fix(auth): close Task 15 review round two

This commit is contained in:
2026-08-18 07:21:24 +02:00
parent 225ffc8e20
commit fe190e7046
10 changed files with 305 additions and 64 deletions
+27 -10
View File
@@ -18,8 +18,8 @@ const thtRoot = join(repositoryRoot, "tools", "tht");
const fakePi = join(frontendRoot, "e2e", "fixtures", "fake-pi.mjs");
const fakeTht = join(frontendRoot, "e2e", "fixtures", "fake-tht.mjs");
const FIXTURE_CLIENT_ID = "thothii-e2e-client";
const FIXTURE_CLIENT_SECRET = "e2e-client-secret-not-a-production-secret";
const FIXTURE_API_TOKEN = "e2e-group-catalog-token-not-a-production-secret";
const DEFAULT_FIXTURE_CLIENT_SECRET = "e2e-client-secret-not-a-production-secret";
const DEFAULT_FIXTURE_API_TOKEN = "e2e-group-catalog-token-not-a-production-secret";
const WRONG_CLIENT_ID = "thothii-e2e-unregistered-client";
const WRONG_CLIENT_SECRET = "e2e-wrong-client-secret-not-production";
const WRONG_API_TOKEN = "e2e-wrong-api-token-not-production";
@@ -31,6 +31,21 @@ function safeError(code) {
return new Error(code);
}
function resolveFixtureCredentials() {
const runtimeCredential = process.env.THT_TASK15_SENTINEL;
if (runtimeCredential === undefined) {
return Object.freeze({
clientSecret: DEFAULT_FIXTURE_CLIENT_SECRET,
apiToken: DEFAULT_FIXTURE_API_TOKEN,
runtime: false,
});
}
if (runtimeCredential.length < 24 || runtimeCredential.length > 512 || /[\r\n\0]/u.test(runtimeCredential)) {
throw safeError("e2e_runtime_fixture_credential_invalid");
}
return Object.freeze({ clientSecret: runtimeCredential, apiToken: runtimeCredential, runtime: true });
}
function buildAuthenticationStorageBridge(output) {
const result = spawn("go", ["build", "-o", output, "./cmd/tht"], {
cwd: thtRoot,
@@ -322,7 +337,7 @@ function cleanBackendEnvironment(overrides) {
"SETTINGS_FILE", "THT_MAINTENANCE_FILE", "THT_WORKSPACE_REGISTRY_ROOT", "THT_WORKSPACE_SECRET_STORE_ROOT",
"THT_WORKSPACE_SECRET_RUNTIME_ROOT", "THT_WORKSPACE_GIT_REMOTE", "THT_WORKSPACE_GIT_BRANCH",
"THT_WORKSPACE_SECRET_ROOTS", "THT_WORKSPACE_INSTALLATION_ID", "THT_LEGACY_WORKSPACE_MODE",
"THT_DWH_PRECHECK", "THT_INTERNAL_QDRANT_URL", "THT_CONFIG",
"THT_DWH_PRECHECK", "THT_INTERNAL_QDRANT_URL", "THT_CONFIG", "THT_TASK15_SENTINEL",
]) delete env[name];
for (const name of Object.keys(env)) {
if (name.startsWith("THT_WS_")) delete env[name];
@@ -331,6 +346,7 @@ function cleanBackendEnvironment(overrides) {
}
export async function createAuthenticationStack({ withF1Workspace = false } = {}) {
const credentials = resolveFixtureCredentials();
const root = mkdtempSync(join(realpathSync(tmpdir()), "thothii-auth-e2e-"));
secureDirectory(root);
const stateRoot = join(root, "auth-state");
@@ -358,10 +374,10 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
directory: providerRoot,
registration: {
clientId: FIXTURE_CLIENT_ID,
clientSecret: FIXTURE_CLIENT_SECRET,
clientSecret: credentials.clientSecret,
redirectUri: new URL("/api/auth/oidc/callback", publicUrl).href,
},
apiToken: FIXTURE_API_TOKEN,
apiToken: credentials.apiToken,
});
await buildAuthenticationStorageBridge(authStorageBinary);
const localPassword = "e2e-local-password";
@@ -395,8 +411,8 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
}));
function writeOidcSecrets(variant) {
if (!OIDC_CREDENTIAL_VARIANTS.has(variant)) throw safeError("e2e_oidc_credential_variant_invalid");
const selectedClientSecret = variant === "wrong-client-secret" ? WRONG_CLIENT_SECRET : FIXTURE_CLIENT_SECRET;
const selectedApiToken = variant === "wrong-api-token" ? WRONG_API_TOKEN : FIXTURE_API_TOKEN;
const selectedClientSecret = variant === "wrong-client-secret" ? WRONG_CLIENT_SECRET : credentials.clientSecret;
const selectedApiToken = variant === "wrong-api-token" ? WRONG_API_TOKEN : credentials.apiToken;
writeSecure(secretsFile, [
`THT_OIDC_CLIENT_SECRET=${selectedClientSecret}`,
`THT_AUTHENTIK_API_TOKEN=${selectedApiToken}`,
@@ -539,7 +555,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
method: "POST",
body: new URLSearchParams({
client_id: FIXTURE_CLIENT_ID,
client_secret: FIXTURE_CLIENT_SECRET,
client_secret: credentials.clientSecret,
}).toString(),
});
const deviceCode = typeof device.body?.device_code === "string" ? device.body.device_code : "";
@@ -548,12 +564,12 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
body: new URLSearchParams({
grant_type: "urn:ietf:params:oauth:grant-type:device_code",
client_id: FIXTURE_CLIENT_ID,
client_secret: FIXTURE_CLIENT_SECRET,
client_secret: credentials.clientSecret,
device_code: deviceCode,
}).toString(),
});
const groups = await providerJson(`${provider.baseUrl}/api/v3/core/groups/?name=fixture-users`, provider.caFile, {
headers: { authorization: `Bearer ${FIXTURE_API_TOKEN}` },
headers: { authorization: `Bearer ${credentials.apiToken}` },
});
return {
discovery: discovery.status === 200 && discovery.body?.issuer === provider.issuer,
@@ -562,6 +578,7 @@ export async function createAuthenticationStack({ withF1Workspace = false } = {}
&& typeof device.body?.verification_uri === "string",
deviceToken: deviceToken.status === 200 && typeof deviceToken.body?.id_token === "string",
groupList: groups.status === 200 && groups.body?.results?.[0]?.name === "fixture-users",
runtimeCredential: credentials.runtime,
};
},
setOidcIdentity(identity) {