fix(backend): harden principal child isolation
This commit is contained in:
@@ -32,3 +32,28 @@ test("production spawnFn launches `pi --mode rpc` with no --approve (pi 0.73 dro
|
||||
expect(args).not.toContain("--approve");
|
||||
mgr.teardown("s1");
|
||||
});
|
||||
|
||||
test("Pi child replaces stale principal env and omits absent display names", async () => {
|
||||
const saved = Object.fromEntries([
|
||||
"THT_PRINCIPAL_ISSUER", "THT_PRINCIPAL_SUBJECT", "THT_PRINCIPAL_DISPLAY_NAME", "THT_PRINCIPAL_IS_ADMIN",
|
||||
].map((key) => [key, process.env[key]]));
|
||||
Object.assign(process.env, {
|
||||
THT_PRINCIPAL_ISSUER: "stale", THT_PRINCIPAL_SUBJECT: "stale", THT_PRINCIPAL_DISPLAY_NAME: "stale",
|
||||
THT_PRINCIPAL_IS_ADMIN: "true",
|
||||
});
|
||||
try {
|
||||
(nodeSpawn as any).mockClear();
|
||||
const mgr = new PiProcessManager(loadConfig({}));
|
||||
await mgr.spawnFor("s-principal", { principal: { issuer: "portal", subject: "42", isAdmin: false } });
|
||||
const env = (nodeSpawn as any).mock.calls[0][2].env;
|
||||
expect(env).toMatchObject({
|
||||
THT_PRINCIPAL_ISSUER: "portal", THT_PRINCIPAL_SUBJECT: "42", THT_PRINCIPAL_IS_ADMIN: "false",
|
||||
});
|
||||
expect(env).not.toHaveProperty("THT_PRINCIPAL_DISPLAY_NAME");
|
||||
mgr.teardown("s-principal");
|
||||
} finally {
|
||||
for (const [key, value] of Object.entries(saved)) {
|
||||
if (value === undefined) delete process.env[key]; else process.env[key] = value;
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user