fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 17:25:26 +02:00
parent 30ee9433dc
commit ef244ab56d
18 changed files with 670 additions and 68 deletions
@@ -6,6 +6,7 @@ import type { AuthDiagnoser, AuthDiagnostics } from "../src/auth/diagnostics.js"
import {
configuredSecretValues,
createConfiguredAuthDiagnoser,
runConfiguredDiagnosticCommand,
runDiagnosticCommand,
} from "../src/auth/diagnostic-command.js";
import type { AppConfig } from "../src/config.js";
@@ -201,6 +202,59 @@ test("redacts every parsed mounted secret before writing an interactive prompt",
expect(stdout.join("") + stderr.join("")).not.toContain(legacyVectorSecret);
});
test("includes every nested Pi authentication scalar in the direct-command redaction corpus", () => {
const piApiKey = "pi-api-key-SENTINEL";
const piAccessToken = "pi-access-token-SENTINEL";
const piAuthFile = secretBundle(JSON.stringify({
providers: {
anthropic: {
key: piApiKey,
oauth: { access: piAccessToken, expires: 1_800_000_000 },
},
},
}));
const config = {
secretsFile: secretBundle("THT_MODEL_API_KEY=model-secret\n"),
secretFiles: {},
piAuthFile,
} as AppConfig;
expect(configuredSecretValues(config)).toEqual(expect.arrayContaining([
"model-secret", piApiKey, piAccessToken,
]));
});
test("fails closed when any declared direct-command secret source cannot be loaded", () => {
const root = mkdtempSync(join(tmpdir(), "thothii-diagnostic-command-missing-"));
roots.push(root);
const config = {
secretsFile: secretBundle("THT_MODEL_API_KEY=model-secret\n"),
secretFiles: {},
piAuthFile: join(root, "missing-pi-auth.json"),
} as AppConfig;
expect(() => configuredSecretValues(config)).toThrow("diagnostic secret corpus is unavailable");
});
test("suppresses interactive prompt forwarding when the production secret preflight is incomplete", async () => {
const root = mkdtempSync(join(tmpdir(), "thothii-diagnostic-command-preflight-"));
roots.push(root);
const stdout: string[] = [];
const stderr: string[] = [];
const exitCode = await runConfiguredDiagnosticCommand(
["--json", "--interactive"],
{ NODE_ENV: "test", AUTH_MODE: "none", THT_PI_AUTH_FILE: join(root, "missing-auth.json") },
(line) => stdout.push(line),
(line) => stderr.push(line),
);
expect(exitCode).toBe(1);
expect(stderr).toEqual([]);
expect(stdout).toHaveLength(1);
expect(JSON.parse(stdout[0])).toMatchObject({ ready: false, checks: [{ code: "auth_config_invalid" }] });
});
test.each([
{
ready: true, mode: "oidc", checks: [{ level: "error", code: "oidc_secret_missing", message: "attacker-message" }],
+7
View File
@@ -47,6 +47,13 @@ test("loadConfig accepts container listening and runtime paths", () => {
});
});
test("loadConfig accepts only an absolute mounted Pi authentication source", () => {
expect(loadConfig({ THT_PI_AUTH_FILE: "/home/thoth/.pi/agent/auth.json" }).piAuthFile)
.toBe("/home/thoth/.pi/agent/auth.json");
expect(() => loadConfig({ THT_PI_AUTH_FILE: "relative/auth.json" }))
.toThrow("Pi authentication source configuration is invalid");
});
test("loadConfig keeps local development defaults", () => {
expect(loadConfig({})).toMatchObject({
host: "127.0.0.1",