fix(auth): restore permission boundary safeguards
This commit is contained in:
@@ -105,9 +105,9 @@ test("loopback-only AUTH_MODE=none may read the sanitized Pi status", async () =
|
||||
}
|
||||
});
|
||||
|
||||
// Route authorization is permission-based; loopback none-mode derives its local admin principal
|
||||
// from trusted installation configuration rather than a browser Origin check.
|
||||
test("loopback-only management accepts cross-origin writes for its local administrator", async () => {
|
||||
// A local implicit administrator has pi.manage, but a browser origin still cannot borrow that
|
||||
// authority to mutate local configuration or trigger provider work.
|
||||
test("loopback-only management rejects cross-origin writes for its local administrator", async () => {
|
||||
const service = fakeService();
|
||||
const app = appWith(service);
|
||||
try {
|
||||
@@ -121,10 +121,10 @@ test("loopback-only management accepts cross-origin writes for its local adminis
|
||||
headers: { host: "127.0.0.1:8080", origin: "https://evil.example" },
|
||||
});
|
||||
|
||||
expect(configured.statusCode).toBe(200);
|
||||
expect(smoke.statusCode).toBe(200);
|
||||
expect(service.configure).toHaveBeenCalledOnce();
|
||||
expect(service.test).toHaveBeenCalledOnce();
|
||||
expect(configured.statusCode).toBe(403);
|
||||
expect(smoke.statusCode).toBe(403);
|
||||
expect(service.configure).not.toHaveBeenCalled();
|
||||
expect(service.test).not.toHaveBeenCalled();
|
||||
} finally {
|
||||
await app.close();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user