fix: dedupe IdP auto-redirect and fix CSP/bfcache bug on the SPA shell

- Extract tryAutoRedirectToIdp() on the login page so onMount's redirect
  guard and the post-setup flow share one check instead of drifting.
- Fix a real bug: 304 Not Modified responses carry no Content-Type, so
  is_html misclassified them and attached the strict headerless CSP,
  which browsers merge into the cached 200's effective headers and
  defeat the SPA's hash-based CSP on revalidated repeat visits.
- Add Cache-Control: no-store on the SPA shell to opt out of bfcache,
  preventing a pre-deploy shell (stale inline hydration script + CSP
  hash) from being resurrected byte-for-byte across the OIDC redirect's
  full-page navigations.
- Add a manual, human-run SSO-only script/env (ports 8090/1081) since
  the automated oidc.hurl suite keeps password login enabled and never
  exercises the auto-redirect guard.
This commit is contained in:
M.Schmidt
2026-07-15 21:03:17 +02:00
parent 1acac1d699
commit 6215f37bf6
7 changed files with 328 additions and 11 deletions
+13
View File
@@ -180,6 +180,12 @@ front-design:
# --config server-with-oidc.env so the
# api and webdav suites stay on the
# OIDC-off config.
# * tests/oidc/run-manual-sso-only.sh — NOT part of this chain (see
# `oidc-manual-sso-only` below): a
# http://localhost:8090/files/1bf4713c-891e-46fb-acf0-b10231fe32c8 human-run check that OIDC-as-only-
# login-method actually redirects a
# real browser, which the curl-driven
# suite above can't observe.
#
# Same chain runs in CI under the `api-test` job in
# .github/workflows/ci.yml; keep the order in sync so a local pass means
@@ -228,6 +234,13 @@ test-caldav:
cargo build
./tests/caldav/run-pycaldav.sh
# Manual, human-run: launches OxiCloud with OIDC as the ONLY login method
# (fake IdP on :1081, server on :8090) and waits for you to eyeball the
# /login auto-redirect in a real browser. Not part of `just api-test` —
# there's no automated assertion here, it's a visual check. Ctrl-C to stop.
#oidc-manual-sso-only:
# bash tests/oidc/run-manual-sso-only.sh
# ---------------------------------------------------------------------------
# SvelteKit frontend (frontend/) — the only frontend. These `fe-*` recipes
# drive its dev server, build, lint and tests.