fix(auth): make diagnostics match runtime safety

This commit is contained in:
2026-08-17 11:23:52 +02:00
parent f0ae680671
commit 7cfbee36fa
14 changed files with 619 additions and 99 deletions
@@ -84,6 +84,47 @@ test("refuses declared and streamed group catalog bodies larger than one MiB", a
}
});
test.each([
["malformed", "not-a-number"],
["oversized", String(1024 * 1024 + 1)],
])("cancels a %s declared-size body without waiting for hanging cancellation", async (_caseName, contentLength) => {
let cancelled = false;
const body = new ReadableStream({
pull() { /* early declared-size rejection must not read */ },
cancel() {
cancelled = true;
return new Promise<void>(() => { /* cancellation remains advisory */ });
},
});
const completion = catalog(vi.fn<typeof globalThis.fetch>(async () => new Response(body, {
headers: { "content-length": contentLength },
}))).verifyConfiguredGroups(["TOT Users"], new AbortController().signal);
await expect(Promise.race([
completion,
new Promise((resolve) => setTimeout(() => resolve("timed-out"), 100)),
])).resolves.toEqual([expect.objectContaining({ code: "oidc_group_catalog_unreachable" })]);
expect(cancelled).toBe(true);
expect(body.locked).toBe(false);
});
test("contains a rejected declared-size cancellation without an unhandled rejection", async () => {
let cancelled = false;
const body = new ReadableStream({
pull() { /* early declared-size rejection must not read */ },
cancel() {
cancelled = true;
return Promise.reject(new Error("cancellation-detail-must-stay-contained"));
},
});
await expect(catalog(vi.fn<typeof globalThis.fetch>(async () => new Response(body, {
headers: { "content-length": "invalid" },
}))).verifyConfiguredGroups(["TOT Users"], new AbortController().signal))
.resolves.toEqual([expect.objectContaining({ code: "oidc_group_catalog_unreachable" })]);
expect(cancelled).toBe(true);
});
test("aborts a hanging request at five seconds", async () => {
vi.useFakeTimers();
try {