test(auth): gate local and OIDC authentication release
This commit is contained in:
@@ -18,10 +18,56 @@ trap cleanup EXIT HUP INT TERM
|
||||
printf '%s\n' '{"zai":{"type":"api_key","key":"fixture-native-auth-key"}}' >"$tmp/pi-auth.json"
|
||||
printf '%s\n' 'THT_MODEL_API_KEY=fixture-model-api-key' >"$tmp/thothii.secrets"
|
||||
chmod 0600 "$tmp/pi-auth.json" "$tmp/thothii.secrets"
|
||||
auth_config="$tmp/auth"
|
||||
mkdir "$auth_config"
|
||||
chmod 0700 "$auth_config"
|
||||
printf '%s\n' \
|
||||
'version: 1' \
|
||||
'mode: local' \
|
||||
'publicUrl: http://127.0.0.1:8080' \
|
||||
'local:' \
|
||||
' usersFile: users.yaml' \
|
||||
>"$auth_config/auth.yaml"
|
||||
node - "$auth_config/users.yaml" <<'NODE'
|
||||
const { argon2 } = require("node:crypto");
|
||||
const { writeFileSync } = require("node:fs");
|
||||
|
||||
const message = Buffer.from("fixture-local-password", "utf8");
|
||||
const nonce = Buffer.from([...Array(16).keys()]);
|
||||
argon2("argon2id", {
|
||||
message,
|
||||
nonce,
|
||||
memory: 65_536,
|
||||
parallelism: 1,
|
||||
tagLength: 32,
|
||||
passes: 3,
|
||||
}, (error, digest) => {
|
||||
message.fill(0);
|
||||
nonce.fill(0);
|
||||
if (error || !digest) throw error ?? new Error("fixture password hash failed");
|
||||
const salt = Buffer.from([...Array(16).keys()]).toString("base64").replaceAll("=", "");
|
||||
const hash = digest.toString("base64").replaceAll("=", "");
|
||||
writeFileSync(process.argv[2], [
|
||||
"version: 1",
|
||||
"users:",
|
||||
" - id: 00000000-0000-4000-8000-000000000001",
|
||||
" username: fixture-user",
|
||||
" displayName: Fixture user",
|
||||
` passwordHash: $argon2id$v=19$m=65536,t=3,p=1$${salt}$${hash}`,
|
||||
" roles:",
|
||||
" - user",
|
||||
" enabled: true",
|
||||
" authRevision: 1",
|
||||
"",
|
||||
].join("\\n"), { mode: 0o600 });
|
||||
});
|
||||
NODE
|
||||
chmod 0600 "$auth_config/auth.yaml" "$auth_config/users.yaml"
|
||||
printf '%s\n' \
|
||||
'THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git' \
|
||||
"PI_AUTH_FILE=$tmp/pi-auth.json" \
|
||||
"THT_SECRETS_FILE=$tmp/thothii.secrets" \
|
||||
"THT_AUTH_CONFIG_ROOT=$auth_config" \
|
||||
'THOTH_CORE_HTTP_PORT=0' \
|
||||
'THOTH_HTTP_PORT=0' \
|
||||
>"$tmp/local.env"
|
||||
|
||||
Reference in New Issue
Block a user