fix(auth): isolate bounded OIDC cleanup

This commit is contained in:
2026-08-17 07:46:43 +02:00
parent bdabecbb63
commit 3e7bb11313
8 changed files with 456 additions and 177 deletions
+33
View File
@@ -199,6 +199,39 @@ describe("Windows auth-storage bridge", () => {
]);
});
test("passes an explicit bounded directory limit to the Go helper", async () => {
const invoke = vi.fn(async () => ({
code: 0,
stdout: Buffer.from('{"version":1,"ok":true,"entries":[]}\n'),
stderr: Buffer.alloc(0),
}));
const bridge = createWindowsAuthStorageBridge({ thtExecutable: "C:\\tht.exe", invoke });
await expect(bridge.list(root, "oidc", 192)).resolves.toEqual([]);
expect(JSON.parse(invoke.mock.calls[0][0].input.toString("utf8"))).toMatchObject({
operation: "list",
directory: "oidc",
maximumEntries: 192,
});
});
test("accepts a bounded ordinary-session page larger than the legacy 256-entry limit", async () => {
const entries = Array.from({ length: 300 }, (_unused, index) => ({
name: `${index.toString(16).padStart(64, "0")}.json`,
modifiedUnixMs: 1_893_456_245_000,
}));
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async () => ({
code: 0,
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, entries })}\n`),
stderr: Buffer.alloc(0),
}),
});
await expect(bridge.list(root, "sessions", 300)).resolves.toHaveLength(300);
});
test("parses the Go helper's required empty entries array", async () => {
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",