fix(auth): restore permission boundary safeguards

This commit is contained in:
2026-08-16 18:03:36 +02:00
parent 2e0489ce22
commit f99bddcdf0
8 changed files with 126 additions and 14 deletions
+7 -7
View File
@@ -105,9 +105,9 @@ test("loopback-only AUTH_MODE=none may read the sanitized Pi status", async () =
}
});
// Route authorization is permission-based; loopback none-mode derives its local admin principal
// from trusted installation configuration rather than a browser Origin check.
test("loopback-only management accepts cross-origin writes for its local administrator", async () => {
// A local implicit administrator has pi.manage, but a browser origin still cannot borrow that
// authority to mutate local configuration or trigger provider work.
test("loopback-only management rejects cross-origin writes for its local administrator", async () => {
const service = fakeService();
const app = appWith(service);
try {
@@ -121,10 +121,10 @@ test("loopback-only management accepts cross-origin writes for its local adminis
headers: { host: "127.0.0.1:8080", origin: "https://evil.example" },
});
expect(configured.statusCode).toBe(200);
expect(smoke.statusCode).toBe(200);
expect(service.configure).toHaveBeenCalledOnce();
expect(service.test).toHaveBeenCalledOnce();
expect(configured.statusCode).toBe(403);
expect(smoke.statusCode).toBe(403);
expect(service.configure).not.toHaveBeenCalled();
expect(service.test).not.toHaveBeenCalled();
} finally {
await app.close();
}