fix(workspaces): align postgres connection diagnostics
This commit is contained in:
@@ -60,6 +60,40 @@ function registryYaml(role: "user" | "admin", passwordHash = validPasswordHash):
|
||||
].join("\n");
|
||||
}
|
||||
|
||||
test("reports upstream authentication ready when its protected session root is valid", async () => {
|
||||
const report = await createAuthDiagnoser({
|
||||
authMode: "upstream",
|
||||
authStateRoot: "/safe/auth-state",
|
||||
sessionRootValidator: acceptSessionRoot,
|
||||
}).inspect({ live: true });
|
||||
|
||||
expect(report).toEqual({
|
||||
ready: true,
|
||||
mode: "upstream",
|
||||
checks: [{ level: "info", code: "auth_ready", message: "Authentication is ready." }],
|
||||
});
|
||||
});
|
||||
|
||||
test("upstream authentication still fails when its protected session root is invalid", async () => {
|
||||
const sentinel = "synthetic-upstream-session-root-secret";
|
||||
const report = await createAuthDiagnoser({
|
||||
authMode: "upstream",
|
||||
authStateRoot: "/safe/auth-state",
|
||||
sessionRootValidator: async () => { throw new Error(sentinel); },
|
||||
}).inspect({ live: true });
|
||||
|
||||
expect(report).toEqual({
|
||||
ready: false,
|
||||
mode: "upstream",
|
||||
checks: [{
|
||||
level: "error",
|
||||
code: "auth_session_store_invalid",
|
||||
message: "The authentication session store is invalid.",
|
||||
}],
|
||||
});
|
||||
expect(JSON.stringify(report)).not.toContain(sentinel);
|
||||
});
|
||||
|
||||
test("reports deterministic live OIDC checks and silently ignores unrelated groups", async () => {
|
||||
const oidcDiagnose = vi.fn(async () => undefined);
|
||||
const fetch = vi.fn<typeof globalThis.fetch>(async (input) => {
|
||||
|
||||
@@ -205,8 +205,9 @@ test("concrete DWH direct diagnostics authenticate, verify resource identity, an
|
||||
const passwordFile = join(root, "password");
|
||||
await writeFile(passwordFile, "password-value");
|
||||
const end = vi.fn(async () => undefined);
|
||||
const query = vi.fn(async () => ({ rows: [{ database: "warehouse", schema: "datawarehouse" }] }));
|
||||
const connect = vi.fn(async () => ({
|
||||
query: vi.fn(async () => ({ rows: [{ database: "warehouse", schema: "datawarehouse" }] })),
|
||||
query,
|
||||
end,
|
||||
}));
|
||||
try {
|
||||
@@ -219,6 +220,88 @@ test("concrete DWH direct diagnostics authenticate, verify resource identity, an
|
||||
});
|
||||
expect(result).toMatchObject({ resolved: true, authenticated: true, tlsVerified: true });
|
||||
expect(connect).toHaveBeenCalledWith(expect.objectContaining({ credentialFile: passwordFile }));
|
||||
expect(query).toHaveBeenCalledWith(
|
||||
expect.stringContaining("pg_catalog.has_schema_privilege"),
|
||||
["datawarehouse"],
|
||||
);
|
||||
expect(query.mock.calls[0]?.[0]).toContain("$1");
|
||||
expect(query.mock.calls[0]?.[0]).not.toContain('"datawarehouse"');
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
} finally {
|
||||
await rm(root, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("concrete DWH direct diagnostics disable TLS when no TLS binding is declared", async () => {
|
||||
const root = await mkdtemp(join(tmpdir(), "thoth-diagnostic-plain-"));
|
||||
const passwordFile = join(root, "password");
|
||||
await writeFile(passwordFile, "password-value");
|
||||
const connect = vi.fn(async () => undefined);
|
||||
const query = vi.fn(async () => ({ rows: [{ database: "warehouse", schema: "datawarehouse" }] }));
