fix(auth): bound OIDC initiation and transport

This commit is contained in:
2026-08-17 07:03:19 +02:00
parent 8573500121
commit bdabecbb63
15 changed files with 747 additions and 111 deletions
+22 -3
View File
@@ -122,9 +122,28 @@ test.each([
expect(() => loadAuthenticationConfig(writeFixture(value))).toThrow("authentication configuration is invalid");
});
test("accepts the explicit loopback HTTP OIDC exception", () => {
expect(loadAuthenticationConfig(writeFixture(oidcConfig({ publicUrl: "http://127.0.0.1:8787" }))).value.mode)
.toBe("oidc");
test.each([
"http://127.0.0.1:8787",
"http://127.255.255.254:8787",
"http://[::1]:8787",
])("accepts the literal loopback HTTP OIDC exception %s", (publicUrl) => {
expect(loadAuthenticationConfig(writeFixture(oidcConfig({ publicUrl }))).value.mode).toBe("oidc");
});
test.each([
"http://localhost:8787",
"http://loopback.example.test:8787",
"http://user@127.0.0.1:8787",
"http://127.1:8787",
"http://127.0.0.01:8787",
"http://0177.0.0.1:8787",
"http://0x7f000001:8787",
"http://2130706433:8787",
"http://[::ffff:127.0.0.1]:8787",
"http://128.0.0.1:8787",
])("rejects non-canonical or non-loopback HTTP public URL %s", (publicUrl) => {
expect(() => loadAuthenticationConfig(writeFixture(oidcConfig({ publicUrl }))))
.toThrow("authentication configuration is invalid");
});
test("rejects unknown roles and requires exactly one admin group", () => {