fix(auth): make local verification portable

Keep upstream identity visible while limiting logout to local auth. Inject the restore privilege gate so the deterministic core tests do not depend on the host OS, and confine descriptor-backed projection tests to Linux. Accept the real remaining Pi timeout budget instead of an exact millisecond.
This commit is contained in:
2026-08-25 10:50:30 +02:00
parent e9c65ef2db
commit 610ae8c85a
10 changed files with 60 additions and 38 deletions
+2 -2
View File
@@ -65,7 +65,7 @@ describe("authenticated shell permissions", () => {
expect(screen.getByRole("button", { name: "All sessions" })).toBeInTheDocument();
});
test("hides identity and logout outside local authentication", async () => {
test("keeps identity but hides logout outside local authentication", async () => {
let logoutCalls = 0;
server.use(http.post("/api/auth/logout", () => {
logoutCalls += 1;
@@ -79,7 +79,7 @@ describe("authenticated shell permissions", () => {
permissions: ["session.use"],
}, false);
await waitFor(() => expect(screen.queryByText("portal-user")).not.toBeInTheDocument());
expect(await screen.findByText("portal-user")).toBeInTheDocument();
expect(screen.queryByRole("button", { name: "Log out" })).not.toBeInTheDocument();
expect(logoutCalls).toBe(0);
});