fix(auth): restore permission boundary safeguards
This commit is contained in:
@@ -1,6 +1,8 @@
|
||||
import { test, expect, vi } from "vitest";
|
||||
import Fastify from "fastify";
|
||||
import { buildApp } from "../src/app.js";
|
||||
import { loadConfig } from "../src/config.js";
|
||||
import { sqlRoutes } from "../src/routes/sql.js";
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// SQL routes
|
||||
@@ -29,6 +31,35 @@ test("POST /sessions/:id/sql/preview returns rows from injected thtRunner stub",
|
||||
expect(res.json()).toEqual(previewResult);
|
||||
});
|
||||
|
||||
test("SQL lookup and execution derive harness admin compatibility from session.read_all", async () => {
|
||||
const seen: boolean[] = [];
|
||||
const app = Fastify();
|
||||
app.addHook("preHandler", async (request) => {
|
||||
request.principal = {
|
||||
issuer: "portal", subject: "inconsistent", roles: ["user"], permissions: ["session.use"], isAdmin: true,
|
||||
};
|
||||
});
|
||||
const runner = {
|
||||
sessionShow: async () => ({ id: "s1" }),
|
||||
sqlPreview: async () => ({ columns: [], rows: [], execution_ms: 0, truncated: false }),
|
||||
};
|
||||
sqlRoutes(app, {
|
||||
tht: {
|
||||
withPrincipal: (principal: { isAdmin: boolean }) => {
|
||||
seen.push(principal.isAdmin);
|
||||
return runner;
|
||||
},
|
||||
} as any,
|
||||
getSettings: async () => ({ workspace: "legacy" }),
|
||||
workspaceRegistry: { list: async () => [] } as any,
|
||||
});
|
||||
|
||||
const response = await app.inject({ method: "POST", url: "/sessions/s1/sql/preview", payload: {} });
|
||||
|
||||
expect(response.statusCode).toBe(200);
|
||||
expect(seen).toEqual([false, false]);
|
||||
});
|
||||
|
||||
test("POST /sessions/:id/sql/preview passes limit and offset to thtRunner", async () => {
|
||||
let captured: any;
|
||||
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
|
||||
|
||||
Reference in New Issue
Block a user