fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -5,6 +5,7 @@ import (
|
||||
"context"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
@@ -91,6 +92,65 @@ func TestProtocolCreatesReadsReplacesListsAndRemovesPrivateRecord(t *testing.T)
|
||||
}
|
||||
}
|
||||
|
||||
func TestProtocolPreflightsRootWithoutCreatingOrFollowingLinks(t *testing.T) {
|
||||
parent := privateTestRoot(t)
|
||||
missing := filepath.Join(parent, "auth")
|
||||
validated := runRequest(t, request{Version: 1, Operation: "validate-root", Root: missing})
|
||||
if !validated.Validated {
|
||||
t.Fatal("missing final root was not validated")
|
||||
}
|
||||
if _, err := os.Lstat(missing); !errors.Is(err, os.ErrNotExist) {
|
||||
t.Fatalf("validate-root mutated missing root: %v", err)
|
||||
}
|
||||
|
||||
realRoot := filepath.Join(parent, "real-auth")
|
||||
if err := safeio.EnsurePrivateDirectory(realRoot); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
linkedRoot := filepath.Join(parent, "linked-auth")
|
||||
testsupport.SymlinkOrSkip(t, realRoot, linkedRoot)
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: linkedRoot})
|
||||
if entries, err := os.ReadDir(realRoot); err != nil || len(entries) != 0 {
|
||||
t.Fatalf("linked target was mutated: entries=%v error=%v", entries, err)
|
||||
}
|
||||
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: filepath.Join(parent, "missing", "auth")})
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: missing, Directory: "sessions"})
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: filepath.Join(parent, "auth\n")})
|
||||
}
|
||||
|
||||
func TestProtocolReadsOnlyBoundedPrivateAuthConfig(t *testing.T) {
|
||||
root := privateTestRoot(t)
|
||||
filename := "auth.yaml"
|
||||
path := filepath.Join(root, filename)
|
||||
contents := []byte("version: 1\nmode: local\n")
|
||||
if err := safeio.WriteCanonicalNewPrivateFile(path, contents, 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
read := runRequest(t, request{Version: 1, Operation: "read-auth-config", Root: root, Filename: filename})
|
||||
if !read.Found || decodeContent(t, read) != string(contents) {
|
||||
t.Fatalf("read-auth-config = %#v", read)
|
||||
}
|
||||
|
||||
hardLink := filepath.Join(root, "auth-copy.yaml")
|
||||
if err := os.Link(path, hardLink); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
runRejected(t, request{Version: 1, Operation: "read-auth-config", Root: root, Filename: filename})
|
||||
if err := os.Remove(hardLink); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.Remove(path); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := safeio.WriteCanonicalNewPrivateFile(path, bytes.Repeat([]byte("x"), maximumAuthConfigBytes+1), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
runRejected(t, request{Version: 1, Operation: "read-auth-config", Root: root, Filename: filename})
|
||||
runRejected(t, request{Version: 1, Operation: "read-auth-config", Root: root, Filename: "../auth.yaml"})
|
||||
runRejected(t, request{Version: 1, Operation: "read-auth-config", Root: root, Directory: "sessions", Filename: filename})
|
||||
}
|
||||
|
||||
func TestProtocolPermitsBoundedReservationSlotsOnlyForOIDCRecords(t *testing.T) {
|
||||
root := filepath.Join(privateTestRoot(t), "auth")
|
||||
slot := "slot-00.json"
|
||||
|
||||
Reference in New Issue
Block a user