fix(auth): honor HTTPS sessions in Pi management

This commit is contained in:
2026-08-17 01:46:34 +02:00
parent 09e546c1ef
commit 8c67cb75dc
5 changed files with 146 additions and 14 deletions
+36
View File
@@ -255,6 +255,42 @@ test("logout revokes the session and clears the cookie with the production attri
expect((await app.inject({ method: "GET", url: "/me", headers: { cookie: cookiePair(setCookie) } })).statusCode).toBe(401);
});
test.each([false, true])(
"an uppercase HTTPS public URL sets and clears the secure cookie for remembered=%s",
async (remember) => {
const configuredPublicUrl = "HTTPS://thothii.example.test";
const origin = new URL(configuredPublicUrl).origin;
const { app } = await createLocalApp({ publicUrl: configuredPublicUrl });
const signedIn = await app.inject({
method: "POST",
url: "/auth/local/login",
headers: { origin, "sec-fetch-site": "same-origin" },
payload: { username: "Admin", password, remember },
});
const setCookie = firstSetCookie(signedIn);
expect(signedIn.statusCode).toBe(200);
expect(setCookie).toContain("Secure");
if (remember) expect(setCookie).toContain("Max-Age=2592000");
else expect(setCookie).not.toMatch(/Max-Age=/i);
const me = await app.inject({ method: "GET", url: "/me", headers: { cookie: cookiePair(setCookie) } });
const loggedOut = await app.inject({
method: "POST",
url: "/auth/logout",
headers: {
cookie: cookiePair(setCookie),
origin,
"sec-fetch-site": "same-origin",
"x-thothii-csrf": me.json().csrfToken,
},
});
expect(loggedOut.statusCode).toBe(204);
expect(firstSetCookie(loggedOut)).toContain("Secure");
},
);
test("failed logins are limited by normalized username and source address", async () => {
const user = {
id: adminId, username: "Admin", normalizedUsername: "admin", displayName: "Local administrator",