test(oidc): test auto_redirect_if_standalone_oidc and RP iniiate logout
This commit is contained in:
@@ -0,0 +1,64 @@
|
||||
# OxiCloud test-server env file for the SSO-only, NO-auto-redirect posture.
|
||||
#
|
||||
# Same as server-with-oidc-only.env EXCEPT OXICLOUD_AUTH_POLICIES is not
|
||||
# set. Proves the /login middleware is opt-in — with AUTH_METHODS=oidc
|
||||
# alone the SPA still renders at /login (with just the SSO button) and
|
||||
# the middleware falls through. Under this posture the user has to click
|
||||
# the button to start the OIDC flow instead of being auto-redirected.
|
||||
#
|
||||
# Paired with tests/oidc/sso-only-no-policy.hurl; both driven by the
|
||||
# `run-sso-only.sh` runner in a two-phase sequence.
|
||||
|
||||
# ── Shared test config (mirrors server.env) ────────────────────────────────
|
||||
DATABASE_URL=postgres://oxicloud_test:oxicloud_test@localhost:5433/oxicloud_test
|
||||
OXICLOUD_DB_CONNECTION_STRING=postgres://oxicloud_test:oxicloud_test@localhost:5433/oxicloud_test
|
||||
OXICLOUD_STATIC_PATH=./static
|
||||
OXICLOUD_JWT_SECRET=test-secret-do-not-use-in-prod-minimum-32-chars
|
||||
OXICLOUD_ENABLE_AUTH=true
|
||||
OXICLOUD_ENABLE_TRASH=true
|
||||
OXICLOUD_ENABLE_SEARCH=true
|
||||
OXICLOUD_ENABLE_FILE_SHARING=true
|
||||
OXICLOUD_ENABLE_MUSIC=true
|
||||
OXICLOUD_EXPOSE_SYSTEM_USERS=true
|
||||
OXICLOUD_WOPI_ENABLED=false
|
||||
OXICLOUD_NEXTCLOUD_ENABLED=true
|
||||
|
||||
RUST_LOG="warn,audit=info,oxicloud::infrastructure::services::oidc_service=info,oxicloud::application::services::auth_application_service=info"
|
||||
|
||||
OXICLOUD_RATE_LIMIT_REFRESH_MAX=3600
|
||||
OXICLOUD_RATE_LIMIT_LOGIN_MAX=3600
|
||||
OXICLOUD_RATE_LIMIT_REGISTER_MAX=3600
|
||||
OXICLOUD_TRUST_PROXY_CIDR=0.0.0.0/0
|
||||
|
||||
# Mock SMTP — kept wired even though magic-link login is disabled under the
|
||||
# OIDC master rule, so the invite/mail transport doesn't 503 unconfigured.
|
||||
OXICLOUD_SMTP_MOCK=true
|
||||
OXICLOUD_SMTP_HOST=localhost
|
||||
OXICLOUD_SMTP_PORT=25
|
||||
OXICLOUD_SMTP_FROM='OxiCloud Tests <test@oxicloud.local>'
|
||||
OXICLOUD_SMTP_TLS=none
|
||||
OXICLOUD_ALLOW_EXTERNAL_USERS=true
|
||||
|
||||
# ── OIDC client wired at the fake-idp sidecar (SSO-only) ───────────────────
|
||||
OXICLOUD_OIDC_ENABLED=true
|
||||
OXICLOUD_OIDC_ISSUER_URL=http://localhost:1081
|
||||
OXICLOUD_OIDC_CLIENT_ID=oxicloud-test
|
||||
OXICLOUD_OIDC_CLIENT_SECRET=test-client-secret-not-used-in-prod
|
||||
OXICLOUD_OIDC_REDIRECT_URI=http://localhost:8090/api/auth/oidc/callback
|
||||
OXICLOUD_OIDC_SCOPES="openid profile email"
