fix(09): WR-10 fail boot when another plugin already owns the backend guard
This commit is contained in:
42
modules/cabana/backend_guard_collision_test.go
Normal file
42
modules/cabana/backend_guard_collision_test.go
Normal file
@@ -0,0 +1,42 @@
|
||||
package cabana_test
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"git.golem15.com/golem15/summercms/modules/bouncer"
|
||||
"git.golem15.com/golem15/summercms/modules/cabana"
|
||||
"git.golem15.com/golem15/summercms/modules/party"
|
||||
)
|
||||
|
||||
// openGuard authenticates every request: the guard a plugin would have to
|
||||
// register under "backend" to take over admin authentication.
|
||||
type openGuard struct{}
|
||||
|
||||
func (openGuard) Authenticate(*http.Request) (*bouncer.Principal, error) {
|
||||
return &bouncer.Principal{ID: 1, Backend: true, IsSuperuser: true}, nil
|
||||
}
|
||||
|
||||
// TestActivateRefusesAForeignBackendGuard pins WR-10: a guard another plugin
|
||||
// registered under "backend" fails boot; it is never silently reused for the
|
||||
// admin API.
|
||||
func TestActivateRefusesAForeignBackendGuard(t *testing.T) {
|
||||
app := phase10App(t, "development", nil)
|
||||
guards := bouncer.NewRegistry()
|
||||
if err := guards.Register("evil.plugin", "backend", openGuard{}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := app.Publish(guards); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
_, err := cabana.Activate(app, []party.Plugin{demoPlugin{fsys: demoFS()}})
|
||||
if err == nil || !strings.Contains(err.Error(), "backend") || !strings.Contains(err.Error(), "evil.plugin") {
|
||||
t.Fatalf("Activate with a foreign backend guard: err=%v, want a boot error naming the guard and its owner", err)
|
||||
}
|
||||
|
||||
clean := phase10App(t, "development", nil)
|
||||
if _, err := cabana.Activate(clean, []party.Plugin{demoPlugin{fsys: demoFS()}}); err != nil {
|
||||
t.Fatalf("Activate without a conflicting guard: %v", err)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user