fix(auth): pin native auth storage operations

This commit is contained in:
2026-08-17 14:52:21 +02:00
parent 6d438f4c7e
commit cb0e873ed7
23 changed files with 3016 additions and 1385 deletions
+7 -4
View File
@@ -6,7 +6,7 @@ import { stringify } from "yaml";
import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
import { LoginFailureLimiter } from "../src/auth/routes.js";
import { prepareAuthStateRoot } from "./auth-test-fixtures.js";
import { createFixtureAuthStorageBridge, prepareAuthStateRoot } from "./auth-test-fixtures.js";
const password = "correct horse battery staple";
const passwordHash = "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4";
@@ -88,7 +88,10 @@ async function createLocalApp(options: {
THT_AUTH_CONFIG_FILE: authConfigFile,
THT_AUTH_STATE_ROOT: authStateRoot,
THT_HARNESS_DIR: "/tmp/h",
}), options.registry === undefined ? undefined : { localUserRegistry: options.registry } as any);
}), {
...(options.registry === undefined ? {} : { localUserRegistry: options.registry }),
authStorageBridgeForTest: createFixtureAuthStorageBridge(),
} as any);
cleanups.push(async () => {
await app.close();
rmSync(directory, { recursive: true, force: true });
@@ -155,7 +158,7 @@ test("remembered login uses a persistent secure cookie under an HTTPS public URL
chmodSync(usersFile, 0o600);
prepareAuthStateRoot(authStateRoot);
const config = () => loadConfig({ THT_AUTH_CONFIG_FILE: authConfigFile, THT_AUTH_STATE_ROOT: authStateRoot, THT_HARNESS_DIR: "/tmp/h" });
const first = buildApp(config());
const first = buildApp(config(), { authStorageBridgeForTest: createFixtureAuthStorageBridge() });
try {
const signedIn = await first.inject({
method: "POST",
@@ -169,7 +172,7 @@ test("remembered login uses a persistent secure cookie under an HTTPS public URL
expect(setCookie).toContain("Secure");
await first.close();
const restarted = buildApp(config());
const restarted = buildApp(config(), { authStorageBridgeForTest: createFixtureAuthStorageBridge() });
cleanups.push(async () => {
await restarted.close();
rmSync(directory, { recursive: true, force: true });