feat(auth): integrate authentication with installation lifecycle
This commit is contained in:
@@ -70,6 +70,75 @@ func TestCreateWritesManifestLastWithConfigurationMetadataAndSevenVolumes(t *tes
|
||||
}
|
||||
}
|
||||
|
||||
func TestCreateReferencesAuthFilesByDefaultAndArchivesThemOnlyWithSecretCustody(t *testing.T) {
|
||||
fixture := newBackupFixture(t, "local")
|
||||
authDirectory := filepath.Join(filepath.Dir(fixture.installation.Path), "auth")
|
||||
if err := os.Mkdir(authDirectory, 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
authPath := filepath.Join(authDirectory, "auth.yaml")
|
||||
usersPath := filepath.Join(authDirectory, "users.yaml")
|
||||
if err := os.WriteFile(authPath, []byte("version: 1\nmode: local\n"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.WriteFile(usersPath, []byte("users:\n - passwordHash: must-not-be-archived-by-default\n"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
fixture.installation.Authentication.ConfigDirectory = authDirectory
|
||||
|
||||
defaultOutput := filepath.Join(t.TempDir(), "default.zip")
|
||||
defaultResult, err := createWithDependencies(context.Background(), fixture.installation, CreateRequest{Output: defaultOutput}, testDependencies(t, newBackupRunner(fixture.installation, false)))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if defaultResult.Warning != "" {
|
||||
t.Fatalf("default backup warning = %q, want no custody warning", defaultResult.Warning)
|
||||
}
|
||||
defaultArchive := readFixtureArchive(t, defaultOutput)
|
||||
defaultBytes := bytes.Join(mapValues(defaultArchive.files), nil)
|
||||
for _, value := range []string{"mode: local", "must-not-be-archived-by-default"} {
|
||||
if bytes.Contains(defaultBytes, []byte(value)) {
|
||||
t.Fatalf("default backup contains authentication content %q", value)
|
||||
}
|
||||
}
|
||||
if !manifestHasReference(defaultArchive.manifest, authPath) || manifestHasReference(defaultArchive.manifest, usersPath) {
|
||||
t.Fatalf("default backup did not record only the auth.yaml configuration path: %#v", defaultArchive.manifest.Entries)
|
||||
}
|
||||
|
||||
secretOutput := filepath.Join(t.TempDir(), "with-auth-secrets.zip")
|
||||
secretResult, err := createWithDependencies(context.Background(), fixture.installation, CreateRequest{Output: secretOutput, IncludeSecrets: true, Confirm: true}, testDependencies(t, newBackupRunner(fixture.installation, false)))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !strings.Contains(secretResult.Warning, "custody") {
|
||||
t.Fatalf("secret backup warning = %q, want custody guidance", secretResult.Warning)
|
||||
}
|
||||
secretArchive := readFixtureArchive(t, secretOutput)
|
||||
for _, path := range []string{authPath, usersPath} {
|
||||
if !manifestHasArchivedSecret(secretArchive.manifest, path) {
|
||||
t.Fatalf("secret backup did not archive authentication file %q", path)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func manifestHasReference(manifest Manifest, sourcePath string) bool {
|
||||
for _, entry := range manifest.Entries {
|
||||
if entry.Kind == EntrySecretReference && entry.SourcePath == sourcePath && !entry.Archived {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func manifestHasArchivedSecret(manifest Manifest, sourcePath string) bool {
|
||||
for _, entry := range manifest.Entries {
|
||||
if entry.Kind == EntryExternalSecret && entry.SourcePath == sourcePath && entry.Archived && entry.Sensitive {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func TestCreateRestartsAndVerifiesAnInstallationThatWasRunning(t *testing.T) {
|
||||
fixture := newBackupFixture(t, "local")
|
||||
runner := newBackupRunner(fixture.installation, true)
|
||||
|
||||
Reference in New Issue
Block a user