fix(auth): bound OIDC initiation and transport
This commit is contained in:
@@ -80,6 +80,42 @@ function bridgeForChild(child: FakeBridgeChild) {
|
||||
}
|
||||
|
||||
describe("Windows auth-storage bridge", () => {
|
||||
test("permits reservation slots only for OIDC record operations", async () => {
|
||||
const requests: Array<Record<string, unknown>> = [];
|
||||
const bridge = createWindowsAuthStorageBridge({
|
||||
thtExecutable: "C:\\tht.exe",
|
||||
invoke: async ({ input }) => {
|
||||
const request = JSON.parse(input.toString("utf8")) as Record<string, unknown>;
|
||||
requests.push(request);
|
||||
const operation = request.operation;
|
||||
const body = operation === "create"
|
||||
? { created: true }
|
||||
: operation === "read"
|
||||
? { found: true, contentBase64: Buffer.from("slot").toString("base64") }
|
||||
: operation === "remove"
|
||||
? { removed: true }
|
||||
: { entries: [{ name: "slot-00.json", modifiedUnixMs: 1 }] };
|
||||
return {
|
||||
code: 0,
|
||||
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, ...body })}\n`),
|
||||
stderr: Buffer.alloc(0),
|
||||
};
|
||||
},
|
||||
});
|
||||
|
||||
await expect(bridge.create("C:\\auth", "oidc", "slot-00.json", Buffer.from("slot"))).resolves.toBe(true);
|
||||
await expect(bridge.read("C:\\auth", "oidc", "slot-00.json")).resolves.toEqual(Buffer.from("slot"));
|
||||
await expect(bridge.list("C:\\auth", "oidc")).resolves.toEqual([
|
||||
{ name: "slot-00.json", modifiedUnixMs: 1 },
|
||||
]);
|
||||
await expect(bridge.remove("C:\\auth", "oidc", "slot-00.json")).resolves.toBe(true);
|
||||
await expect(bridge.create("C:\\auth", "sessions", "slot-00.json", Buffer.from("slot")))
|
||||
.rejects.toThrow("auth_session_store_invalid");
|
||||
await expect(bridge.create("C:\\auth", "oidc", "slot-64.json", Buffer.from("slot")))
|
||||
.rejects.toThrow("auth_session_store_invalid");
|
||||
expect(requests).toHaveLength(4);
|
||||
});
|
||||
|
||||
test("uses hidden tht argv and sends record bytes only over bounded stdin", async () => {
|
||||
const calls: Array<{ executable: string; args: readonly string[]; input: Buffer; timeoutMs: number }> = [];
|
||||
const bridge = createWindowsAuthStorageBridge({
|
||||
|
||||
Reference in New Issue
Block a user