fix(auth): pin native auth storage operations
This commit is contained in:
@@ -14,7 +14,7 @@ import {
|
||||
import { mkdtempSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { afterEach, describe, expect, test } from "vitest";
|
||||
import { afterEach, describe, expect, test, vi } from "vitest";
|
||||
import { createLocalUserRegistry } from "../src/auth/local-registry.js";
|
||||
|
||||
const password = "correct horse battery staple";
|
||||
@@ -204,4 +204,28 @@ describe("local user registry", () => {
|
||||
|
||||
await expect(registry.findByUsername("admin")).resolves.toMatchObject({ displayName: "Owner" });
|
||||
});
|
||||
|
||||
test("routes native Windows users.yaml loading only through the bounded auth-storage bridge", async () => {
|
||||
const usersPath = "C:\\ProgramData\\ThothII\\auth\\users.yaml";
|
||||
const readLocalUsers = vi.fn(async (path: string) => {
|
||||
expect(path).toBe(usersPath);
|
||||
return Buffer.from(registryYaml(userYaml({ displayName: "Bridge administrator" })), "utf8");
|
||||
});
|
||||
const originalPlatform = Object.getOwnPropertyDescriptor(process, "platform");
|
||||
if (!originalPlatform) throw new Error("platform descriptor unavailable");
|
||||
Object.defineProperty(process, "platform", { configurable: true, value: "win32" });
|
||||
try {
|
||||
const registry = createLocalUserRegistry(usersPath, { windowsStorageBridge: { readLocalUsers } } as never);
|
||||
await expect(registry.findByUsername("ADMIN")).resolves.toMatchObject({
|
||||
id: adminId,
|
||||
displayName: "Bridge administrator",
|
||||
});
|
||||
await expect(registry.hasEnabledAdmin()).resolves.toBe(true);
|
||||
// Windows reloads from the bridge on every registry observation so an atomic host
|
||||
// replacement cannot be missed between authorization checks.
|
||||
expect(readLocalUsers).toHaveBeenCalledTimes(2);
|
||||
} finally {
|
||||
Object.defineProperty(process, "platform", originalPlatform);
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user