feat(auth): integrate authentication with installation lifecycle

This commit is contained in:
2026-08-17 20:21:42 +02:00
parent 0a2c667231
commit 9558eaa508
30 changed files with 756 additions and 120 deletions
+15 -5
View File
@@ -1,4 +1,4 @@
import { constants, accessSync, readFileSync, statSync } from "node:fs";
import { constants, accessSync, readFileSync, realpathSync, statSync } from "node:fs";
import { basename, dirname, join } from "node:path";
import { createRequire } from "node:module";
import { resolveRuntimeBindings } from "../backend/src/workspaces/bindings.js";
@@ -28,7 +28,12 @@ for (const [name, service, expectedExpose] of [
["qdrant", qdrant, "6333"],
["embedding", embedding, "11434"],
] as const) {
if ((service.ports || []).length !== 0) throw new Error(`${name} must not publish host ports`);
const localQdrantDashboard = name === "qdrant" && profile === "local"
&& (service.ports || []).length === 1
&& service.ports[0].host_ip === "127.0.0.1" && Number(service.ports[0].target) === 6333;
if ((service.ports || []).length !== 0 && !localQdrantDashboard) {
throw new Error(`${name} must not publish host ports outside the local Qdrant dashboard`);
}
if ((service.expose || []).join(",") !== expectedExpose) {
throw new Error(`${name} must expose only ${expectedExpose}`);
}
@@ -139,8 +144,9 @@ for (const target of [
}
const resolverEnvironment = { ...core.environment };
resolverEnvironment.THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE = runtimePasswordMounts[0].source;
const bindings = resolveRuntimeBindings(workspace, resolverEnvironment, [dirname(runtimePasswordMounts[0].source)]);
const runtimePasswordSource = realpathSync(runtimePasswordMounts[0].source);
resolverEnvironment.THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE = runtimePasswordSource;
const bindings = resolveRuntimeBindings(workspace, resolverEnvironment, [dirname(runtimePasswordSource)]);
for (const [role, binding] of Object.entries(bindings)) {
if ((binding as any).missing.length !== 0) {
throw new Error(`workspace resolver reports missing ${role} bindings: ${(binding as any).missing.join(",")}`);
@@ -150,10 +156,14 @@ const runtime = parse(renderRuntimeConfig(workspace, bindings, {
sessions: "/data/sessions",
artifacts: "/data/artifacts",
indexes: "/data/indexes",
}, {
workspaceId: "task13-smoke",
workspaceRevision: "task13-fixture",
revisionContentRoot: join(dirname(workspacePath), "task13-fixture"),
}));
if (runtime.database.host !== expected.THT_WS_TASK13_SMOKE_DWH_HOST
|| runtime.database.user !== expected.THT_WS_TASK13_SMOKE_DWH_USER
|| runtime.database.password_file !== runtimePasswordMounts[0].source) {
|| runtime.database.password_file !== runtimePasswordSource) {
throw new Error("workspace resolver produced the wrong DWH runtime");
}
if (runtime.resources?.vector?.base_url !== "http://qdrant:6333"