fix(auth): address Task 13 deployment review findings
This commit is contained in:
@@ -184,6 +184,43 @@ test("the session boundary exposes only exact health and authentication protocol
|
||||
expect((await app.inject({ method: "GET", url: "/auth/configured" })).statusCode).toBe(401);
|
||||
});
|
||||
|
||||
test("the session boundary retains the exact loopback tht maintenance identity in configured auth modes", async () => {
|
||||
const app = Fastify();
|
||||
app.addHook("preHandler", authenticateSession({ mode: "local" }));
|
||||
app.get("/private", async (request) => getPrincipal(request));
|
||||
app.post("/private", async (request) => getPrincipal(request));
|
||||
const headers = {
|
||||
"x-thoth-principal-issuer": "tht",
|
||||
"x-thoth-principal-subject": "tht-maintenance",
|
||||
"x-thoth-principal-display-name": "Tht maintenance",
|
||||
"x-thoth-is-admin": "1",
|
||||
};
|
||||
|
||||
for (const method of ["GET", "POST"] as const) {
|
||||
const response = await app.inject({ method, url: "/private", headers, remoteAddress: "127.0.0.1" });
|
||||
expect(response.statusCode).toBe(200);
|
||||
expect(response.json()).toMatchObject({ issuer: "tht", subject: "tht-maintenance", isAdmin: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("the session boundary rejects tht maintenance headers outside exact loopback provenance", async () => {
|
||||
const app = Fastify();
|
||||
app.addHook("preHandler", authenticateSession({ mode: "local" }));
|
||||
app.get("/private", async (request) => getPrincipal(request));
|
||||
const exact = {
|
||||
"x-thoth-principal-issuer": "tht",
|
||||
"x-thoth-principal-subject": "tht-maintenance",
|
||||
"x-thoth-principal-display-name": "Tht maintenance",
|
||||
"x-thoth-is-admin": "1",
|
||||
};
|
||||
|
||||
expect((await app.inject({ method: "GET", url: "/private", headers: exact, remoteAddress: "172.30.0.9" })).statusCode).toBe(503);
|
||||
expect((await app.inject({
|
||||
method: "GET", url: "/private", remoteAddress: "127.0.0.1",
|
||||
headers: { ...exact, "x-thoth-principal-subject": "not-maintenance" },
|
||||
})).statusCode).toBe(503);
|
||||
});
|
||||
|
||||
test("the session boundary touches a valid cookie session through the bounded Task 7 store operation", async () => {
|
||||
const sessions = {
|
||||
resolve: vi.fn(async () => ({
|
||||
|
||||
Reference in New Issue
Block a user