fix(auth): harden unified diagnostic execution
This commit is contained in:
@@ -101,7 +101,7 @@ type authDiagnosticWire struct {
|
||||
}
|
||||
|
||||
type authDiagnosticsWire struct {
|
||||
Ready bool `json:"ready"`
|
||||
Ready *bool `json:"ready"`
|
||||
Mode string `json:"mode"`
|
||||
Checks []authDiagnosticWire `json:"checks"`
|
||||
}
|
||||
@@ -246,7 +246,10 @@ func decodeAuthDiagnostics(value string) (AuthDiagnostics, error) {
|
||||
if err := decoder.Decode(&wire); err != nil || decoder.Decode(&struct{}{}) != io.EOF {
|
||||
return AuthDiagnostics{}, errors.New("authentication diagnostic report is invalid")
|
||||
}
|
||||
report := AuthDiagnostics{Ready: wire.Ready, Mode: wire.Mode, Checks: make([]AuthDiagnostic, 0, len(wire.Checks))}
|
||||
if wire.Ready == nil {
|
||||
return AuthDiagnostics{}, errors.New("authentication diagnostic report is invalid")
|
||||
}
|
||||
report := AuthDiagnostics{Ready: *wire.Ready, Mode: wire.Mode, Checks: make([]AuthDiagnostic, 0, len(wire.Checks))}
|
||||
for _, item := range wire.Checks {
|
||||
var field *string
|
||||
if item.Field != nil {
|
||||
@@ -266,16 +269,16 @@ func decodeAuthDiagnostics(value string) (AuthDiagnostics, error) {
|
||||
return report, nil
|
||||
}
|
||||
|
||||
func authenticationSecretValues(installation config.Installation) []string {
|
||||
func authenticationSecretValues(installation config.Installation) ([]string, error) {
|
||||
files, err := installation.SecretFiles()
|
||||
if err != nil {
|
||||
return nil
|
||||
return nil, errors.New("authentication diagnostic secret corpus is unavailable")
|
||||
}
|
||||
values, err := output.SecretValuesFromFiles(files)
|
||||
if err != nil {
|
||||
return nil
|
||||
return nil, errors.New("authentication diagnostic secret corpus is unavailable")
|
||||
}
|
||||
return values
|
||||
return values, nil
|
||||
}
|
||||
|
||||
func sanitizeAuthDiagnostics(report AuthDiagnostics, secrets []string) AuthDiagnostics {
|
||||
@@ -339,15 +342,23 @@ func runCheck(ctx context.Context, installation config.Installation, runner comp
|
||||
if runner == nil {
|
||||
return AuthDiagnostics{}, "", errors.New("authentication diagnostic runner is unavailable")
|
||||
}
|
||||
secrets, err := authenticationSecretValues(installation)
|
||||
if err != nil {
|
||||
return AuthDiagnostics{}, "", err
|
||||
}
|
||||
timeout := authCheckTimeout
|
||||
if interactive {
|
||||
timeout = interactiveAuthCheckTimeout
|
||||
}
|
||||
bounded, cancel := context.WithTimeout(ctx, timeout)
|
||||
defer cancel()
|
||||
command := []string{"run", "--rm", "--no-deps", "--no-TTY", "core", "node", "dist/auth/diagnostic-command.js", "--json"}
|
||||
if useRunningCore {
|
||||
command = []string{"exec", "-T", "core", "node", "dist/auth/diagnostic-command.js", "--json"}
|
||||
command := []string{"exec", "-T", "core", "node", "dist/auth/diagnostic-command.js", "--json"}
|
||||
if !useRunningCore {
|
||||
containerName, err := compose.NewOneShotContainerName("thothii-auth-check")
|
||||
if err != nil {
|
||||
return AuthDiagnostics{}, "", errors.New("authentication diagnostic command failed")
|
||||
}
|
||||
command = []string{"run", "--rm", "--no-deps", "--no-TTY", "--name", containerName, "core", "node", "dist/auth/diagnostic-command.js", "--json"}
|
||||
}
|
||||
if interactive {
|
||||
command = append(command, "--interactive")
|
||||
@@ -356,7 +367,6 @@ func runCheck(ctx context.Context, installation config.Installation, runner comp
|
||||
StdoutBytes: maxAuthDiagnosticOutputBytes,
|
||||
StderrBytes: maxAuthDiagnosticOutputBytes,
|
||||
})
|
||||
secrets := authenticationSecretValues(installation)
|
||||
var exitError *exec.ExitError
|
||||
validProcessOutcome := result.ExitCode == 0 && err == nil ||
|
||||
result.ExitCode == 1 && (err == nil || errors.As(err, &exitError))
|
||||
|
||||
Reference in New Issue
Block a user