fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 17:25:26 +02:00
parent 30ee9433dc
commit ef244ab56d
18 changed files with 670 additions and 68 deletions
@@ -250,6 +250,33 @@ test("renders one authentication section with configured-group errors and no unm
expect(within(section).queryByText(/unmapped/i)).not.toBeInTheDocument();
});
test("clears a previous authentication result as soon as validation is retried", async () => {
const user = userEvent.setup();
let calls = 0;
let releaseRetry!: () => void;
const retryStarted = new Promise<void>((resolve) => { releaseRetry = resolve; });
server.use(http.post("/api/workspaces/validate", async () => {
calls += 1;
if (calls > 1) await retryStarted;
return HttpResponse.json({
workspace, contract: {}, activatable: true, diagnostics: [], authentication: readyAuthentication,
});
}));
renderManager();
await user.click(await screen.findByRole("button", { name: "PSD Clinical" }));
const button = screen.getByRole("button", { name: "Validate workspace source" });
await user.click(button);
expect(await screen.findByTestId("workspace-authentication")).toBeVisible();
await user.click(button);
await waitFor(() => expect(calls).toBe(2));
expect(screen.queryByTestId("workspace-authentication")).not.toBeInTheDocument();
releaseRetry();
expect(await screen.findByTestId("workspace-authentication")).toBeVisible();
});
test("never renders a hostile authentication field rejected by the API decoder", async () => {
const user = userEvent.setup();
const attacker = "attacker-field-SENTINEL";
+2
View File
@@ -194,6 +194,7 @@ export function WorkspaceManager({
if (!guard) return;
setBusyAction("validate");
clearGlobalMessages();
setAuthentication(undefined);
setValidationNotice(undefined);
setValidationDiagnostics([]);
try {
@@ -217,6 +218,7 @@ export function WorkspaceManager({
if (!guard) return;
setBusyAction("test");
clearGlobalMessages();
setAuthentication(undefined);
setConnectionNotice(undefined);
setConnectionDiagnostics([]);
try {