fix(auth): harden Windows storage bridge
This commit is contained in:
@@ -73,6 +73,22 @@ func TestCreateCanonicalNewPrivateFileInstallsOwnerOnlyDACLAtCreation(t *testing
|
||||
}
|
||||
}
|
||||
|
||||
func TestGenericNewFileAllowsInheritedOperatorParentButAuthNewFileRequiresPrivateParent(t *testing.T) {
|
||||
directory := filepath.Join(t.TempDir(), "operator-output")
|
||||
if err := os.Mkdir(directory, 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := setPermissiveDACL(directory); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := WriteCanonicalNewFile(filepath.Join(directory, "candidates.yaml"), []byte("reviewed: []\n"), 0o600); err != nil {
|
||||
t.Fatalf("generic operator output error = %v", err)
|
||||
}
|
||||
if err := WriteCanonicalNewPrivateFile(filepath.Join(directory, "auth.json"), []byte("record"), 0o600); !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("auth record in inherited directory error = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWithWindowsSecurityDescriptorKeepsOwnedDescriptorValidDuringInspection(t *testing.T) {
|
||||
directory := filepath.Join(t.TempDir(), "auth")
|
||||
if err := os.Mkdir(directory, 0o700); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user