feat(auth): include authentication in workspace and tht diagnostics

This commit is contained in:
2026-08-17 15:51:16 +02:00
parent cb0e873ed7
commit 3ed00ff086
19 changed files with 1050 additions and 34 deletions
+43 -3
View File
@@ -26,6 +26,12 @@ const requirement = {
configured: false,
};
const readyAuthentication = {
ready: true,
mode: "none",
checks: [{ level: "info", code: "auth_ready", message: "Authentication is ready." }],
};
function runtimeConfiguration(configured = false) {
return {
workspaceId: "psd-clinical",
@@ -187,10 +193,13 @@ test("workspace-specific commands remain isolated until a workspace is selected"
test("keeps validation and connection results inside their respective action cards", async () => {
const user = userEvent.setup();
server.use(
http.post("/api/workspaces/validate", () => HttpResponse.json({ workspace, contract: {} })),
http.post("/api/workspaces/validate", () => HttpResponse.json({
workspace, contract: {}, activatable: true, diagnostics: [], authentication: readyAuthentication,
})),
http.post("/api/workspaces/psd-clinical/test", () => HttpResponse.json({
activatable: false,
diagnostics: [{ level: "error", code: "connector_unavailable", message: "Connector diagnostic failed." }],
authentication: readyAuthentication,
})),
);
renderManager();
@@ -200,9 +209,9 @@ test("keeps validation and connection results inside their respective action car
const connectionCard = screen.getByTestId("workspace-connection-card");
await user.click(within(validationCard).getByRole("button", { name: "Validate workspace source" }));
const validationStatus = await within(validationCard).findByRole("status");
expect(validationStatus).toHaveTextContent("Workspace source is valid.");
expect(validationStatus).toHaveTextContent("Workspace source and authentication are valid.");
expect(validationStatus).toHaveClass("text-emerald-700");
expect(within(connectionCard).queryByText("Workspace source is valid.")).not.toBeInTheDocument();
expect(within(connectionCard).queryByText("Workspace source and authentication are valid.")).not.toBeInTheDocument();
await user.click(within(connectionCard).getByRole("button", { name: "Test workspace connections" }));
expect(await within(connectionCard).findByRole("alert")).toHaveTextContent(
@@ -211,12 +220,43 @@ test("keeps validation and connection results inside their respective action car
expect(within(validationCard).queryByText("connector_unavailable: Connector diagnostic failed.")).not.toBeInTheDocument();
});
test("renders one authentication section with configured-group errors and no unmapped-group list", async () => {
const user = userEvent.setup();
server.use(http.post("/api/workspaces/validate", () => HttpResponse.json({
workspace,
contract: {},
activatable: false,
diagnostics: [],
authentication: {
ready: false,
mode: "oidc",
checks: [{
level: "error",
code: "oidc_mapped_group_missing",
field: "Thoth Administrators",
message: "A configured authorization group does not exist.",
}],
},
})));
renderManager();
await user.click(await screen.findByRole("button", { name: "PSD Clinical" }));
await user.click(screen.getByRole("button", { name: "Validate workspace source" }));
const section = await screen.findByTestId("workspace-authentication");
expect(within(section).getByRole("heading", { name: "Authentication" })).toBeVisible();
expect(within(section).getByText("Failed")).toBeVisible();
expect(within(section).getByText("oidc_mapped_group_missing: Thoth Administrators — A configured authorization group does not exist.")).toBeVisible();
expect(within(section).queryByText(/unmapped/i)).not.toBeInTheDocument();
});
test("renders binding_ok as a green connection success", async () => {
const user = userEvent.setup();
server.use(
http.post("/api/workspaces/psd-clinical/test", () => HttpResponse.json({
activatable: true,
diagnostics: [{ level: "info", code: "binding_ok", message: "Installation bindings and diagnostics succeeded." }],
authentication: readyAuthentication,
})),
);
renderManager();
+24 -2
View File
@@ -23,6 +23,7 @@ import {
saveWorkspaceSecrets,
testWorkspace,
validateWorkspace,
type AuthDiagnostics,
type WorkspaceRuntimeConfiguration,
} from "../api/workspaces";
import { captureAuthOperation, isAuthOperationCurrent, StaleAuthOperationError } from "../auth/authOperation";
@@ -81,6 +82,7 @@ export function WorkspaceManager({
const [validationDiagnostics, setValidationDiagnostics] = useState<string[]>([]);
const [connectionNotice, setConnectionNotice] = useState<string>();
const [connectionDiagnostics, setConnectionDiagnostics] = useState<string[]>([]);
const [authentication, setAuthentication] = useState<AuthDiagnostics>();
const [busyAction, setBusyAction] = useState<string>();
const operationEpochRef = useRef(0);
const selectedIdRef = useRef(selectedId);
@@ -135,6 +137,7 @@ export function WorkspaceManager({
setValidationDiagnostics([]);
setConnectionNotice(undefined);
setConnectionDiagnostics([]);
setAuthentication(undefined);
};
const clearGlobalMessages = () => {
@@ -194,9 +197,10 @@ export function WorkspaceManager({
setValidationNotice(undefined);
setValidationDiagnostics([]);
try {
await validateWorkspace(detailQuery.data.workspace);
const result = await validateWorkspace(detailQuery.data.workspace);
if (!isAuthOperationCurrent(guard, { sessionId: selectedIdRef.current, disposalEpoch: operationEpochRef.current })) return;
setValidationNotice("Workspace source is valid.");
setAuthentication(result.authentication);
setValidationNotice(result.activatable ? "Workspace source and authentication are valid." : "Workspace source is valid.");
} catch (error) {
if (isAuthOperationCurrent(guard, { sessionId: selectedIdRef.current, disposalEpoch: operationEpochRef.current })) {
setValidationDiagnostics([publicError(error, "workspace_invalid: Workspace validation could not be completed")]);
@@ -218,6 +222,7 @@ export function WorkspaceManager({
try {
const result = await testWorkspace(selectedId);
if (!isAuthOperationCurrent(guard, { sessionId: selectedIdRef.current, disposalEpoch: operationEpochRef.current })) return;
setAuthentication(result.authentication);
const issues = result.diagnostics.filter(({ level }) => level !== "info");
const informational = result.diagnostics.find(({ level }) => level === "info");
setConnectionDiagnostics(issues.map(({ code, message }) => `${code}: ${message}`));
@@ -480,6 +485,23 @@ export function WorkspaceManager({
</div>
</div>
{authentication && <section data-testid="workspace-authentication" className="rounded-lg border border-border p-4">
<div className="flex flex-wrap items-center justify-between gap-2">
<h4 className="font-heading font-semibold">Authentication</h4>
<span className={authentication.ready ? "text-sm font-medium text-emerald-700" : "text-sm font-medium text-amber-700"}>
{authentication.ready ? "Passed" : "Failed"}
</span>
</div>
{!authentication.ready && <div role="alert" className="mt-3 grid gap-1 rounded-md border border-amber-500/30 bg-amber-500/10 px-3 py-2 text-sm">
{authentication.checks.filter(({ level }) => level === "error").map(({ code, field, message }) => (
<p key={`${code}:${field ?? ""}`} className="flex items-start gap-2">
<AlertCircle className="mt-0.5 size-4 shrink-0 text-amber-700" />
{code}: {field === undefined ? message : `${field} — ${message}`}
</p>
))}
</div>}
</section>}
{canManageSecrets && <div className="rounded-lg border border-border p-4">
<div className="mb-4 flex items-start gap-3">
<KeyRound className="mt-0.5 size-5 text-primary" />