fix(auth): close Task 15 review round two
This commit is contained in:
@@ -18,8 +18,8 @@ const thtRoot = join(repositoryRoot, "tools", "tht");
|
||||
const fakePi = join(frontendRoot, "e2e", "fixtures", "fake-pi.mjs");
|
||||
const fakeTht = join(frontendRoot, "e2e", "fixtures", "fake-tht.mjs");
|
||||
const FIXTURE_CLIENT_ID = "thothii-e2e-client";
|
||||
const FIXTURE_CLIENT_SECRET = "e2e-client-secret-not-a-production-secret";
|
||||
const FIXTURE_API_TOKEN = "e2e-group-catalog-token-not-a-production-secret";
|
||||
const DEFAULT_FIXTURE_CLIENT_SECRET = "e2e-client-secret-not-a-production-secret";
|
||||
const DEFAULT_FIXTURE_API_TOKEN = "e2e-group-catalog-token-not-a-production-secret";
|
||||
const WRONG_CLIENT_ID = "thothii-e2e-unregistered-client";
|
||||
const WRONG_CLIENT_SECRET = "e2e-wrong-client-secret-not-production";
|
||||
const WRONG_API_TOKEN = "e2e-wrong-api-token-not-production";
|
||||
@@ -31,6 +31,21 @@ function safeError(code) {
|
||||
return new Error(code);
|
||||
}
|
||||
|
||||
function resolveFixtureCredentials() {
|
||||
const runtimeCredential = process.env.THT_TASK15_SENTINEL;
|
||||
if (runtimeCredential === undefined) {
|
||||
return Object.freeze({
|
||||
clientSecret: DEFAULT_FIXTURE_CLIENT_SECRET,
|
||||
apiToken: DEFAULT_FIXTURE_API_TOKEN,
|
||||
runtime: false,
|
||||
});
|
||||
}
|
||||
if (runtimeCredential.length < 24 || runtimeCredential.length > 512 || /[\r\n\0]/u.test(runtimeCredential)) {
|
||||
throw safeError("e2e_runtime_fixture_credential_invalid");
|
||||
}
|
||||
return Object.freeze({ clientSecret: runtimeCredential, apiToken: runtimeCredential, runtime: true });
|
||||
}
|
||||
|
||||
function buildAuthenticationStorageBridge(output) {
|
||||
const result = spawn("go", ["build", "-o", output, "./cmd/tht"], {
|
||||
cwd: thtRoot,
|
||||
@@ -322,7 +337,7 @@ function cleanBackendEnvironment(overrides) {
|
||||
"SETTINGS_FILE", "THT_MAINTENANCE_FILE", "THT_WORKSPACE_REGISTRY_ROOT", "THT_WORKSPACE_SECRET_STORE_ROOT",
|
||||
"THT_WORKSPACE_SECRET_RUNTIME_ROOT", "THT_WORKSPACE_GIT_REMOTE", "THT_WORKSPACE_GIT_BRANCH",
|
||||
"THT_WORKSPACE_SECRET_ROOTS", "THT_WORKSPACE_INSTALLATION_ID", "THT_LEGACY_WORKSPACE_MODE",
|
||||
"THT_DWH_PRECHECK", "THT_INTERNAL_QDRANT_URL", "THT_CONFIG",
|
||||
"THT_DWH_PRECHECK", "THT_INTERNAL_QDRANT_URL", "THT_CONFIG", "THT_TASK15_SENTINEL",
|
||||
]) delete env[name];
|
||||
for (const name of Object.keys(env)) {
|
||||
if (name.startsWith("THT_WS_")) delete env[name];
|
||||
@@ -331,6 +346,7 @@ function cleanBackendEnvironment(overrides) {
|
||||
}
|
||||
|
||||
export async function createAuthenticationStack({ withF1Workspace = false } = {}) {
|
||||
const credentials = resolveFixtureCredentials();
|
||||
const root = mkdtempSync(join(realpathSync(tmpdir()), "thothii-auth-e2e-"));
|
||||
secureDirectory(root);
|
||||
const stateRoot = join(root, "auth-state");
|
||||
@@ -358,10 +374,10 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
directory: providerRoot,
|
||||
registration: {
|
||||
clientId: FIXTURE_CLIENT_ID,
|
||||
clientSecret: FIXTURE_CLIENT_SECRET,
|
||||
clientSecret: credentials.clientSecret,
|
||||
redirectUri: new URL("/api/auth/oidc/callback", publicUrl).href,
|
||||
},
|
||||
apiToken: FIXTURE_API_TOKEN,
|
||||
apiToken: credentials.apiToken,
|
||||
});
|
||||
await buildAuthenticationStorageBridge(authStorageBinary);
|
||||
const localPassword = "e2e-local-password";
|
||||
@@ -395,8 +411,8 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
}));
|
||||
function writeOidcSecrets(variant) {
|
||||
if (!OIDC_CREDENTIAL_VARIANTS.has(variant)) throw safeError("e2e_oidc_credential_variant_invalid");
|
||||
const selectedClientSecret = variant === "wrong-client-secret" ? WRONG_CLIENT_SECRET : FIXTURE_CLIENT_SECRET;
|
||||
const selectedApiToken = variant === "wrong-api-token" ? WRONG_API_TOKEN : FIXTURE_API_TOKEN;
|
||||
const selectedClientSecret = variant === "wrong-client-secret" ? WRONG_CLIENT_SECRET : credentials.clientSecret;
|
||||
const selectedApiToken = variant === "wrong-api-token" ? WRONG_API_TOKEN : credentials.apiToken;
|
||||
writeSecure(secretsFile, [
|
||||
`THT_OIDC_CLIENT_SECRET=${selectedClientSecret}`,
|
||||
`THT_AUTHENTIK_API_TOKEN=${selectedApiToken}`,
|
||||
@@ -539,7 +555,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
method: "POST",
|
||||
body: new URLSearchParams({
|
||||
client_id: FIXTURE_CLIENT_ID,
|
||||
client_secret: FIXTURE_CLIENT_SECRET,
|
||||
client_secret: credentials.clientSecret,
|
||||
}).toString(),
|
||||
});
|
||||
const deviceCode = typeof device.body?.device_code === "string" ? device.body.device_code : "";
|
||||
@@ -548,12 +564,12 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
body: new URLSearchParams({
|
||||
grant_type: "urn:ietf:params:oauth:grant-type:device_code",
|
||||
client_id: FIXTURE_CLIENT_ID,
|
||||
client_secret: FIXTURE_CLIENT_SECRET,
|
||||
client_secret: credentials.clientSecret,
|
||||
device_code: deviceCode,
|
||||
}).toString(),
|
||||
});
|
||||
const groups = await providerJson(`${provider.baseUrl}/api/v3/core/groups/?name=fixture-users`, provider.caFile, {
|
||||
headers: { authorization: `Bearer ${FIXTURE_API_TOKEN}` },
|
||||
headers: { authorization: `Bearer ${credentials.apiToken}` },
|
||||
});
|
||||
return {
|
||||
discovery: discovery.status === 200 && discovery.body?.issuer === provider.issuer,
|
||||
@@ -562,6 +578,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
|
||||
&& typeof device.body?.verification_uri === "string",
|
||||
deviceToken: deviceToken.status === 200 && typeof deviceToken.body?.id_token === "string",
|
||||
groupList: groups.status === 200 && groups.body?.results?.[0]?.name === "fixture-users",
|
||||
runtimeCredential: credentials.runtime,
|
||||
};
|
||||
},
|
||||
setOidcIdentity(identity) {
|
||||
|
||||
Reference in New Issue
Block a user