feat: harden self-managed reconciliation
This commit is contained in:
@@ -155,7 +155,9 @@ function connection(role: "viewer" | "operator" | "admin" = "operator") {
|
||||
} as ExecConnection;
|
||||
}
|
||||
|
||||
async function authenticatedStore(role: "viewer" | "operator" | "admin" = "operator") {
|
||||
async function authenticatedStore(
|
||||
role: "viewer" | "operator" | "admin" = "operator",
|
||||
) {
|
||||
const store = new MemoryAuthStore();
|
||||
await store.putUser({ username: role, passwordHash: "hash", roles: [role] });
|
||||
await store.putSession({
|
||||
@@ -176,7 +178,9 @@ function request(path = "/api/v2/workspaces/shop/exec") {
|
||||
describe("authorizeExecConnection", () => {
|
||||
test("resolves the workspace UID server-side for authorized operators", async () => {
|
||||
const store = await authenticatedStore("operator");
|
||||
const workspaceStore = new MemoryWorkspaceStore({ uid: () => "workspace-1" });
|
||||
const workspaceStore = new MemoryWorkspaceStore({
|
||||
uid: () => "workspace-1",
|
||||
});
|
||||
await workspaceStore.create({
|
||||
id: "shop",
|
||||
source: { uri: "oci://example/demo", digest: "sha256:abc" },
|
||||
@@ -285,7 +289,9 @@ describe("WireExecSession", () => {
|
||||
createExecService(new FakeBackend()),
|
||||
connection(),
|
||||
);
|
||||
await session.receive(JSON.stringify({ type: "resize", columns: 1, rows: 1 }));
|
||||
await session.receive(
|
||||
JSON.stringify({ type: "resize", columns: 1, rows: 1 }),
|
||||
);
|
||||
expect(JSON.parse(socket.sent[0]!)).toMatchObject({
|
||||
type: "error",
|
||||
code: "EXEC_INVALID",
|
||||
|
||||
Reference in New Issue
Block a user