fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 17:25:26 +02:00
parent 30ee9433dc
commit ef244ab56d
18 changed files with 670 additions and 68 deletions
+22
View File
@@ -181,6 +181,28 @@ func TestRunRedactsWorkflowDiagnosticFailures(t *testing.T) {
}
}
func TestRunFailsBeforeDockerWhenDeclaredSecretCorpusIsIncomplete(t *testing.T) {
installation := doctorInstallation(t, "")
missing := filepath.Join(filepath.Dir(installation.EnvFile), "missing-pi-auth.json")
if err := os.WriteFile(installation.EnvFile, []byte("PI_AUTH_FILE="+missing+"\n"), 0o600); err != nil {
t.Fatal(err)
}
runner := &doctorRunner{services: healthyServices}
report, err := Run(context.Background(), installation, runner)
if err != nil {
t.Fatal(err)
}
if report.OK || checkStatus(report, "files") != StatusFailed || len(runner.calls) != 0 {
t.Fatalf("incomplete corpus was not refused before Docker: report=%#v calls=%v", report, runner.calls)
}
if strings.Contains(reportText(report), missing) {
t.Fatalf("incomplete corpus report exposed a secret path: %#v", report)
}
assertChecklist(t, report, []string{"descriptor", "files", "docker", "compose", "configuration", "authentication", "services", "core-http", "frontend-http", "workspace-registry", "workflow", "pi"})
}
func doctorInstallation(t *testing.T, _ string) config.Installation {
t.Helper()
base, err := filepath.EvalSymlinks(os.TempDir())