|
||||
const end = vi.fn(async () => undefined);
|
||||
const createPostgresClient = vi.fn(() => ({ connect, query, end }));
|
||||
try {
|
||||
const adapter = createConcreteDiagnosticAdapters({ createPostgresClient });
|
||||
await adapter.probeConnector({
|
||||
role: "dwh", transport: "postgres_direct", host: "127.0.0.1", port: 5432,
|
||||
user: "reader", credentialFile: passwordFile,
|
||||
resource: { database: "warehouse", schema: "datawarehouse" },
|
||||
timeoutMs: 1_000, signal: new AbortController().signal,
|
||||
});
|
||||
expect(createPostgresClient).toHaveBeenCalledWith(expect.objectContaining({ ssl: false }));
|
||||
expect(connect).toHaveBeenCalledOnce();
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
} finally {
|
||||
await rm(root, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("concrete DWH direct diagnostics use strict TLS only for explicit TLS bindings", async () => {
|
||||
const root = await mkdtemp(join(tmpdir(), "thoth-diagnostic-tls-"));
|
||||
const passwordFile = join(root, "password");
|
||||
const caFile = join(root, "ca.pem");
|
||||
await writeFile(passwordFile, "password-value");
|
||||
await writeFile(caFile, "test-ca");
|
||||
const connect = vi.fn(async () => undefined);
|
||||
const query = vi.fn(async () => ({ rows: [{ database: "warehouse", schema: "datawarehouse" }] }));
|
||||
const end = vi.fn(async () => undefined);
|
||||
const createPostgresClient = vi.fn(() => ({ connect, query, end }));
|
||||
try {
|
||||
const adapter = createConcreteDiagnosticAdapters({ createPostgresClient });
|
||||
await adapter.probeConnector({
|
||||
role: "dwh", transport: "postgres_direct", host: "dwh.example.test", port: 5432,
|
||||
user: "reader", credentialFile: passwordFile, tlsCaFile: caFile,
|
||||
tlsServername: "dwh.example.test",
|
||||
resource: { database: "warehouse", schema: "datawarehouse" },
|
||||
timeoutMs: 1_000, signal: new AbortController().signal,
|
||||
});
|
||||
expect(createPostgresClient).toHaveBeenCalledWith(expect.objectContaining({
|
||||
ssl: { ca: "test-ca", servername: "dwh.example.test", rejectUnauthorized: true },
|
||||
}));
|
||||
expect(connect).toHaveBeenCalledOnce();
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
} finally {
|
||||
await rm(root, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test("concrete DWH direct diagnostics fail closed when the declared schema is inaccessible", async () => {
|
||||
const root = await mkdtemp(join(tmpdir(), "thoth-diagnostic-schema-"));
|
||||
const passwordFile = join(root, "password");
|
||||
await writeFile(passwordFile, "CANARY-DATABASE-SECRET");
|
||||
const end = vi.fn(async () => undefined);
|
||||
const connect = vi.fn(async () => ({
|
||||
query: vi.fn(async () => ({ rows: [{ database: "warehouse", schema: null }] })),
|
||||
end,
|
||||
}));
|
||||
try {
|
||||
const adapter = createConcreteDiagnosticAdapters({ databaseClient: { connect } });
|
||||
await expect(adapter.probeConnector({
|
||||
role: "dwh", transport: "postgres_direct", host: "127.0.0.1", port: 5432,
|
||||
user: "reader", credentialFile: passwordFile,
|
||||
resource: { database: "warehouse", schema: "datawarehouse" },
|
||||
timeoutMs: 1_000, signal: new AbortController().signal,
|
||||
})).rejects.toThrow("direct probe failed");
|
||||
expect(end).toHaveBeenCalledOnce();
|
||||
} finally {
|
||||
await rm(root, { recursive: true, force: true });
|
||||
|
||||
Reference in New Issue
Block a user