fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 17:25:26 +02:00
parent 30ee9433dc
commit ef244ab56d
18 changed files with 670 additions and 68 deletions
+16
View File
@@ -159,3 +159,19 @@ test.each([
await expect(validateWorkspace(workspace)).rejects.toThrow("invalid authentication diagnostics");
});
test("rejects a workspace claimed activatable when authentication is not ready", async () => {
server.use(http.post("/api/workspaces/validate", () => HttpResponse.json({
workspace,
contract: {},
activatable: true,
diagnostics: [],
authentication: {
ready: false,
mode: "oidc",
checks: [{ level: "error", code: "oidc_secret_missing", message: "Authentication is unavailable." }],
},
})));
await expect(validateWorkspace(workspace)).rejects.toThrow("invalid diagnostic result");
});
+5 -1
View File
@@ -291,7 +291,11 @@ function decodeWorkspaceDiagnostics(value: unknown): WorkspaceDiagnostics {
...(diagnostic.field === undefined ? {} : { field: diagnostic.field }),
};
});
return { activatable: source.activatable, diagnostics, authentication: decodeAuthentication(source.authentication) };
const authentication = decodeAuthentication(source.authentication);
if (source.activatable && !authentication.ready) {
throw new Error("Workspace API returned an invalid diagnostic result");
}
return { activatable: source.activatable, diagnostics, authentication };
}
function exactObject(value: unknown, keys: readonly string[]): Record<string, unknown> | undefined {