fix(deploy): close container final review
This commit is contained in:
@@ -22,3 +22,17 @@ test("mode mock legge l'header", async () => {
|
||||
});
|
||||
expect(res.json()).toEqual({ id: "alice" });
|
||||
});
|
||||
|
||||
test("upstream mode requires the authenticated proxy identity header", async () => {
|
||||
const app = Fastify();
|
||||
app.addHook("preHandler", authPreHandler("upstream"));
|
||||
app.get("/me", async (req) => getUser(req));
|
||||
|
||||
expect((await app.inject({ method: "GET", url: "/me" })).statusCode).toBe(401);
|
||||
const authenticated = await app.inject({
|
||||
method: "GET",
|
||||
url: "/me",
|
||||
headers: { "x-authenticated-user": "alice@example.test" },
|
||||
});
|
||||
expect(authenticated.json()).toEqual({ id: "alice@example.test" });
|
||||
});
|
||||
|
||||
@@ -32,3 +32,17 @@ test("loadConfig keeps local development defaults", () => {
|
||||
});
|
||||
expect(loadConfig({}).dataRoot).toBeUndefined();
|
||||
});
|
||||
|
||||
test("loadConfig rejects unauthenticated public exposure", () => {
|
||||
expect(() => loadConfig({
|
||||
THOTH_PUBLIC_EXPOSURE: "true",
|
||||
AUTH_MODE: "none",
|
||||
})).toThrow(/public exposure requires AUTH_MODE=upstream/);
|
||||
});
|
||||
|
||||
test("loadConfig accepts an authenticated upstream trust boundary", () => {
|
||||
expect(loadConfig({
|
||||
THOTH_PUBLIC_EXPOSURE: "true",
|
||||
AUTH_MODE: "upstream",
|
||||
}).authMode).toBe("upstream");
|
||||
});
|
||||
|
||||
@@ -10,6 +10,17 @@ test("GET /health reports process readiness without external services", async ()
|
||||
expect(res.json()).toEqual({ status: "ok" });
|
||||
});
|
||||
|
||||
test("GET /health remains available to container probes in upstream auth mode", async () => {
|
||||
const app = buildApp(loadConfig({
|
||||
THT_HARNESS_DIR: "/tmp/h",
|
||||
AUTH_MODE: "upstream",
|
||||
THOTH_PUBLIC_EXPOSURE: "true",
|
||||
}));
|
||||
const res = await app.inject({ method: "GET", url: "/health" });
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(res.json()).toEqual({ status: "ok" });
|
||||
});
|
||||
|
||||
test("SSE response headers are flushed before the first event", async () => {
|
||||
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "/tmp/h" }));
|
||||
await app.listen({ port: 0, host: "127.0.0.1" });
|
||||
|
||||
Reference in New Issue
Block a user