fix(auth): address Task 13 deployment review findings
This commit is contained in:
@@ -1,6 +1,8 @@
|
||||
package backup
|
||||
|
||||
import (
|
||||
"archive/tar"
|
||||
"bytes"
|
||||
"context"
|
||||
"errors"
|
||||
"io"
|
||||
@@ -13,6 +15,85 @@ import (
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/config"
|
||||
)
|
||||
|
||||
func TestRestorePublicPathUsesConcreteProductionPreflight(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
installation := config.Installation{
|
||||
Path: filepath.Join(root, "deploy", "local-dev", "thothii-installation.yaml"),
|
||||
ProjectDirectory: root,
|
||||
}
|
||||
missing := filepath.Join(root, "missing.zip")
|
||||
|
||||
_, err := Restore(context.Background(), installation, RestoreRequest{Archive: missing, Confirm: true})
|
||||
|
||||
if err == nil || strings.Contains(err.Error(), "dependencies are unavailable") || !strings.Contains(err.Error(), "backup archive") {
|
||||
t.Fatalf("Restore() error = %v, want production archive preflight", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRestoreRestoresVerifiedVolumesInManifestOrderBeforeAuthenticationReset(t *testing.T) {
|
||||
installation := preflightTestInstallation(t)
|
||||
archive := filepath.Join(t.TempDir(), "restore-volumes.zip")
|
||||
sessionsTar := safeRestoreTar(t, "session.txt", "session")
|
||||
settingsTar := safeRestoreTar(t, "settings.json", "settings")
|
||||
writePreflightArchive(t, archive, preflightArchiveSpec{
|
||||
volumes: []VolumeMetadata{
|
||||
{LogicalName: "sessions", Name: "project_sessions", Driver: "local"},
|
||||
{LogicalName: "settings", Name: "project_settings", Driver: "local"},
|
||||
},
|
||||
entries: []preflightArchiveEntry{
|
||||
{path: "configuration/operator.env", body: []byte("safe")},
|
||||
{path: "volumes/settings.tar", body: settingsTar, kind: EntryVolume, owner: "volume:settings", logicalName: "settings"},
|
||||
{path: "volumes/sessions.tar", body: sessionsTar, kind: EntryVolume, owner: "volume:sessions", logicalName: "sessions"},
|
||||
},
|
||||
})
|
||||
runner := newBackupRunner(installation, false)
|
||||
deps := restoreTestDependencies(t, runner)
|
||||
var events []string
|
||||
deps.restoreFile = func(_ context.Context, _ config.Installation, entry ArchiveEntryMetadata, _ io.Reader) error {
|
||||
events = append(events, "file:"+entry.Path)
|
||||
return nil
|
||||
}
|
||||
deps.restoreVolume = func(_ context.Context, _ config.Installation, volume VolumeMetadata, stream io.Reader) error {
|
||||
if _, err := io.ReadAll(stream); err != nil {
|
||||
return err
|
||||
}
|
||||
events = append(events, "volume:"+volume.LogicalName)
|
||||
return nil
|
||||
}
|
||||
deps.resetAuthenticationState = func(context.Context, config.Installation, archiveRunner) error {
|
||||
events = append(events, "reset-auth-state")
|
||||
return nil
|
||||
}
|
||||
|
||||
if _, err := restoreWithDependencies(context.Background(), installation, RestoreRequest{Archive: archive, Confirm: true}, deps); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got, want := events, []string{
|
||||
"file:configuration/operator.env",
|
||||
"volume:sessions",
|
||||
"volume:settings",
|
||||
"reset-auth-state",
|
||||
}; !equalStrings(got, want) {
|
||||
t.Fatalf("restore events = %v, want %v", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
func safeRestoreTar(t *testing.T, name, contents string) []byte {
|
||||
t.Helper()
|
||||
var output bytes.Buffer
|
||||
writer := tar.NewWriter(&output)
|
||||
if err := writer.WriteHeader(&tar.Header{Name: name, Mode: 0o600, Size: int64(len(contents)), Typeflag: tar.TypeReg}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := writer.Write([]byte(contents)); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := writer.Close(); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
return output.Bytes()
|
||||
}
|
||||
|
||||
func TestRestoreStoppedInstallationRunsCheckpointRestoreAndVerification(t *testing.T) {
|
||||
installation := preflightTestInstallation(t)
|
||||
archive := filepath.Join(t.TempDir(), "restore.zip")
|
||||
@@ -103,7 +184,9 @@ func TestResetAuthenticationStateCreatesOnlyPrivateEmptyStateDirectories(t *test
|
||||
joined := strings.Join(runner.args, "\x00")
|
||||
for _, required := range []string{
|
||||
"run", "--rm", "--no-deps", "--no-TTY", "--entrypoint", "sh", "core", "-ceu",
|
||||
"rm -rf /data/auth && install -d -m 0700 /data/auth /data/auth/sessions /data/auth/oidc",
|
||||
"find /data/auth -mindepth 1 -maxdepth 1 -exec rm -rf -- {} +",
|
||||
"install -d -m 0700 /data/auth /data/auth/sessions /data/auth/oidc",
|
||||
"find /data/auth/sessions /data/auth/oidc -mindepth 1 -print -quit",
|
||||
} {
|
||||
if !strings.Contains(joined, required) {
|
||||
t.Fatalf("authentication state reset command omits %q: %#v", required, runner.args)
|
||||
|
||||
Reference in New Issue
Block a user