fix(auth): make diagnostics match runtime safety

This commit is contained in:
2026-08-17 11:23:52 +02:00
parent f0ae680671
commit 7cfbee36fa
14 changed files with 619 additions and 99 deletions
+12 -1
View File
@@ -125,6 +125,18 @@ describe("local user registry", () => {
await expect(registry.verify(await registry.findByUsername("operator"), password)).resolves.toBe(false);
});
test("reports whether a structurally valid registry has an enabled administrator", async () => {
const admin = createLocalUserRegistry(writeRegistry(registryYaml(userYaml())).path);
const usersOnly = createLocalUserRegistry(writeRegistry(registryYaml(userYaml({ role: "user" }))).path);
const disabledAdmin = createLocalUserRegistry(writeRegistry(registryYaml(userYaml({ enabled: false }))).path);
await expect(admin.hasEnabledAdmin()).resolves.toBe(true);
await expect(usersOnly.hasEnabledAdmin()).resolves.toBe(false);
await expect(disabledAdmin.hasEnabledAdmin()).resolves.toBe(false);
await expectInvalid(usersOnly.findByUsername("admin"));
await expectInvalid(disabledAdmin.findBySubject(adminId));
});
test("rejects a valid registry under a non-private authentication directory", async () => {
const fixture = writeRegistry(registryYaml(userYaml()));
chmodSync(fixture.root, 0o750);
@@ -151,7 +163,6 @@ describe("local user registry", () => {
["duplicate normalized usernames", registryYaml(userYaml() + userYaml({ id: userId, username: "admin" }))],
["duplicate IDs", registryYaml(userYaml() + userYaml({ username: "operator" }))],
["unknown YAML fields", `${registryYaml(userYaml())}unexpected: true\n`],
["no enabled admin", registryYaml(userYaml({ role: "user" }))],
["duplicate roles", registryYaml(userYaml().replace(" - admin", " - admin\n - admin"))],
["invalid password hash", registryYaml(userYaml().replace(passwordHash, "not-a-password-hash"))],
["control character in display name", registryYaml(userYaml().replace("displayName: Admin", 'displayName: "Admin\\tUser"'))],