feat(auth): integrate authentication with installation lifecycle
This commit is contained in:
@@ -11,7 +11,9 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/authconfig"
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/compose"
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/config"
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/doctor"
|
||||
)
|
||||
|
||||
@@ -65,6 +67,55 @@ func TestRunConfigureOnlyStopsAfterRenderedConfiguration(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunConfiguresAndStaticallyValidatesLocalAuthBeforeComposeRender(t *testing.T) {
|
||||
projectRoot, request := setupRunFixture(t, true)
|
||||
passwordFile := filepath.Join(projectRoot, "initial-admin-password")
|
||||
if err := os.WriteFile(passwordFile, []byte("correct horse battery staple"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
request.NonInteractive = true
|
||||
request.Answers.AuthMode = "local"
|
||||
request.Answers.AuthPublicURL = "http://127.0.0.1:8080"
|
||||
request.Answers.AuthAdminUser = "admin"
|
||||
request.Answers.AuthAdminDisplayName = "Initial Admin"
|
||||
request.Answers.AuthPasswordFile = passwordFile
|
||||
runner := &setupRunner{}
|
||||
|
||||
if _, err := Run(context.Background(), runner, request, strings.NewReader(""), io.Discard); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
installationPath := filepath.Join(projectRoot, "deploy", "ci", "thothii-installation.yaml")
|
||||
installation, err := config.Load(installationPath)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
configuration, registry, err := authconfig.Load(installation.AuthenticationDirectory())
|
||||
if err != nil {
|
||||
t.Fatalf("setup did not create a statically valid authentication configuration: %v", err)
|
||||
}
|
||||
if configuration.Mode != "local" || len(registry.Users) != 1 || registry.Users[0].Username != "admin" {
|
||||
t.Fatalf("authentication configuration = %#v registry = %#v", configuration, registry)
|
||||
}
|
||||
assertSetupStages(t, runner, "docker engine", "docker compose", "architecture", "compose config")
|
||||
}
|
||||
|
||||
func TestRunRejectsIncompleteNonInteractiveLocalAuthenticationBeforeComposeRender(t *testing.T) {
|
||||
_, request := setupRunFixture(t, true)
|
||||
request.NonInteractive = true
|
||||
request.Answers.AuthMode = "local"
|
||||
request.Answers.AuthPublicURL = ""
|
||||
request.Answers.AuthAdminUser = ""
|
||||
request.Answers.AuthAdminDisplayName = ""
|
||||
request.Answers.AuthPasswordFile = ""
|
||||
runner := &setupRunner{}
|
||||
|
||||
_, err := Run(context.Background(), runner, request, strings.NewReader(""), io.Discard)
|
||||
if err == nil || !strings.Contains(err.Error(), "non-interactive local authentication") {
|
||||
t.Fatalf("Run() error = %v, want non-interactive local authentication guidance", err)
|
||||
}
|
||||
assertSetupStages(t, runner, "docker engine", "docker compose", "architecture")
|
||||
}
|
||||
|
||||
func TestRunPropagatesPreflightFailureBeforeWritingConfiguration(t *testing.T) {
|
||||
projectRoot, request := setupRunFixture(t, false)
|
||||
runner := &setupRunner{failureAt: "docker engine"}
|
||||
@@ -137,7 +188,7 @@ func TestRunPiDoctorFailurePreservesCauseAndOffersRecovery(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestRequireVolumesRequiresEveryInstallationVolume(t *testing.T) {
|
||||
all := []string{"settings", "pi-state", "workspace-registry", "workspace-secrets", "sessions", "qdrant-data", "embedding-models"}
|
||||
all := []string{"settings", "pi-state", "workspace-registry", "workspace-secrets", "sessions", "qdrant-data", "embedding-models", "auth-state"}
|
||||
for _, missing := range all {
|
||||
t.Run("missing "+missing, func(t *testing.T) {
|
||||
volumes := make([]string, 0, len(all)-1)
|
||||
@@ -301,7 +352,7 @@ func setupStage(args []string) (string, compose.Result) {
|
||||
}
|
||||
}
|
||||
|
||||
const renderedSetupConfig = `{"volumes":{"settings":{},"pi-state":{},"workspace-registry":{},"workspace-secrets":{},"sessions":{},"qdrant-data":{},"embedding-models":{}},"services":{"core":{"image":"thothii-core:local","environment":{"THT_LLM_URL":"https://llm.example.invalid"}}}}`
|
||||
const renderedSetupConfig = `{"volumes":{"settings":{},"pi-state":{},"workspace-registry":{},"workspace-secrets":{},"sessions":{},"qdrant-data":{},"embedding-models":{},"auth-state":{}},"services":{"core":{"image":"thothii-core:local","environment":{"THT_LLM_URL":"https://llm.example.invalid"}}}}`
|
||||
|
||||
func renderedConfigForVolumes(volumes ...string) string {
|
||||
entries := make([]string, 0, len(volumes))
|
||||
@@ -338,12 +389,18 @@ func setupRunFixture(t *testing.T, configureOnly bool) (string, Request) {
|
||||
if err := os.MkdirAll(secrets, 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
passwordFile := filepath.Join(secrets, "initial-admin-password")
|
||||
if err := os.WriteFile(passwordFile, []byte("fixture authentication password"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
return root, Request{
|
||||
ProjectRoot: root, InstallationID: "ci", Profile: "local", ConfigureOnly: configureOnly, NonInteractive: true,
|
||||
Answers: Answers{
|
||||
WorkspaceRemote: "https://git.example.invalid/thothii-workspaces.git", WorkspaceBranch: "main", WorkspaceAccess: "https",
|
||||
SecretsFile: filepath.Join(secrets, "thothii.secrets"), PiAuthFile: filepath.Join(secrets, "pi-auth.json"),
|
||||
GitCredentialsFile: filepath.Join(secrets, "git-credentials"), GitCAFile: filepath.Join(secrets, "git-ca.pem"),
|
||||
AuthMode: "local", AuthPublicURL: "http://127.0.0.1:8080", AuthAdminUser: "admin",
|
||||
AuthAdminDisplayName: "Initial Admin", AuthPasswordFile: passwordFile,
|
||||
CreateSecretTemplates: true,
|
||||
},
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user