fix(deploy): close container final review

This commit is contained in:
2026-07-12 00:44:39 +02:00
parent 0ca6346f75
commit a3a266fd81
30 changed files with 526 additions and 37 deletions
+14
View File
@@ -22,3 +22,17 @@ test("mode mock legge l'header", async () => {
});
expect(res.json()).toEqual({ id: "alice" });
});
test("upstream mode requires the authenticated proxy identity header", async () => {
const app = Fastify();
app.addHook("preHandler", authPreHandler("upstream"));
app.get("/me", async (req) => getUser(req));
expect((await app.inject({ method: "GET", url: "/me" })).statusCode).toBe(401);
const authenticated = await app.inject({
method: "GET",
url: "/me",
headers: { "x-authenticated-user": "alice@example.test" },
});
expect(authenticated.json()).toEqual({ id: "alice@example.test" });
});
+14
View File
@@ -32,3 +32,17 @@ test("loadConfig keeps local development defaults", () => {
});
expect(loadConfig({}).dataRoot).toBeUndefined();
});
test("loadConfig rejects unauthenticated public exposure", () => {
expect(() => loadConfig({
THOTH_PUBLIC_EXPOSURE: "true",
AUTH_MODE: "none",
})).toThrow(/public exposure requires AUTH_MODE=upstream/);
});
test("loadConfig accepts an authenticated upstream trust boundary", () => {
expect(loadConfig({
THOTH_PUBLIC_EXPOSURE: "true",
AUTH_MODE: "upstream",
}).authMode).toBe("upstream");
});
+11
View File
@@ -10,6 +10,17 @@ test("GET /health reports process readiness without external services", async ()
expect(res.json()).toEqual({ status: "ok" });
});
test("GET /health remains available to container probes in upstream auth mode", async () => {
const app = buildApp(loadConfig({
THT_HARNESS_DIR: "/tmp/h",
AUTH_MODE: "upstream",
THOTH_PUBLIC_EXPOSURE: "true",
}));
const res = await app.inject({ method: "GET", url: "/health" });
expect(res.statusCode).toBe(200);
expect(res.json()).toEqual({ status: "ok" });
});
test("SSE response headers are flushed before the first event", async () => {
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "/tmp/h" }));
await app.listen({ port: 0, host: "127.0.0.1" });