fix(auth): harden unified diagnostic execution
This commit is contained in:
@@ -6,6 +6,7 @@ import type { AuthDiagnoser, AuthDiagnostics } from "../src/auth/diagnostics.js"
|
||||
import {
|
||||
configuredSecretValues,
|
||||
createConfiguredAuthDiagnoser,
|
||||
runConfiguredDiagnosticCommand,
|
||||
runDiagnosticCommand,
|
||||
} from "../src/auth/diagnostic-command.js";
|
||||
import type { AppConfig } from "../src/config.js";
|
||||
@@ -201,6 +202,59 @@ test("redacts every parsed mounted secret before writing an interactive prompt",
|
||||
expect(stdout.join("") + stderr.join("")).not.toContain(legacyVectorSecret);
|
||||
});
|
||||
|
||||
test("includes every nested Pi authentication scalar in the direct-command redaction corpus", () => {
|
||||
const piApiKey = "pi-api-key-SENTINEL";
|
||||
const piAccessToken = "pi-access-token-SENTINEL";
|
||||
const piAuthFile = secretBundle(JSON.stringify({
|
||||
providers: {
|
||||
anthropic: {
|
||||
key: piApiKey,
|
||||
oauth: { access: piAccessToken, expires: 1_800_000_000 },
|
||||
},
|
||||
},
|
||||
}));
|
||||
const config = {
|
||||
secretsFile: secretBundle("THT_MODEL_API_KEY=model-secret\n"),
|
||||
secretFiles: {},
|
||||
piAuthFile,
|
||||
} as AppConfig;
|
||||
|
||||
expect(configuredSecretValues(config)).toEqual(expect.arrayContaining([
|
||||
"model-secret", piApiKey, piAccessToken,
|
||||
]));
|
||||
});
|
||||
|
||||
test("fails closed when any declared direct-command secret source cannot be loaded", () => {
|
||||
const root = mkdtempSync(join(tmpdir(), "thothii-diagnostic-command-missing-"));
|
||||
roots.push(root);
|
||||
const config = {
|
||||
secretsFile: secretBundle("THT_MODEL_API_KEY=model-secret\n"),
|
||||
secretFiles: {},
|
||||
piAuthFile: join(root, "missing-pi-auth.json"),
|
||||
} as AppConfig;
|
||||
|
||||
expect(() => configuredSecretValues(config)).toThrow("diagnostic secret corpus is unavailable");
|
||||
});
|
||||
|
||||
test("suppresses interactive prompt forwarding when the production secret preflight is incomplete", async () => {
|
||||
const root = mkdtempSync(join(tmpdir(), "thothii-diagnostic-command-preflight-"));
|
||||
roots.push(root);
|
||||
const stdout: string[] = [];
|
||||
const stderr: string[] = [];
|
||||
|
||||
const exitCode = await runConfiguredDiagnosticCommand(
|
||||
["--json", "--interactive"],
|
||||
{ NODE_ENV: "test", AUTH_MODE: "none", THT_PI_AUTH_FILE: join(root, "missing-auth.json") },
|
||||
(line) => stdout.push(line),
|
||||
(line) => stderr.push(line),
|
||||
);
|
||||
|
||||
expect(exitCode).toBe(1);
|
||||
expect(stderr).toEqual([]);
|
||||
expect(stdout).toHaveLength(1);
|
||||
expect(JSON.parse(stdout[0])).toMatchObject({ ready: false, checks: [{ code: "auth_config_invalid" }] });
|
||||
});
|
||||
|
||||
test.each([
|
||||
{
|
||||
ready: true, mode: "oidc", checks: [{ level: "error", code: "oidc_secret_missing", message: "attacker-message" }],
|
||||
|
||||
@@ -47,6 +47,13 @@ test("loadConfig accepts container listening and runtime paths", () => {
|
||||
});
|
||||
});
|
||||
|
||||
test("loadConfig accepts only an absolute mounted Pi authentication source", () => {
|
||||
expect(loadConfig({ THT_PI_AUTH_FILE: "/home/thoth/.pi/agent/auth.json" }).piAuthFile)
|
||||
.toBe("/home/thoth/.pi/agent/auth.json");
|
||||
expect(() => loadConfig({ THT_PI_AUTH_FILE: "relative/auth.json" }))
|
||||
.toThrow("Pi authentication source configuration is invalid");
|
||||
});
|
||||
|
||||
test("loadConfig keeps local development defaults", () => {
|
||||
expect(loadConfig({})).toMatchObject({
|
||||
host: "127.0.0.1",
|
||||
|
||||
Reference in New Issue
Block a user