fix: harden workspace registry deployment

This commit is contained in:
2026-08-04 07:42:35 +02:00
parent f71feecaea
commit 802b564200
11 changed files with 132 additions and 14 deletions
+18
View File
@@ -39,6 +39,24 @@ test("loadConfig keeps local development defaults", () => {
expect(loadConfig({}).dataRoot).toBeUndefined();
});
test("loadConfig enables the legacy workspace request only through explicit local mode", () => {
expect(loadConfig({ THT_LEGACY_WORKSPACE_MODE: "local" }).legacyWorkspaceMode).toBe(true);
expect(() => loadConfig({
THT_LEGACY_WORKSPACE_MODE: "local",
AUTH_MODE: "upstream",
THT_SESSION_STORAGE: "postgres",
THT_SESSION_DB_HOST: "db.internal",
THT_SESSION_DB_NAME: "thoth",
THT_SESSION_RUNTIME_USER: "thoth_sessions_app",
THT_SESSION_RUNTIME_PASSWORD_FILE: "/run/secrets/session_runtime_password",
THT_SESSION_DB_SSLMODE: "verify-full",
THT_SESSION_DB_SSLROOTCERT: "/run/secrets/session_ca.pem",
})).toThrow(/legacy workspace mode requires local session storage/);
expect(() => loadConfig({ THT_LEGACY_WORKSPACE_MODE: "true" }))
.toThrow(/legacy workspace mode configuration is invalid/);
});
test("loadConfig rejects unauthenticated public exposure", () => {
expect(() => loadConfig({
THOTH_PUBLIC_EXPOSURE: "true",