fix(auth): make diagnostics match runtime safety
This commit is contained in:
@@ -1,14 +1,16 @@
|
||||
import { expect, test } from "vitest";
|
||||
import { mkdtempSync, readFileSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { chmodSync, mkdtempSync, readFileSync, realpathSync, rmSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { stringify } from "yaml";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
|
||||
function authFile(value: unknown): { directory: string; file: string } {
|
||||
const directory = mkdtempSync(join(tmpdir(), "thothii-app-auth-config-"));
|
||||
const directory = mkdtempSync(join(realpathSync(tmpdir()), "thothii-app-auth-config-"));
|
||||
chmodSync(directory, 0o700);
|
||||
const file = join(directory, "auth.yaml");
|
||||
writeFileSync(file, stringify(value), "utf8");
|
||||
writeFileSync(file, stringify(value), { encoding: "utf8", mode: 0o600 });
|
||||
chmodSync(file, 0o600);
|
||||
return { directory, file };
|
||||
}
|
||||
|
||||
@@ -109,7 +111,7 @@ test("loadConfig makes an existing auth.yaml authoritative and rejects AUTH_MODE
|
||||
});
|
||||
|
||||
test("loadConfig rejects an auth config path that exists but is not a regular file", () => {
|
||||
const directory = mkdtempSync(join(tmpdir(), "thothii-app-auth-config-directory-"));
|
||||
const directory = mkdtempSync(join(realpathSync(tmpdir()), "thothii-app-auth-config-directory-"));
|
||||
try {
|
||||
expect(() => loadConfig({ THT_AUTH_CONFIG_FILE: directory }))
|
||||
.toThrow("authentication configuration is invalid");
|
||||
|
||||
Reference in New Issue
Block a user