fix(auth): close diagnostic filesystem races
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
import { chmodSync, mkdtempSync, realpathSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { chmodSync, mkdirSync, mkdtempSync, realpathSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import type { FastifyInstance } from "fastify";
|
||||
@@ -37,6 +37,16 @@ function cookiePair(setCookie: string): string {
|
||||
return setCookie.split(";", 1)[0] ?? "";
|
||||
}
|
||||
|
||||
/** Unit fixtures which bypass the installed tht binary start from an already-safe native layout. */
|
||||
export function prepareAuthStateRoot(root: string): void {
|
||||
mkdirSync(root, { mode: 0o700 });
|
||||
chmodSync(root, 0o700);
|
||||
for (const child of ["sessions", "oidc"]) {
|
||||
mkdirSync(join(root, child), { mode: 0o700 });
|
||||
chmodSync(join(root, child), 0o700);
|
||||
}
|
||||
}
|
||||
|
||||
/** Creates a production-local app and authenticates through the real login/session boundary. */
|
||||
export async function createLocalAuthFixture(
|
||||
deps?: BuildAppDeps,
|
||||
@@ -70,9 +80,11 @@ export async function createLocalAuthFixture(
|
||||
chmodSync(authConfigFile, 0o600);
|
||||
chmodSync(usersFile, 0o600);
|
||||
|
||||
const authStateRoot = join(directory, "auth-state");
|
||||
prepareAuthStateRoot(authStateRoot);
|
||||
const app = buildApp(loadConfig({
|
||||
THT_AUTH_CONFIG_FILE: authConfigFile,
|
||||
THT_AUTH_STATE_ROOT: join(directory, "auth-state"),
|
||||
THT_AUTH_STATE_ROOT: authStateRoot,
|
||||
THT_HARNESS_DIR: "/tmp/h",
|
||||
}), deps);
|
||||
let downstream = 0;
|
||||
|
||||
Reference in New Issue
Block a user