test(auth): gate local and OIDC authentication release

This commit is contained in:
2026-08-18 06:02:25 +02:00
parent 7cf7d9db6b
commit 8a3fa5031d
23 changed files with 1711 additions and 168 deletions
+4 -1
View File
@@ -13,11 +13,14 @@ def test_local_compose_uses_the_generic_external_endpoint_contract():
}
# workspace-maintenance is profile-gated: it must not be part of the default local startup.
assert compose["services"]["workspace-maintenance"].get("profiles") == ["workspace-maintenance"]
assert local["services"]["core"]["environment"]["AUTH_MODE"] == "none"
# Authentication is controlled by the mounted configuration; the local profile
# must not silently re-enable the legacy unauthenticated development mode.
assert "AUTH_MODE" not in local["services"]["core"]["environment"]
assert local["services"]["core"]["ports"] == ["127.0.0.1:${THOTH_CORE_HTTP_PORT:-8787}:8787"]
assert local["services"]["frontend"]["ports"] == ["127.0.0.1:${THOTH_HTTP_PORT:-8080}:8080"]
environment = compose["services"]["core"]["environment"]
assert {"THT_AUTH_CONFIG_FILE", "THT_AUTH_STATE_ROOT"} <= set(environment)
for name in ("THT_DWH_REST_URL", "THT_LLM_URL"):
assert name in environment
assert environment["THT_INTERNAL_QDRANT_URL"] == "http://qdrant:6333"