fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -144,6 +144,42 @@ describe("Windows auth-storage bridge", () => {
|
||||
expect(calls[0].timeoutMs).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
test("validates Windows roots and reads auth.yaml through the same bounded hidden bridge", async () => {
|
||||
const asyncCalls: Array<Record<string, unknown>> = [];
|
||||
const syncCalls: Array<{ args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }> = [];
|
||||
const config = Buffer.from("version: 1\nmode: local\n");
|
||||
const bridge = createWindowsAuthStorageBridge({
|
||||
thtExecutable: "C:\\Program Files\\ThothII\\tht.exe",
|
||||
invoke: async ({ input }) => {
|
||||
asyncCalls.push(JSON.parse(input.toString("utf8")) as Record<string, unknown>);
|
||||
return { code: 0, stdout: Buffer.from('{"version":1,"ok":true,"validated":true}\n'), stderr: Buffer.alloc(0) };
|
||||
},
|
||||
invokeSync: (call: { args: readonly string[]; input: Buffer; timeoutMs: number; maximumOutputBytes: number }) => {
|
||||
syncCalls.push(call);
|
||||
return {
|
||||
code: 0,
|
||||
stdout: Buffer.from(`${JSON.stringify({ version: 1, ok: true, found: true, contentBase64: config.toString("base64") })}\n`),
|
||||
stderr: Buffer.alloc(0),
|
||||
};
|
||||
},
|
||||
} as never) as unknown as {
|
||||
validateRoot(root: string): Promise<void>;
|
||||
readAuthConfig(path: string): Buffer;
|
||||
};
|
||||
|
||||
await expect(bridge.validateRoot(root)).resolves.toBeUndefined();
|
||||
expect(bridge.readAuthConfig(`${root}\\auth.yaml`)).toEqual(config);
|
||||
expect(asyncCalls).toEqual([{ version: 1, operation: "validate-root", root }]);
|
||||
expect(JSON.parse(syncCalls[0]!.input.toString("utf8"))).toEqual({
|
||||
version: 1, operation: "read-auth-config", root, filename: "auth.yaml",
|
||||
});
|
||||
expect(syncCalls[0]!.args).toEqual(["_auth-storage"]);
|
||||
expect(syncCalls[0]!.timeoutMs).toBe(5_000);
|
||||
expect(syncCalls[0]!.maximumOutputBytes).toBeGreaterThan(1024 * 1024);
|
||||
expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(root);
|
||||
expect(JSON.stringify(syncCalls[0]!.args)).not.toContain(config.toString("utf8"));
|
||||
});
|
||||
|
||||
test.each([
|
||||
{ label: "nonzero", result: { code: 1, stdout: Buffer.from('{"version":1,"ok":true}\n'), stderr: Buffer.from("secret") } },
|
||||
{ label: "malformed stdout", result: { code: 0, stdout: Buffer.from("not-json"), stderr: Buffer.alloc(0) } },
|
||||
|
||||
Reference in New Issue
Block a user