fix(auth): close diagnostic filesystem races
This commit is contained in:
@@ -55,6 +55,22 @@ func TestProtocolRejectsRecordCreationAfterSessionsDirectoryDACLBecomesPermissiv
|
||||
runRejected(t, request{Version: 1, Operation: "create", Root: root, Directory: "sessions", Filename: filename, ContentBase64: base64.StdEncoding.EncodeToString([]byte("record"))})
|
||||
}
|
||||
|
||||
func TestProtocolValidatesAndCreatesTheCompleteWindowsSessionLayout(t *testing.T) {
|
||||
root := filepath.Join(t.TempDir(), "auth")
|
||||
runRequest(t, request{Version: 1, Operation: "ensure-layout", Root: root})
|
||||
runRequest(t, request{Version: 1, Operation: "validate-root", Root: root})
|
||||
for _, directory := range []string{"sessions", "oidc"} {
|
||||
if err := safeio.ValidatePrivateDirectory(filepath.Join(root, directory)); err != nil {
|
||||
t.Fatalf("%s DACL = %v", directory, err)
|
||||
}
|
||||
}
|
||||
|
||||
if err := setPermissiveDACL(filepath.Join(root, "oidc")); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: root})
|
||||
}
|
||||
|
||||
func setPermissiveDACL(path string) error {
|
||||
world, err := windows.StringToSid("S-1-1-0")
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user