fix(auth): harden unified diagnostic execution
This commit is contained in:
@@ -159,3 +159,19 @@ test.each([
|
||||
|
||||
await expect(validateWorkspace(workspace)).rejects.toThrow("invalid authentication diagnostics");
|
||||
});
|
||||
|
||||
test("rejects a workspace claimed activatable when authentication is not ready", async () => {
|
||||
server.use(http.post("/api/workspaces/validate", () => HttpResponse.json({
|
||||
workspace,
|
||||
contract: {},
|
||||
activatable: true,
|
||||
diagnostics: [],
|
||||
authentication: {
|
||||
ready: false,
|
||||
mode: "oidc",
|
||||
checks: [{ level: "error", code: "oidc_secret_missing", message: "Authentication is unavailable." }],
|
||||
},
|
||||
})));
|
||||
|
||||
await expect(validateWorkspace(workspace)).rejects.toThrow("invalid diagnostic result");
|
||||
});
|
||||
|
||||
@@ -291,7 +291,11 @@ function decodeWorkspaceDiagnostics(value: unknown): WorkspaceDiagnostics {
|
||||
...(diagnostic.field === undefined ? {} : { field: diagnostic.field }),
|
||||
};
|
||||
});
|
||||
return { activatable: source.activatable, diagnostics, authentication: decodeAuthentication(source.authentication) };
|
||||
const authentication = decodeAuthentication(source.authentication);
|
||||
if (source.activatable && !authentication.ready) {
|
||||
throw new Error("Workspace API returned an invalid diagnostic result");
|
||||
}
|
||||
return { activatable: source.activatable, diagnostics, authentication };
|
||||
}
|
||||
|
||||
function exactObject(value: unknown, keys: readonly string[]): Record<string, unknown> | undefined {
|
||||
|
||||
Reference in New Issue
Block a user