|
||||
OXICLOUD_OIDC_FRONTEND_URL=http://localhost:8090
|
||||
OXICLOUD_OIDC_AUTO_PROVISION=true
|
||||
OXICLOUD_OIDC_PROVIDER_NAME=MockSSO-NoPolicy
|
||||
OXICLOUD_OIDC_ADMIN_GROUPS=admin-users
|
||||
|
||||
# Same modern SSO-only mechanism as server-with-oidc-only.env.
|
||||
OXICLOUD_AUTH_METHODS=oidc
|
||||
|
||||
# ── The DELIBERATE OMISSION ────────────────────────────────────────────────
|
||||
# OXICLOUD_AUTH_POLICIES is NOT set here. This is the whole point of the
|
||||
# test — with AUTH_METHODS=oidc alone, the login middleware in
|
||||
# src/interfaces/web/mod.rs::oidc_standalone_login_redirect must fall
|
||||
# through (SPA shell served at /login) instead of returning 302. The
|
||||
# with-policy variant (server-with-oidc-only.env) proves the flip side.
|
||||
|
||||
OXICLOUD_REQUIRE_VERIFIED_EMAIL=false
|
||||
@@ -1,18 +1,25 @@
|
||||
# OxiCloud test-server env file for the MANUAL SSO-only auto-redirect test.
|
||||
# OxiCloud test-server env file for the SSO-only auto-redirect test.
|
||||
#
|
||||
# Layered on top of server-with-oidc.env: identical EXCEPT
|
||||
# OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN=true, which makes OIDC the ONLY
|
||||
# login method (magic-link is already hard-disabled whenever OIDC is
|
||||
# enabled, per the "OIDC master rule" — see example.env). This is the
|
||||
# config the frontend's login-page auto-redirect guard
|
||||
# (frontend/src/routes/login/+page.svelte) actually fires under —
|
||||
# tests/common/server-with-oidc.env keeps password login on, so the
|
||||
# automated tests/oidc/oidc.hurl suite never exercises the redirect.
|
||||
# Used by BOTH runners on port 8090 / IdP 1081:
|
||||
# * tests/oidc/run-sso-only.sh — automated, drives Hurl assertions
|
||||
# (server-side /login 302 + RP-initiated logout post_logout_url shape).
|
||||
# * tests/oidc/run-manual-sso-only.sh — human-run browser eyeball to
|
||||
# confirm zero login-form flash before the redirect fires.
|
||||
#
|
||||
# Used by tests/oidc/run-manual-sso-only.sh (human-run, not CI). Distinct
|
||||
# ports (8090 / IdP 1081) so it doesn't collide with a concurrently running
|
||||
# `just api-test` (which uses 8087 / IdP 1080) or a local `cargo run` dev
|
||||
# server.
|
||||
# What makes it "SSO-only":
|
||||
# * OXICLOUD_AUTH_METHODS=oidc — allowlist is [Oidc] only. Password
|
||||
# and magic-link are both hard-off at the deployment level; the
|
||||
# fail-fast validator in config.rs refuses to boot if `oidc` is in
|
||||
# the list without OXICLOUD_OIDC_ENABLED=true (or vice versa in a
|
||||
# future major).
|
||||
# * OXICLOUD_AUTH_POLICIES=auto_redirect_if_standalone_oidc — the
|
||||
# policy switch that makes GET /login return a server-side 302 to
|
||||
# /api/auth/oidc/authorize BEFORE the SPA loads (no form flash).
|
||||
# Interception lives in src/interfaces/web/mod.rs.
|
||||
#
|
||||
# Distinct ports (8090 / IdP 1081) so it doesn't collide with a
|
||||
# concurrently running `just api-test` (which uses 8087 / IdP 1080) or a
|
||||
# local `cargo run` dev server.
|
||||
#
|
||||
# `--config` makes the binary read THIS file verbatim — there is no
|
||||
# auto-merge with server.env, so every variable the server needs has
|
||||
@@ -70,9 +77,21 @@ OXICLOUD_OIDC_PROVIDER_NAME=MockSSO-Only
|
||||
# Group-to-role mapping — same fake-idp claim shape as server-with-oidc.env.
|
||||
OXICLOUD_OIDC_ADMIN_GROUPS=admin-users
|
||||
|
||||
# The single flag that makes OIDC the ONLY login method: is_password_login_allowed()
|
||||
# is exactly `!disable_password_login` (auth_application_service.rs). Magic-link
|
||||
# is already hard-disabled whenever OIDC is enabled, regardless of AUTH_METHODS.
|
||||
OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN=true
|
||||
# Modern SSO-only mechanism (preferred over legacy
|
||||
# OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN=true, which still works but is a
|
||||
# per-flag toggle instead of the composable allowlist below).
|
||||
#
|
||||
# AUTH_METHODS=oidc restricts the effective allowlist to [Oidc]. Password
|
||||
# and magic-link both refuse at the endpoint layer. Combined with the
|
||||
# OIDC master rule (magic-link hard-off whenever OIDC is enabled) this
|
||||
# closes every non-SSO login path.
|
||||
OXICLOUD_AUTH_METHODS=oidc
|
||||
|
||||
# AUTH_POLICIES: additive switches to auth behavior. The
|
||||
# auto_redirect_if_standalone_oidc token makes GET /login return a 302
|
||||
# to /api/auth/oidc/authorize (server-side, via web-layer middleware) so
|
||||
# the SPA never renders. Loop-guards are built in — a Location or
|
||||
# ?error= query on /login falls through to the SPA shell.
|
||||
OXICLOUD_AUTH_POLICIES=auto_redirect_if_standalone_oidc
|
||||
|
||||
OXICLOUD_REQUIRE_VERIFIED_EMAIL=false
|
||||
|
||||
Reference in New Issue
Block a user