test: cover user-owned session security boundaries

This commit is contained in:
User
2026-07-16 19:16:58 +02:00
parent 7a65fc80a2
commit ccb3cf4aa9
5 changed files with 160 additions and 2 deletions
+14
View File
@@ -51,6 +51,20 @@ test("upstream mode accepts only normalized proxy principal headers", async () =
});
});
test("upstream mode rejects legacy client identity headers without proxy principal fields", async () => {
const app = Fastify();
app.addHook("preHandler", authPreHandler("upstream"));
app.get("/me", async (req) => getPrincipal(req));
for (const headers of [
{ "x-authenticated-user": "mallory" },
{ "x-mock-user": "mallory" },
{ "x-authenticated-user": "mallory", "x-mock-user": "mallory" },
]) {
expect((await app.inject({ method: "GET", url: "/me", headers })).statusCode).toBe(401);
}
});
test("local identity expands tilde homes and restores private POSIX permissions", () => {
expect(expandLocalHome("~/thoth-test", "/home/tester")).toBe("/home/tester/thoth-test");
expect(expandLocalHome("~", "/home/tester")).toBe("/home/tester");