feat(auth): add generic OIDC login with mandatory groups

This commit is contained in:
2026-08-17 05:44:10 +02:00
parent 202822f3ba
commit 4fe51cbeb1
20 changed files with 1144 additions and 40 deletions
+4 -4
View File
@@ -6,7 +6,7 @@ import { stringify } from "yaml";
import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
test("configured OIDC starts with provider-neutral protocol placeholders that fail closed", async () => {
test("configured OIDC advertises login but fails closed without its runtime client secret", async () => {
const directory = mkdtempSync(join(tmpdir(), "thothii-app-oidc-mode-"));
const file = join(directory, "auth.yaml");
writeFileSync(file, stringify({
@@ -22,10 +22,10 @@ test("configured OIDC starts with provider-neutral protocol placeholders that fa
const app = buildApp(loadConfig({ THT_AUTH_CONFIG_FILE: file, THT_AUTH_STATE_ROOT: join(directory, "auth-state") }));
try {
expect((await app.inject({ method: "GET", url: "/auth/config" })).json())
.toEqual({ mode: "oidc", localLogin: false, oidcLogin: false });
.toEqual({ mode: "oidc", localLogin: false, oidcLogin: true });
const placeholder = await app.inject({ method: "GET", url: "/auth/oidc/login" });
expect(placeholder.statusCode).toBe(501);
expect(placeholder.json()).toEqual({ code: "auth_not_implemented", error: "OIDC login is not implemented" });
expect(placeholder.statusCode).toBe(503);
expect(placeholder.json()).toEqual({ code: "auth_unavailable", error: "Authentication is unavailable" });
} finally {
await app.close();
}