fix(auth): bind current local registry and CORS
This commit is contained in:
@@ -5,6 +5,8 @@ import { chmodSync, mkdtempSync, readFileSync, rmSync, statSync } from "node:fs"
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { expandLocalHome, localPrincipal, upstreamPrincipal } from "../src/auth/principal.js";
|
||||
import { buildApp } from "../src/app.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
|
||||
test("server smoke trusted claims transform through nginx to a non-admin principal", () => {
|
||||
const smoke = readFileSync("../scripts/unified-deployment-smoke.sh", "utf8");
|
||||
@@ -107,6 +109,48 @@ test("upstream mode rejects legacy client identity headers without proxy princip
|
||||
}
|
||||
});
|
||||
|
||||
test("buildApp exposes safe nullable session metadata for authenticated legacy modes", async () => {
|
||||
const configurations = [
|
||||
{
|
||||
name: "none",
|
||||
config: loadConfig({ NODE_ENV: "test", AUTH_MODE: "none", THT_HARNESS_DIR: "/tmp/h" }),
|
||||
headers: {},
|
||||
expected: { issuer: "local", roles: ["admin"] },
|
||||
},
|
||||
{
|
||||
name: "mock",
|
||||
config: loadConfig({ NODE_ENV: "test", AUTH_MODE: "mock", THT_HARNESS_DIR: "/tmp/h" }),
|
||||
headers: { "x-mock-user": "legacy-mock" },
|
||||
expected: { issuer: "mock", subject: "legacy-mock", roles: ["user"] },
|
||||
},
|
||||
{
|
||||
name: "upstream",
|
||||
config: loadConfig({ NODE_ENV: "production", AUTH_MODE: "upstream", THT_HARNESS_DIR: "/tmp/h" }),
|
||||
headers: {
|
||||
"x-thoth-principal-issuer": "portal",
|
||||
"x-thoth-principal-subject": "legacy-upstream",
|
||||
"x-thoth-is-admin": "0",
|
||||
},
|
||||
expected: { issuer: "portal", subject: "legacy-upstream", roles: ["user"] },
|
||||
},
|
||||
];
|
||||
|
||||
for (const legacy of configurations) {
|
||||
const app = buildApp(legacy.config, { thtRunner: {} as any, listModels: async () => [] });
|
||||
try {
|
||||
const response = await app.inject({ method: "GET", url: "/me", headers: legacy.headers });
|
||||
expect(response.statusCode, legacy.name).toBe(200);
|
||||
expect(response.json()).toMatchObject({
|
||||
...legacy.expected,
|
||||
csrfToken: null,
|
||||
session: null,
|
||||
});
|
||||
} finally {
|
||||
await app.close();
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
test("the session boundary exposes only exact health and authentication protocol paths", async () => {
|
||||
const app = Fastify();
|
||||
app.addHook("preHandler", authenticateSession({
|
||||
|
||||
Reference in New Issue
Block a user