fix(auth): close diagnostic filesystem races

This commit is contained in:
2026-08-17 13:04:15 +02:00
parent be1724890a
commit 6d438f4c7e
16 changed files with 545 additions and 90 deletions
+35 -1
View File
@@ -6,7 +6,10 @@ import { fileURLToPath } from "node:url";
import { EventEmitter } from "node:events";
import { PassThrough } from "node:stream";
import { afterEach, describe, expect, test, vi } from "vitest";
import { createWindowsAuthStorageBridge } from "../src/auth/windows-auth-storage.js";
import {
createPosixAuthStorageBridge,
createWindowsAuthStorageBridge,
} from "../src/auth/windows-auth-storage.js";
const root = "C:\\ProgramData\\ThothII\\auth";
const filename = "a".repeat(64) + ".json";
@@ -80,6 +83,37 @@ function bridgeForChild(child: FakeBridgeChild) {
}
describe("Windows auth-storage bridge", () => {
test("uses the same bounded hidden bridge to ensure a POSIX session layout", async () => {
const calls: Array<{ executable: string; args: readonly string[]; input: Buffer; timeoutMs: number }> = [];
const bridge = createPosixAuthStorageBridge({
thtExecutable: "/opt/thothii/bin/tht",
invoke: async (call) => {
calls.push(call);
return {
code: 0,
stdout: Buffer.from('{"version":1,"ok":true,"prepared":true}\n'),
stderr: Buffer.alloc(0),
};
},
});
await expect(bridge.ensureLayout("/var/lib/thothii/auth")).resolves.toBeUndefined();
expect(calls).toHaveLength(1);
expect(calls[0]).toMatchObject({
executable: "/opt/thothii/bin/tht",
args: ["_auth-storage"],
timeoutMs: 5_000,
});
expect(JSON.parse(calls[0]!.input.toString("utf8"))).toEqual({
version: 1,
operation: "ensure-layout",
root: "/var/lib/thothii/auth",
});
expect(JSON.stringify(calls[0]!.args)).not.toContain("/var/lib/thothii/auth");
await expect(bridge.ensureLayout("/var/lib/thothii/../auth"))
.rejects.toThrow("auth_session_store_invalid");
});
test("permits reservation slots only for OIDC record operations", async () => {
const requests: Array<Record<string, unknown>> = [];
const bridge = createWindowsAuthStorageBridge({