fix(auth): restore permission boundary safeguards
This commit is contained in:
@@ -10,6 +10,8 @@ import { SseHub } from "../src/sse/sse-hub.js";
|
||||
import { MaintenanceBarrier } from "../src/runtime/maintenance-gate.js";
|
||||
import { PiProcessManager } from "../src/pi/pi-process-manager.js";
|
||||
import { validateDeclarativePiConfig } from "../src/pi/managed-config.js";
|
||||
import Fastify from "fastify";
|
||||
import { sessionRoutes } from "../src/routes/sessions.js";
|
||||
|
||||
const FAKE = path.resolve("../harness/tests/fake_pi/fake_pi_rpc.mjs");
|
||||
const SCRIPT = path.resolve("../harness/tests/fake_pi/scripts/f1_disambiguation.json");
|
||||
@@ -99,6 +101,29 @@ test("upstream requests without a principal fail before a Pi runtime can be crea
|
||||
expect(created).toBe(false);
|
||||
});
|
||||
|
||||
test("GET /sessions with a query still requires session.use", async () => {
|
||||
const app = Fastify();
|
||||
app.addHook("preHandler", async (request) => {
|
||||
request.principal = { issuer: "oidc", subject: "no-role", roles: [], permissions: [], isAdmin: false };
|
||||
});
|
||||
sessionRoutes(app, {
|
||||
mgr: { get: () => undefined } as any,
|
||||
tht: { sessionList: async () => [] } as any,
|
||||
hub: {} as any,
|
||||
getSettings: async () => ({}),
|
||||
readiness: {} as any,
|
||||
listModels: async () => [],
|
||||
workspaceRegistry: { list: async () => [] } as any,
|
||||
workspaceRuntimeSupport: () => true,
|
||||
maintenanceBarrier: new MaintenanceBarrier(),
|
||||
});
|
||||
|
||||
const response = await app.inject({ method: "GET", url: "/sessions?scope=mine" });
|
||||
|
||||
expect(response.statusCode).toBe(403);
|
||||
expect(response.json()).toEqual({ code: "auth_forbidden", error: "This operation is not permitted" });
|
||||
});
|
||||
|
||||
test("maintenance rejects new and resumed session admission without interrupting running sessions", async () => {
|
||||
const maintenanceBarrier = new MaintenanceBarrier();
|
||||
await maintenanceBarrier.activate();
|
||||
|
||||
Reference in New Issue
Block a user