fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -167,6 +167,18 @@ test("rejects unknown roles and requires exactly one admin group", () => {
|
||||
})))).toThrow("authentication configuration is invalid");
|
||||
});
|
||||
|
||||
test("caps configured group mappings at the OIDC direct-groups bound", () => {
|
||||
const mappings = Object.fromEntries(Array.from({ length: 128 }, (_unused, index) => [
|
||||
`Mapped Group ${String(index).padStart(3, "0")}`,
|
||||
index === 0 ? ["admin"] : ["user"],
|
||||
]));
|
||||
expect(loadAuthenticationConfig(writeFixture(oidcConfig({ authorization: { groupRoles: mappings } }))).value.mode)
|
||||
.toBe("oidc");
|
||||
mappings["Mapped Group overflow"] = ["user"];
|
||||
expect(() => loadAuthenticationConfig(writeFixture(oidcConfig({ authorization: { groupRoles: mappings } }))))
|
||||
.toThrow("authentication configuration is invalid");
|
||||
});
|
||||
|
||||
test("roles collapse duplicates and admin contains all administrative permissions", () => {
|
||||
expect(rolesToPermissions(["admin", "admin", "user"])).toEqual([
|
||||
"session.use",
|
||||
@@ -235,6 +247,29 @@ test("provider reloads after an atomic configuration replacement", () => {
|
||||
expect(reloaded.value.publicUrl).toBe("http://127.0.0.1:9999");
|
||||
});
|
||||
|
||||
test("loads and reloads Windows auth.yaml through the production storage bridge boundary", () => {
|
||||
const originalPlatform = process.platform;
|
||||
const windowsPath = "C:\\ProgramData\\ThothII\\auth\\auth.yaml";
|
||||
let source = stringify(localConfig());
|
||||
const readAuthConfig = vi.fn(() => Buffer.from(source));
|
||||
Object.defineProperty(process, "platform", { configurable: true, value: "win32" });
|
||||
try {
|
||||
const options = { windowsStorageBridge: { readAuthConfig } as never };
|
||||
expect(loadAuthenticationConfig(windowsPath, options).value.publicUrl).toBe("http://127.0.0.1:8080");
|
||||
const provider = createAuthenticationConfigProvider(windowsPath, options);
|
||||
const original = provider.current();
|
||||
source = stringify(localConfig({ publicUrl: "http://127.0.0.1:9999" }));
|
||||
const reloaded = provider.current();
|
||||
|
||||
expect(reloaded.value.publicUrl).toBe("http://127.0.0.1:9999");
|
||||
expect(reloaded.revision).not.toBe(original.revision);
|
||||
expect(readAuthConfig).toHaveBeenCalledTimes(3);
|
||||
expect(readAuthConfig).toHaveBeenCalledWith(windowsPath);
|
||||
} finally {
|
||||
Object.defineProperty(process, "platform", { configurable: true, value: originalPlatform });
|
||||
}
|
||||
});
|
||||
|
||||
test("provider retries when replacement occurs between its read and cache identity check", () => {
|
||||
const file = writeFixture(localConfig());
|
||||
const replacement = `${file}.replacement`;
|
||||
|
||||
Reference in New Issue
Block a user