fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -30,6 +30,17 @@ test("accepts the fixed OIDC and Authentik secret references", () => {
|
||||
]));
|
||||
});
|
||||
|
||||
test.each([
|
||||
["THT_OIDC_CLIENT_SECRET", 4096],
|
||||
["THT_AUTHENTIK_API_TOKEN", 16 * 1024],
|
||||
])("enforces the shared exact value boundary for %s", (name, maximum) => {
|
||||
expect(loadSecretBundle(bundle(`${name}=${"x".repeat(maximum)}\n`)).get(name)).toHaveLength(maximum);
|
||||
expect(() => loadSecretBundle(bundle(`${name}=${"x".repeat(maximum + 1)}\n`)))
|
||||
.toThrow("secret bundle is unavailable");
|
||||
expect(() => loadSecretBundle(bundle(`${name}=invalid\u0000secret\n`)))
|
||||
.toThrow("secret bundle is unavailable");
|
||||
});
|
||||
|
||||
test.each([
|
||||
["duplicate", "THT_MODEL_API_KEY=a\nTHT_MODEL_API_KEY=b\n"],
|
||||
["unknown", "UNKNOWN_KEY=x\n"],
|
||||
|
||||
Reference in New Issue
Block a user