feat: add CI deployment and live progress

This commit is contained in:
2026-09-05 12:09:16 +00:00 Unverified
parent 321f4e807a
commit aa02826dbb
27 changed files with 2711 additions and 180 deletions
+39 -1
View File
@@ -49,8 +49,10 @@ class FakeObjects {
readonly secrets = new Map<string, StoredSecret>();
readonly patches: StoredSecret[] = [];
readonly deleted: string[] = [];
reads = 0;
async read(value: KubernetesObject): Promise<StoredSecret> {
this.reads += 1;
const found = this.secrets.get(value.metadata?.name ?? "");
if (!found) throw { code: 404 };
return found;
@@ -97,7 +99,10 @@ class FakeObjects {
}
}
function setup(): { fake: FakeObjects; store: KubernetesAuthStore } {
function setup(): {
fake: FakeObjects;
store: KubernetesAuthStore;
} {
const fake = new FakeObjects();
return {
fake,
@@ -106,6 +111,39 @@ function setup(): { fake: FakeObjects; store: KubernetesAuthStore } {
}
describe("KubernetesAuthStore", () => {
test("validates the session and user from the store on every request", async () => {
const { fake, store } = setup();
const tokenHash = hashToken("fresh");
await store.putUser({
username: "alice",
passwordHash: "hash",
roles: ["viewer"],
});
await store.putSession({
tokenHash,
username: "alice",
roles: ["viewer"],
expiresAt: "2026-09-03T00:00:00.000Z",
});
fake.reads = 0;
await expect(store.getSession(tokenHash)).resolves.toMatchObject({
tokenHash,
});
fake.secrets.set(
objectName("user", "alice"),
secret("user", objectName("user", "alice"), {
username: "alice",
passwordHash: "hash",
roles: JSON.stringify(["viewer"]),
authVersion: "1",
disabled: "true",
}),
);
await expect(store.getSession(tokenHash)).resolves.toBeUndefined();
expect(fake.reads).toBe(4);
});
test("persists authVersion and not copied roles in new sessions", async () => {
const { fake, store } = setup();
await store.putUser({