fix(backend): harden principal child isolation
This commit is contained in:
@@ -1282,6 +1282,27 @@ test("POST /sessions/:id/rename calls setName", async () => {
|
||||
expect(arg).toEqual({ id: "s1", name: "N" });
|
||||
});
|
||||
|
||||
test("rename authorizes and mutates through the same selected workspace", async () => {
|
||||
const workspaces: string[] = [];
|
||||
const app = buildApp(loadConfig({ AUTH_MODE: "upstream", THT_HARNESS_DIR: "../harness" }), {
|
||||
thtRunner: {
|
||||
withPrincipal: () => ({
|
||||
sessionShow: async (_id: string, workspace: string) => { workspaces.push(`show:${workspace}`); return { id: "s1" }; },
|
||||
setName: async (_id: string, _name: string, workspace: string) => { workspaces.push(`set:${workspace}`); },
|
||||
}),
|
||||
} as any,
|
||||
getSettings: () => ({ workspace: "tenant-a" }) as any,
|
||||
});
|
||||
const res = await app.inject({
|
||||
method: "POST", url: "/sessions/s1/rename", payload: { name: "N" },
|
||||
headers: {
|
||||
"x-thoth-principal-issuer": "portal", "x-thoth-principal-subject": "42", "x-thoth-is-admin": "false",
|
||||
},
|
||||
});
|
||||
expect(res.statusCode).toBe(204);
|
||||
expect(workspaces).toEqual(["show:tenant-a", "set:tenant-a"]);
|
||||
});
|
||||
|
||||
test("POST /sessions/:id/group calls setGroup", async () => {
|
||||
let arg: any;
|
||||
const app = mutApp({ setGroup: async (id: string, group: string) => { arg = { id, group }; } });
|
||||
|
||||
Reference in New Issue
Block a user