#!/usr/bin/env bash set -euo pipefail root=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P) expected_node=${THT_EXPECTED_NODE_VERSION:-v24.16.0} actual_node=$(node --version) if [[ "$actual_node" != "$expected_node" ]]; then printf 'authentication smoke requires Node %s; found %s\n' "$expected_node" "$actual_node" >&2 exit 2 fi for command in go openssl; do command -v "$command" >/dev/null 2>&1 || { printf 'authentication smoke requires %s\n' "$command" >&2 exit 2 } done playwright="$root/frontend/node_modules/.bin/playwright" [[ -x "$playwright" ]] || { echo "authentication smoke requires frontend dependencies (run npm ci in frontend)" >&2 exit 2 } temporary_root=$(mktemp -d "${TMPDIR:-/tmp}/thothii-authentication-smoke.XXXXXX") trap 'rm -rf "$temporary_root"' EXIT HUP INT TERM log="$temporary_root/playwright.log" output="$temporary_root/playwright" mkdir -p "$output" sentinel="task15-sentinel-$(openssl rand -hex 24)" export THT_TASK15_SENTINEL="$sentinel" sanitize_failure_log() { sed -E \ -e "s/${sentinel}/[redacted]/g" \ -e 's#https?://[^[:space:])]+#[url]#g' \ -e 's/(THT_[A-Z_]+|PI_[A-Z_]+|AUTH_MODE)=[^[:space:]]+/\1=[redacted]/g' \ "$log" | tail -n 100 >&2 } if ! ( cd "$root/frontend" THT_E2E_AUTH_STACK=1 "$playwright" test e2e/auth.spec.ts --workers=1 --output="$output" ) >"$log" 2>&1; then echo "authentication smoke: hermetic browser suite failed" >&2 sanitize_failure_log exit 1 fi if rg -a -Fq -- "$sentinel" "$log" "$output"; then echo "authentication smoke: sentinel appeared in retained test output" >&2 exit 1 fi printf 'authentication smoke: hermetic OIDC/browser suite passed on Node %s\n' "$actual_node"