feat(auth): include authentication in workspace and tht diagnostics
This commit is contained in:
@@ -0,0 +1,67 @@
|
||||
import { expect, test, vi } from "vitest";
|
||||
import type { AuthDiagnoser, AuthDiagnostics } from "../src/auth/diagnostics.js";
|
||||
import { runDiagnosticCommand } from "../src/auth/diagnostic-command.js";
|
||||
|
||||
const failure: AuthDiagnostics = {
|
||||
ready: false,
|
||||
mode: "oidc",
|
||||
checks: [{
|
||||
level: "error",
|
||||
code: "oidc_mapped_group_missing",
|
||||
field: "Thoth Administrators",
|
||||
message: "A configured authorization group does not exist: command-secret-sentinel.",
|
||||
}],
|
||||
};
|
||||
|
||||
test("writes one redacted JSON diagnostic report and uses a failing diagnostic exit status", async () => {
|
||||
const stdout: string[] = [];
|
||||
const stderr: string[] = [];
|
||||
const diagnoser: AuthDiagnoser = { inspect: vi.fn(async () => failure) };
|
||||
|
||||
const exitCode = await runDiagnosticCommand(["--json"], {
|
||||
diagnoser,
|
||||
secretValues: ["command-secret-sentinel"],
|
||||
stdout: (line) => stdout.push(line),
|
||||
stderr: (line) => stderr.push(line),
|
||||
});
|
||||
|
||||
expect(exitCode).toBe(1);
|
||||
expect(diagnoser.inspect).toHaveBeenCalledWith({ live: true });
|
||||
expect(stderr).toEqual([]);
|
||||
expect(stdout).toHaveLength(1);
|
||||
expect(JSON.parse(stdout[0])).toEqual({
|
||||
...failure,
|
||||
checks: [{
|
||||
...failure.checks[0],
|
||||
message: "A configured authorization group does not exist: [REDACTED].",
|
||||
}],
|
||||
});
|
||||
expect(stdout.join("\n")).not.toContain("command-secret-sentinel");
|
||||
});
|
||||
|
||||
test("delegates an interactive diagnostic to OIDC and keeps its device prompt on stderr", async () => {
|
||||
const stdout: string[] = [];
|
||||
const stderr: string[] = [];
|
||||
const ready: AuthDiagnostics = {
|
||||
ready: true,
|
||||
mode: "oidc",
|
||||
checks: [{ level: "info", code: "auth_ready", message: "Authentication is ready." }],
|
||||
};
|
||||
const diagnoser: AuthDiagnoser = {
|
||||
inspect: vi.fn(async (options) => {
|
||||
options.presentDeviceCode?.("https://issuer.example.test/device", "ABCD-EFGH");
|
||||
return ready;
|
||||
}),
|
||||
};
|
||||
|
||||
const exitCode = await runDiagnosticCommand(["--json", "--interactive"], {
|
||||
diagnoser,
|
||||
stdout: (line) => stdout.push(line),
|
||||
stderr: (line) => stderr.push(line),
|
||||
});
|
||||
|
||||
expect(exitCode).toBe(0);
|
||||
expect(diagnoser.inspect).toHaveBeenCalledWith(expect.objectContaining({ live: true, interactive: true }));
|
||||
expect(stderr).toEqual(["Open https://issuer.example.test/device and enter code ABCD-EFGH"]);
|
||||
expect(JSON.parse(stdout.join(""))).toEqual(ready);
|
||||
});
|
||||
Reference in New Issue
Block a user