fix(auth): bound OIDC initiation and transport

This commit is contained in:
2026-08-17 07:03:19 +02:00
parent 8573500121
commit bdabecbb63
15 changed files with 747 additions and 111 deletions
+36
View File
@@ -80,6 +80,42 @@ function bridgeForChild(child: FakeBridgeChild) {
}
describe("Windows auth-storage bridge", () => {
test("permits reservation slots only for OIDC record operations", async () => {
const requests: Array<Record<string, unknown>> = [];
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\tht.exe",
invoke: async ({ input }) => {
const request = JSON.parse(input.toString("utf8")) as Record<string, unknown>;
requests.push(request);
const operation = request.operation;
const body = operation === "create"
? { created: true }
: operation === "read"
? { found: true, contentBase64: Buffer.from("slot").toString("base64") }
: operation === "remove"
? { removed: true }
: { entries: [{ name: "slot-00.json", modifiedUnixMs: 1 }] };
return {
code: 0,
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, ...body })}\n`),
stderr: Buffer.alloc(0),
};
},
});
await expect(bridge.create("C:\\auth", "oidc", "slot-00.json", Buffer.from("slot"))).resolves.toBe(true);
await expect(bridge.read("C:\\auth", "oidc", "slot-00.json")).resolves.toEqual(Buffer.from("slot"));
await expect(bridge.list("C:\\auth", "oidc")).resolves.toEqual([
{ name: "slot-00.json", modifiedUnixMs: 1 },
]);
await expect(bridge.remove("C:\\auth", "oidc", "slot-00.json")).resolves.toBe(true);
await expect(bridge.create("C:\\auth", "sessions", "slot-00.json", Buffer.from("slot")))
.rejects.toThrow("auth_session_store_invalid");
await expect(bridge.create("C:\\auth", "oidc", "slot-64.json", Buffer.from("slot")))
.rejects.toThrow("auth_session_store_invalid");
expect(requests).toHaveLength(4);
});
test("uses hidden tht argv and sends record bytes only over bounded stdin", async () => {
const calls: Array<{ executable: string; args: readonly string[]; input: Buffer; timeoutMs: number }> = [];
const bridge = createWindowsAuthStorageBridge({