fix: dedupe IdP auto-redirect and fix CSP/bfcache bug on the SPA shell
- Extract tryAutoRedirectToIdp() on the login page so onMount's redirect guard and the post-setup flow share one check instead of drifting. - Fix a real bug: 304 Not Modified responses carry no Content-Type, so is_html misclassified them and attached the strict headerless CSP, which browsers merge into the cached 200's effective headers and defeat the SPA's hash-based CSP on revalidated repeat visits. - Add Cache-Control: no-store on the SPA shell to opt out of bfcache, preventing a pre-deploy shell (stale inline hydration script + CSP hash) from being resurrected byte-for-byte across the OIDC redirect's full-page navigations. - Add a manual, human-run SSO-only script/env (ports 8090/1081) since the automated oidc.hurl suite keeps password login enabled and never exercises the auto-redirect guard.
This commit is contained in:
@@ -180,6 +180,12 @@ front-design:
|
||||
# --config server-with-oidc.env so the
|
||||
# api and webdav suites stay on the
|
||||
# OIDC-off config.
|
||||
# * tests/oidc/run-manual-sso-only.sh — NOT part of this chain (see
|
||||
# `oidc-manual-sso-only` below): a
|
||||
# http://localhost:8090/files/1bf4713c-891e-46fb-acf0-b10231fe32c8 human-run check that OIDC-as-only-
|
||||
# login-method actually redirects a
|
||||
# real browser, which the curl-driven
|
||||
# suite above can't observe.
|
||||
#
|
||||
# Same chain runs in CI under the `api-test` job in
|
||||
# .github/workflows/ci.yml; keep the order in sync so a local pass means
|
||||
@@ -228,6 +234,13 @@ test-caldav:
|
||||
cargo build
|
||||
./tests/caldav/run-pycaldav.sh
|
||||
|
||||
# Manual, human-run: launches OxiCloud with OIDC as the ONLY login method
|
||||
# (fake IdP on :1081, server on :8090) and waits for you to eyeball the
|
||||
# /login auto-redirect in a real browser. Not part of `just api-test` —
|
||||
# there's no automated assertion here, it's a visual check. Ctrl-C to stop.
|
||||
#oidc-manual-sso-only:
|
||||
# bash tests/oidc/run-manual-sso-only.sh
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# SvelteKit frontend (frontend/) — the only frontend. These `fe-*` recipes
|
||||
# drive its dev server, build, lint and tests.
|
||||
|
||||
Reference in New Issue
Block a user