fix(auth): honor HTTPS sessions in Pi management
This commit is contained in:
@@ -255,6 +255,42 @@ test("logout revokes the session and clears the cookie with the production attri
|
||||
expect((await app.inject({ method: "GET", url: "/me", headers: { cookie: cookiePair(setCookie) } })).statusCode).toBe(401);
|
||||
});
|
||||
|
||||
test.each([false, true])(
|
||||
"an uppercase HTTPS public URL sets and clears the secure cookie for remembered=%s",
|
||||
async (remember) => {
|
||||
const configuredPublicUrl = "HTTPS://thothii.example.test";
|
||||
const origin = new URL(configuredPublicUrl).origin;
|
||||
const { app } = await createLocalApp({ publicUrl: configuredPublicUrl });
|
||||
|
||||
const signedIn = await app.inject({
|
||||
method: "POST",
|
||||
url: "/auth/local/login",
|
||||
headers: { origin, "sec-fetch-site": "same-origin" },
|
||||
payload: { username: "Admin", password, remember },
|
||||
});
|
||||
const setCookie = firstSetCookie(signedIn);
|
||||
expect(signedIn.statusCode).toBe(200);
|
||||
expect(setCookie).toContain("Secure");
|
||||
if (remember) expect(setCookie).toContain("Max-Age=2592000");
|
||||
else expect(setCookie).not.toMatch(/Max-Age=/i);
|
||||
|
||||
const me = await app.inject({ method: "GET", url: "/me", headers: { cookie: cookiePair(setCookie) } });
|
||||
const loggedOut = await app.inject({
|
||||
method: "POST",
|
||||
url: "/auth/logout",
|
||||
headers: {
|
||||
cookie: cookiePair(setCookie),
|
||||
origin,
|
||||
"sec-fetch-site": "same-origin",
|
||||
"x-thothii-csrf": me.json().csrfToken,
|
||||
},
|
||||
});
|
||||
|
||||
expect(loggedOut.statusCode).toBe(204);
|
||||
expect(firstSetCookie(loggedOut)).toContain("Secure");
|
||||
},
|
||||
);
|
||||
|
||||
test("failed logins are limited by normalized username and source address", async () => {
|
||||
const user = {
|
||||
id: adminId, username: "Admin", normalizedUsername: "admin", displayName: "Local administrator",
|
||||
|
||||
Reference in New Issue
Block a user