fix(auth): make diagnostics bounded and portable

This commit is contained in:
2026-08-17 12:19:19 +02:00
parent 7cfbee36fa
commit be1724890a
23 changed files with 1088 additions and 116 deletions
+35
View File
@@ -167,6 +167,18 @@ test("rejects unknown roles and requires exactly one admin group", () => {
})))).toThrow("authentication configuration is invalid");
});
test("caps configured group mappings at the OIDC direct-groups bound", () => {
const mappings = Object.fromEntries(Array.from({ length: 128 }, (_unused, index) => [
`Mapped Group ${String(index).padStart(3, "0")}`,
index === 0 ? ["admin"] : ["user"],
]));
expect(loadAuthenticationConfig(writeFixture(oidcConfig({ authorization: { groupRoles: mappings } }))).value.mode)
.toBe("oidc");
mappings["Mapped Group overflow"] = ["user"];
expect(() => loadAuthenticationConfig(writeFixture(oidcConfig({ authorization: { groupRoles: mappings } }))))
.toThrow("authentication configuration is invalid");
});
test("roles collapse duplicates and admin contains all administrative permissions", () => {
expect(rolesToPermissions(["admin", "admin", "user"])).toEqual([
"session.use",
@@ -235,6 +247,29 @@ test("provider reloads after an atomic configuration replacement", () => {
expect(reloaded.value.publicUrl).toBe("http://127.0.0.1:9999");
});
test("loads and reloads Windows auth.yaml through the production storage bridge boundary", () => {
const originalPlatform = process.platform;
const windowsPath = "C:\\ProgramData\\ThothII\\auth\\auth.yaml";
let source = stringify(localConfig());
const readAuthConfig = vi.fn(() => Buffer.from(source));
Object.defineProperty(process, "platform", { configurable: true, value: "win32" });
try {
const options = { windowsStorageBridge: { readAuthConfig } as never };
expect(loadAuthenticationConfig(windowsPath, options).value.publicUrl).toBe("http://127.0.0.1:8080");
const provider = createAuthenticationConfigProvider(windowsPath, options);
const original = provider.current();
source = stringify(localConfig({ publicUrl: "http://127.0.0.1:9999" }));
const reloaded = provider.current();
expect(reloaded.value.publicUrl).toBe("http://127.0.0.1:9999");
expect(reloaded.revision).not.toBe(original.revision);
expect(readAuthConfig).toHaveBeenCalledTimes(3);
expect(readAuthConfig).toHaveBeenCalledWith(windowsPath);
} finally {
Object.defineProperty(process, "platform", { configurable: true, value: originalPlatform });
}
});
test("provider retries when replacement occurs between its read and cache identity check", () => {
const file = writeFixture(localConfig());
const replacement = `${file}.replacement`;