fix(auth): pin native auth storage operations

This commit is contained in:
2026-08-17 14:52:21 +02:00
parent 6d438f4c7e
commit cb0e873ed7
23 changed files with 3016 additions and 1385 deletions
+17 -5
View File
@@ -5,6 +5,7 @@ import type { FastifyInstance } from "fastify";
import { stringify } from "yaml";
import { buildApp, type BuildAppDeps } from "../src/app.js";
import { loadConfig } from "../src/config.js";
import { createFixturePosixAuthStorageBridge } from "./fixtures/posix-auth-storage-bridge.mjs";
export const localPassword = "correct horse battery staple";
export const localPasswordHash = "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4";
@@ -47,6 +48,11 @@ export function prepareAuthStateRoot(root: string): void {
}
}
/** Explicit test-only substitute for the production tht-backed POSIX storage bridge. */
export function createFixtureAuthStorageBridge() {
return createFixturePosixAuthStorageBridge();
}
/** Creates a production-local app and authenticates through the real login/session boundary. */
export async function createLocalAuthFixture(
deps?: BuildAppDeps,
@@ -82,11 +88,17 @@ export async function createLocalAuthFixture(
const authStateRoot = join(directory, "auth-state");
prepareAuthStateRoot(authStateRoot);
const app = buildApp(loadConfig({
THT_AUTH_CONFIG_FILE: authConfigFile,
THT_AUTH_STATE_ROOT: authStateRoot,
THT_HARNESS_DIR: "/tmp/h",
}), deps);
const app = buildApp(
loadConfig({
THT_AUTH_CONFIG_FILE: authConfigFile,
THT_AUTH_STATE_ROOT: authStateRoot,
THT_HARNESS_DIR: "/tmp/h",
}),
{
...deps,
authStorageBridgeForTest: deps?.authStorageBridgeForTest ?? createFixtureAuthStorageBridge(),
},
);
let downstream = 0;
app.addHook("preHandler", async () => { downstream += 1; });