRequiresAuthState(t *testing.T) {
legacy := `{"volumes":{"settings":{},"pi-state":{},"workspace-registry":{},"workspace-secrets":{},"sessions":{},"qdrant-data":{},"embedding-models":{}}}`
if err := ValidateVolumes(legacy); err == nil || !strings.Contains(err.Error(), "auth-state") {