fix(auth): make diagnostics match runtime safety

This commit is contained in:
2026-08-17 11:23:52 +02:00
parent f0ae680671
commit 7cfbee36fa
14 changed files with 619 additions and 99 deletions
+5 -3
View File
@@ -1,5 +1,5 @@
import { expect, test } from "vitest";
import { mkdtempSync, rmSync, writeFileSync } from "node:fs";
import { chmodSync, mkdtempSync, realpathSync, rmSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { stringify } from "yaml";
@@ -7,7 +7,8 @@ import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
test("configured OIDC advertises login but fails closed without its runtime client secret", async () => {
const directory = mkdtempSync(join(tmpdir(), "thothii-app-oidc-mode-"));
const directory = mkdtempSync(join(realpathSync(tmpdir()), "thothii-app-oidc-mode-"));
chmodSync(directory, 0o700);
const file = join(directory, "auth.yaml");
writeFileSync(file, stringify({
version: 1, mode: "oidc", publicUrl: "https://thothii.example.org",
@@ -17,7 +18,8 @@ test("configured OIDC advertises login but fails closed without its runtime clie
},
groupCatalog: { driver: "authentik", baseUrl: "https://authentik.example.org", apiTokenRef: "THT_AUTHENTIK_API_TOKEN" },
authorization: { groupRoles: { "TOT Users": ["user"], "TOT Admin": ["admin"] } },
}), "utf8");
}), { encoding: "utf8", mode: 0o600 });
chmodSync(file, 0o600);
try {
const app = buildApp(loadConfig({ THT_AUTH_CONFIG_FILE: file, THT_AUTH_STATE_ROOT: join(directory, "auth-state") }));
try {