fix(auth): harden unified diagnostic execution
This commit is contained in:
@@ -53,6 +53,9 @@ if (secretTargets.join(",") !== expectedSecrets.join(",")) {
|
||||
if (core.environment?.THT_SECRETS_FILE !== "/run/secrets/thothii.secrets") {
|
||||
throw new Error(`${name}: core does not use the canonical /run/secrets bundle path`);
|
||||
}
|
||||
if (core.environment?.THT_PI_AUTH_FILE !== "/home/thoth/.pi/agent/auth.json") {
|
||||
throw new Error(`${name}: core does not declare the mounted Pi authentication source`);
|
||||
}
|
||||
if ((config.services.frontend?.secrets || []).length !== 0) {
|
||||
throw new Error(`${name}: frontend must not receive runtime secrets`);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user