feat: prepare 2.6.1-rc5 shared databases and build SSE
This commit is contained in:
@@ -7,7 +7,11 @@ import type { ManagementService } from "../../server/management";
|
||||
import { MemoryTrustStore } from "../../server/trust-store";
|
||||
import { MemoryWorkspaceStore } from "../../server/workspace-store";
|
||||
|
||||
const now = Date.parse("2026-09-05T00:00:00.000Z");
|
||||
const now = Date.parse("2030-09-05T00:00:00.000Z");
|
||||
const finiteExpiry = new Date(now + 30 * 24 * 60 * 60 * 1000).toISOString();
|
||||
const delegatedLaterExpiry = new Date(
|
||||
now + 31 * 24 * 60 * 60 * 1000,
|
||||
).toISOString();
|
||||
|
||||
function request(path: string, init: RequestInit = {}, token = "admin-token") {
|
||||
const headers = new Headers(init.headers);
|
||||
@@ -33,7 +37,7 @@ async function setup() {
|
||||
tokenHash: hashToken("admin-token"),
|
||||
username: "admin",
|
||||
authVersion: 1,
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
return {
|
||||
store,
|
||||
@@ -86,7 +90,7 @@ describe("API keys", () => {
|
||||
tokenHash: hashToken("ci-key"),
|
||||
username: "ci",
|
||||
capabilities: ["kubernetes:read"],
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
expect((await app(request("/api/v2/users", {}, "ci-key"))).status).toBe(
|
||||
403,
|
||||
@@ -104,7 +108,7 @@ describe("API keys", () => {
|
||||
username: "ci",
|
||||
capabilities: ["users:write", "kubernetes:read"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
const create = (body: unknown) =>
|
||||
app(
|
||||
@@ -149,14 +153,14 @@ describe("API keys", () => {
|
||||
const laterExpiry = await create({
|
||||
capabilities: ["kubernetes:read"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-06T00:00:00.000Z",
|
||||
expiresAt: delegatedLaterExpiry,
|
||||
});
|
||||
expect(laterExpiry.status).toBe(403);
|
||||
|
||||
const subset = await create({
|
||||
capabilities: ["kubernetes:read"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
expect(subset.status).toBe(201);
|
||||
expect(
|
||||
@@ -194,7 +198,7 @@ describe("API keys", () => {
|
||||
tokenHash: hashToken("unscoped-delegation"),
|
||||
username: "ci",
|
||||
capabilities: ["users:write", "kubernetes:read"],
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
const unscopedSubset = await app(
|
||||
request(
|
||||
@@ -204,7 +208,7 @@ describe("API keys", () => {
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify({
|
||||
capabilities: ["kubernetes:read"],
|
||||
expiresAt: "2026-09-20T00:00:00.000Z",
|
||||
expiresAt: new Date(now + 15 * 24 * 60 * 60 * 1000).toISOString(),
|
||||
}),
|
||||
},
|
||||
"unscoped-delegation",
|
||||
@@ -248,7 +252,7 @@ describe("API keys", () => {
|
||||
tokenHash: hashToken("expired-key"),
|
||||
username: "ci",
|
||||
capabilities: ["kubernetes:read"],
|
||||
expiresAt: "2026-09-04T00:00:00.000Z",
|
||||
expiresAt: new Date(now - 24 * 60 * 60 * 1000).toISOString(),
|
||||
});
|
||||
expect((await app(request("/api/v2/me", {}, "expired-key"))).status).toBe(
|
||||
401,
|
||||
@@ -261,7 +265,7 @@ describe("API keys", () => {
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify({
|
||||
capabilities: ["kubernetes:read"],
|
||||
expiresAt: "2027-09-06T00:00:00.000Z",
|
||||
expiresAt: new Date(now + 366 * 24 * 60 * 60 * 1000).toISOString(),
|
||||
}),
|
||||
}),
|
||||
)
|
||||
@@ -291,7 +295,7 @@ describe("API keys", () => {
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify({
|
||||
capabilities: ["kubernetes:read"],
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
}),
|
||||
}),
|
||||
);
|
||||
@@ -300,7 +304,7 @@ describe("API keys", () => {
|
||||
token: string;
|
||||
expiresAt: string;
|
||||
};
|
||||
expect(finiteKey.expiresAt).toBe("2026-10-05T00:00:00.000Z");
|
||||
expect(finiteKey.expiresAt).toBe(finiteExpiry);
|
||||
expect(
|
||||
(await app(request("/api/v2/logout", { method: "POST" }, key.token)))
|
||||
.status,
|
||||
@@ -326,7 +330,7 @@ describe("API keys", () => {
|
||||
username: "ci",
|
||||
capabilities: ["kubernetes:read"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
expect(
|
||||
(await app(request("/api/v2/workspaces/other", {}, "scoped-key"))).status,
|
||||
@@ -366,7 +370,7 @@ describe("API keys", () => {
|
||||
username: "ci",
|
||||
capabilities: ["kubernetes:write"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
const apply = (workspace: string) =>
|
||||
app(
|
||||
@@ -402,7 +406,7 @@ describe("API keys", () => {
|
||||
username: "ci",
|
||||
capabilities: ["users:read"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
await auditStore.append({
|
||||
actor: { username: "admin" },
|
||||
@@ -459,7 +463,7 @@ describe("API keys", () => {
|
||||
username: "ci",
|
||||
capabilities: ["kubernetes:read"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
|
||||
const unfiltered = await app(
|
||||
@@ -525,7 +529,7 @@ describe("API keys", () => {
|
||||
username: "admin",
|
||||
capabilities: ["kubernetes:write"],
|
||||
workspace: "kuber-system",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
await store.createApiKey({
|
||||
id: "key_platform_scope",
|
||||
@@ -533,7 +537,7 @@ describe("API keys", () => {
|
||||
username: "admin",
|
||||
capabilities: ["platform:adopt"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
await store.createApiKey({
|
||||
id: "key_platform_allowed",
|
||||
@@ -541,7 +545,7 @@ describe("API keys", () => {
|
||||
username: "admin",
|
||||
capabilities: ["platform:adopt"],
|
||||
workspace: "kuber-system",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
const adopt = (token: string) =>
|
||||
app(
|
||||
@@ -569,7 +573,7 @@ describe("API keys", () => {
|
||||
username: "ci",
|
||||
capabilities: ["kubernetes:write"],
|
||||
workspace: "shop",
|
||||
expiresAt: "2026-10-05T00:00:00.000Z",
|
||||
expiresAt: finiteExpiry,
|
||||
});
|
||||
const matching = await app(
|
||||
request(
|
||||
|
||||
Reference in New Issue
Block a user