feat: add local auth billing and usage management
This commit is contained in:
1 parent
f642b5e71f
commit
196fdde83f
119 files changed
+15695
-2650
No files matched your search
@@ -3,6 +3,7 @@ import { afterEach, describe, expect, it, vi } from "vitest";
|
||||
import {
|
||||
chunkCookieValue,
|
||||
chunkedCookieName,
|
||||
createSignedJsonValue,
|
||||
createSessionCookieValue,
|
||||
parseSessionCookieValue,
|
||||
readChunkedCookieValue,
|
||||
@@ -43,6 +44,7 @@ describe("SSO auth helpers", () => {
|
||||
it("round-trips signed session cookies and rejects tampering or expiry", async () => {
|
||||
const session: AuthSession = {
|
||||
version: 1,
|
||||
authMode: "admin",
|
||||
issuedAt: 100,
|
||||
expiresAt: 200,
|
||||
accessToken: "access-token-1",
|
||||
@@ -60,6 +62,7 @@ describe("SSO auth helpers", () => {
|
||||
|
||||
const cookie = await createSessionCookieValue(session, authConfig.sessionSecret || "");
|
||||
expect(await parseSessionCookieValue(cookie, authConfig.sessionSecret || "", 150)).toMatchObject({
|
||||
authMode: "admin",
|
||||
accessToken: "access-token-1",
|
||||
tokenType: "bearer",
|
||||
user: { id: "auth:customPC:1", displayName: "张三" }
|
||||
@@ -71,6 +74,7 @@ describe("SSO auth helpers", () => {
|
||||
it("reassembles chunked session cookies for large auth payloads", async () => {
|
||||
const session: AuthSession = {
|
||||
version: 1,
|
||||
authMode: "user",
|
||||
issuedAt: 100,
|
||||
expiresAt: 200,
|
||||
accessToken: "token.".repeat(1200),
|
||||
@@ -98,6 +102,28 @@ describe("SSO auth helpers", () => {
|
||||
});
|
||||
});
|
||||
|
||||
it("treats legacy sessions without an auth mode as ordinary user sessions", async () => {
|
||||
const legacyCookie = await createSignedJsonValue({
|
||||
version: 1,
|
||||
issuedAt: 100,
|
||||
expiresAt: 200,
|
||||
user: {
|
||||
id: "auth:customPC:legacy-admin",
|
||||
subject: "legacy-admin",
|
||||
username: "legacy-admin",
|
||||
displayName: "旧管理员",
|
||||
clientId: "customPC",
|
||||
authorities: ["ROLE_ADMIN"],
|
||||
scope: ["server"]
|
||||
}
|
||||
}, authConfig.sessionSecret || "");
|
||||
|
||||
expect(await parseSessionCookieValue(legacyCookie, authConfig.sessionSecret || "", 150)).toMatchObject({
|
||||
authMode: "user",
|
||||
user: { username: "legacy-admin", authorities: ["ROLE_ADMIN"] }
|
||||
});
|
||||
});
|
||||
|
||||
it("verifies RS256 JWTs from JWKS and maps stable owner ids", async () => {
|
||||
const { publicKey, privateKey } = generateKeyPairSync("rsa", { modulusLength: 2048 });
|
||||
const jwk = publicKey.export({ format: "jwk" }) as TestJwk;
|
||||
|
||||
Reference in new issue
Block a user