fix(backend): harden principal child isolation
This commit is contained in:
@@ -1,6 +1,10 @@
|
||||
import { test, expect } from "vitest";
|
||||
import Fastify from "fastify";
|
||||
import { authPreHandler, getPrincipal } from "../src/auth/auth.js";
|
||||
import { chmodSync, mkdtempSync, rmSync, statSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { expandLocalHome, localPrincipal } from "../src/auth/principal.js";
|
||||
|
||||
test("local mode resolves a stable local principal", async () => {
|
||||
const app = Fastify();
|
||||
@@ -46,3 +50,22 @@ test("upstream mode accepts only normalized proxy principal headers", async () =
|
||||
issuer: "portal", subject: "42", displayName: "Alice", isAdmin: true,
|
||||
});
|
||||
});
|
||||
|
||||
test("local identity expands tilde homes and restores private POSIX permissions", () => {
|
||||
expect(expandLocalHome("~/thoth-test", "/home/tester")).toBe("/home/tester/thoth-test");
|
||||
expect(expandLocalHome("~", "/home/tester")).toBe("/home/tester");
|
||||
const home = mkdtempSync(join(tmpdir(), "thoth-principal-"));
|
||||
chmodSync(home, 0o755);
|
||||
const previous = process.env.THT_HOME;
|
||||
process.env.THT_HOME = home;
|
||||
try {
|
||||
localPrincipal();
|
||||
if (process.platform !== "win32") {
|
||||
expect(statSync(home).mode & 0o777).toBe(0o700);
|
||||
expect(statSync(join(home, "identity.json")).mode & 0o777).toBe(0o600);
|
||||
}
|
||||
} finally {
|
||||
if (previous === undefined) delete process.env.THT_HOME; else process.env.THT_HOME = previous;
|
||||
rmSync(home, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user