fix(auth): make diagnostics bounded and portable

This commit is contained in:
2026-08-17 12:19:19 +02:00
parent 7cfbee36fa
commit be1724890a
23 changed files with 1088 additions and 116 deletions
+36
View File
@@ -144,6 +144,42 @@ describe("Windows auth-storage bridge", () => {
expect(calls[0].timeoutMs).toBeGreaterThan(0);
});
test("validates Windows roots and reads auth.yaml through the same bounded hidden bridge", async () => {
const asyncCalls: Array<Record<string, unknown>> = [];
const syncCalls: Array<{ args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }> = [];
const config = Buffer.from("version: 1\nmode: local\n");
const bridge = createWindowsAuthStorageBridge({
thtExecutable: "C:\\Program Files\\ThothII\\tht.exe",
invoke: async ({ input }) => {
asyncCalls.push(JSON.parse(input.toString("utf8")) as Record<string, unknown>);
return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"validated":true}\n'), stderr: Buffer.alloc(0) };
},
invokeSync: (call: { args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }) => {
syncCalls.push(call);
return {
code: 0,
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, found: true, contentBase64: config.toString("base64") })}\n`),
stderr: Buffer.alloc(0),
};
},
} as never) as unknown as {
validateRoot(root: string): Promise<void>;
readAuthConfig(path: string): Buffer;
};
await expect(bridge.validateRoot(root)).resolves.toBeUndefined();
expect(bridge.readAuthConfig(`${root}\\auth.yaml`)).toEqual(config);
expect(asyncCalls).toEqual([{ version: 1, operation: "validate-root", root }]);
expect(JSON.parse(syncCalls[0]!.input.toString("utf8"))).toEqual({
version: 1, operation: "read-auth-config", root, filename: "auth.yaml",
});
expect(syncCalls[0]!.args).toEqual(["_auth-storage"]);
expect(syncCalls[0]!.timeoutMs).toBe(5_000);
expect(syncCalls[0]!.maximumOutputBytes).toBeGreaterThan(1024 * 1024);
expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(root);
expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(config.toString("utf8"));
});
test.each([
{ label: "nonzero", result: { code: 1, stdout: Buffer.from('{"version":1,"ok":true}\n'), stderr: Buffer.from("secret") } },
{ label: "malformed stdout", result: { code: 0, stdout: Buffer.from("not-json"), stderr: Buffer.alloc(0) } },