fix(auth): harden interactive diagnostic lifecycle

This commit is contained in:
2026-08-17 17:57:10 +02:00
parent ef244ab56d
commit af16464e68
9 changed files with 576 additions and 59 deletions
+62 -2
View File
@@ -273,8 +273,68 @@ test("clears a previous authentication result as soon as validation is retried",
await waitFor(() => expect(calls).toBe(2));
expect(screen.queryByTestId("workspace-authentication")).not.toBeInTheDocument();
releaseRetry();
expect(await screen.findByTestId("workspace-authentication")).toBeVisible();
releaseRetry();
expect(await screen.findByTestId("workspace-authentication")).toBeVisible();
});
test("ignores an older validation response that completes after a newer connection test", async () => {
const user = userEvent.setup();
let releaseValidation!: () => void;
let releaseTest!: () => void;
let validationStarted!: () => void;
let testStarted!: () => void;
let validationSettled!: () => void;
const heldValidation = new Promise<void>((resolve) => { releaseValidation = resolve; });
const heldTest = new Promise<void>((resolve) => { releaseTest = resolve; });
const validationRequestStarted = new Promise<void>((resolve) => { validationStarted = resolve; });
const testRequestStarted = new Promise<void>((resolve) => { testStarted = resolve; });
const validationRequestSettled = new Promise<void>((resolve) => { validationSettled = resolve; });
server.use(
http.post("/api/workspaces/validate", async () => {
validationStarted();
try {
await heldValidation;
return HttpResponse.json({
workspace, contract: {}, activatable: true, diagnostics: [], authentication: readyAuthentication,
});
} finally {
validationSettled();
}
}),
http.post("/api/workspaces/psd-clinical/test", async () => {
testStarted();
await heldTest;
return HttpResponse.json({
activatable: false,
diagnostics: [],
authentication: {
ready: false,
mode: "oidc",
checks: [{ level: "error", code: "oidc_secret_missing", message: "Newer connection result." }],
},
});
}),
);
renderManager();
await user.click(await screen.findByRole("button", { name: "PSD Clinical" }));
await user.click(screen.getByRole("button", { name: "Validate workspace source" }));
await validationRequestStarted;
await user.click(screen.getByRole("button", { name: "Test workspace connections" }));
await testRequestStarted;
expect(screen.queryByTestId("workspace-authentication")).not.toBeInTheDocument();
act(() => releaseTest());
const authentication = await screen.findByTestId("workspace-authentication");
expect(within(authentication).getByText(/Newer connection result/)).toBeVisible();
act(() => releaseValidation());
await act(async () => {
await validationRequestSettled;
await new Promise((resolve) => { setTimeout(resolve, 50); });
});
expect(within(authentication).getByText(/Newer connection result/)).toBeVisible();
expect(within(authentication).queryByText("Passed")).not.toBeInTheDocument();
});
test("never renders a hostile authentication field rejected by the API decoder", async () => {