test: cover user-owned session security boundaries
This commit is contained in:
@@ -51,6 +51,20 @@ test("upstream mode accepts only normalized proxy principal headers", async () =
|
||||
});
|
||||
});
|
||||
|
||||
test("upstream mode rejects legacy client identity headers without proxy principal fields", async () => {
|
||||
const app = Fastify();
|
||||
app.addHook("preHandler", authPreHandler("upstream"));
|
||||
app.get("/me", async (req) => getPrincipal(req));
|
||||
|
||||
for (const headers of [
|
||||
{ "x-authenticated-user": "mallory" },
|
||||
{ "x-mock-user": "mallory" },
|
||||
{ "x-authenticated-user": "mallory", "x-mock-user": "mallory" },
|
||||
]) {
|
||||
expect((await app.inject({ method: "GET", url: "/me", headers })).statusCode).toBe(401);
|
||||
}
|
||||
});
|
||||
|
||||
test("local identity expands tilde homes and restores private POSIX permissions", () => {
|
||||
expect(expandLocalHome("~/thoth-test", "/home/tester")).toBe("/home/tester/thoth-test");
|
||||
expect(expandLocalHome("~", "/home/tester")).toBe("/home/tester");
|
||||
|
||||
Reference in New Issue
Block a user