fix(auth): make diagnostics bounded and portable

This commit is contained in:
2026-08-17 12:19:19 +02:00
parent 7cfbee36fa
commit be1724890a
23 changed files with 1088 additions and 116 deletions
+11
View File
@@ -30,6 +30,17 @@ test("accepts the fixed OIDC and Authentik secret references", () => {
]));
});
test.each([
["THT_OIDC_CLIENT_SECRET", 4096],
["THT_AUTHENTIK_API_TOKEN", 16 * 1024],
])("enforces the shared exact value boundary for %s", (name, maximum) => {
expect(loadSecretBundle(bundle(`${name}=${"x".repeat(maximum)}\n`)).get(name)).toHaveLength(maximum);
expect(() => loadSecretBundle(bundle(`${name}=${"x".repeat(maximum + 1)}\n`)))
.toThrow("secret bundle is unavailable");
expect(() => loadSecretBundle(bundle(`${name}=invalid\u0000secret\n`)))
.toThrow("secret bundle is unavailable");
});
test.each([
["duplicate", "THT_MODEL_API_KEY=a\nTHT_MODEL_API_KEY=b\n"],
["unknown", "UNKNOWN_KEY=x\n"],