login fix
This commit is contained in:
@@ -163,3 +163,32 @@ func (s stubAssistant) Ask(_ context.Context, _, _ string, _ tools.Caller) (serv
|
||||
func (s stubAssistant) Approve(_ context.Context, _, _ string, _ tools.Caller) (services.AssistantAnswer, error) {
|
||||
return services.AssistantAnswer{}, nil
|
||||
}
|
||||
|
||||
func TestHealthSaysWhetherSessionsCanBeIssued(t *testing.T) {
|
||||
// The failure this exists for: `attachWebSession` logs a minting failure and
|
||||
// lets the login succeed anyway, so a server with no signing secret issues
|
||||
// sessions that cannot authenticate. The console renders, every request
|
||||
// after it 401s with no `authorization` header, and nothing says why.
|
||||
t.Setenv("POS_TOKEN_SECRET", "")
|
||||
t.Setenv("JWT_SECRET_KEY", "")
|
||||
_, broken, body := readHealth(t, healthApp(t, true, true))
|
||||
if broken["sessions"] != false {
|
||||
t.Fatalf("a server that cannot sign a session claimed it could: %s", body)
|
||||
}
|
||||
|
||||
t.Setenv("POS_TOKEN_SECRET", "a-secret-of-quite-sufficient-length")
|
||||
_, working, _ := readHealth(t, healthApp(t, true, true))
|
||||
if working["sessions"] != true {
|
||||
t.Fatal("a server with a signing secret reported it could not issue sessions")
|
||||
}
|
||||
}
|
||||
|
||||
func TestHealthDoesNotLeakTheSigningSecret(t *testing.T) {
|
||||
// A boolean about the secret, never the secret.
|
||||
t.Setenv("POS_TOKEN_SECRET", "correct-horse-battery-staple")
|
||||
_, _, body := readHealth(t, healthApp(t, true, true))
|
||||
|
||||
if strings.Contains(body, "correct-horse") {
|
||||
t.Fatalf("the signing secret is on an unauthenticated endpoint: %s", body)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user