test(oidc): test auto_redirect_if_standalone_oidc and RP iniiate logout

This commit is contained in:
Edouard Vanbelle
2026-08-03 21:35:54 +02:00
parent 921cbef152
commit ac32595846
7 changed files with 583 additions and 17 deletions
+36 -17
View File
@@ -1,18 +1,25 @@
# OxiCloud test-server env file for the MANUAL SSO-only auto-redirect test.
# OxiCloud test-server env file for the SSO-only auto-redirect test.
#
# Layered on top of server-with-oidc.env: identical EXCEPT
# OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN=true, which makes OIDC the ONLY
# login method (magic-link is already hard-disabled whenever OIDC is
# enabled, per the "OIDC master rule" — see example.env). This is the
# config the frontend's login-page auto-redirect guard
# (frontend/src/routes/login/+page.svelte) actually fires under —
# tests/common/server-with-oidc.env keeps password login on, so the
# automated tests/oidc/oidc.hurl suite never exercises the redirect.
# Used by BOTH runners on port 8090 / IdP 1081:
# * tests/oidc/run-sso-only.sh — automated, drives Hurl assertions
# (server-side /login 302 + RP-initiated logout post_logout_url shape).
# * tests/oidc/run-manual-sso-only.sh — human-run browser eyeball to
# confirm zero login-form flash before the redirect fires.
#
# Used by tests/oidc/run-manual-sso-only.sh (human-run, not CI). Distinct
# ports (8090 / IdP 1081) so it doesn't collide with a concurrently running
# `just api-test` (which uses 8087 / IdP 1080) or a local `cargo run` dev
# server.
# What makes it "SSO-only":
# * OXICLOUD_AUTH_METHODS=oidc — allowlist is [Oidc] only. Password
# and magic-link are both hard-off at the deployment level; the
# fail-fast validator in config.rs refuses to boot if `oidc` is in
# the list without OXICLOUD_OIDC_ENABLED=true (or vice versa in a
# future major).
# * OXICLOUD_AUTH_POLICIES=auto_redirect_if_standalone_oidc — the
# policy switch that makes GET /login return a server-side 302 to
# /api/auth/oidc/authorize BEFORE the SPA loads (no form flash).
# Interception lives in src/interfaces/web/mod.rs.
#
# Distinct ports (8090 / IdP 1081) so it doesn't collide with a
# concurrently running `just api-test` (which uses 8087 / IdP 1080) or a
# local `cargo run` dev server.
#
# `--config` makes the binary read THIS file verbatim — there is no
# auto-merge with server.env, so every variable the server needs has
@@ -70,9 +77,21 @@ OXICLOUD_OIDC_PROVIDER_NAME=MockSSO-Only
# Group-to-role mapping — same fake-idp claim shape as server-with-oidc.env.
OXICLOUD_OIDC_ADMIN_GROUPS=admin-users
# The single flag that makes OIDC the ONLY login method: is_password_login_allowed()
# is exactly `!disable_password_login` (auth_application_service.rs). Magic-link
# is already hard-disabled whenever OIDC is enabled, regardless of AUTH_METHODS.
OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN=true
# Modern SSO-only mechanism (preferred over legacy
# OXICLOUD_OIDC_DISABLE_PASSWORD_LOGIN=true, which still works but is a
# per-flag toggle instead of the composable allowlist below).
#
# AUTH_METHODS=oidc restricts the effective allowlist to [Oidc]. Password
# and magic-link both refuse at the endpoint layer. Combined with the
# OIDC master rule (magic-link hard-off whenever OIDC is enabled) this
# closes every non-SSO login path.
OXICLOUD_AUTH_METHODS=oidc
# AUTH_POLICIES: additive switches to auth behavior. The
# auto_redirect_if_standalone_oidc token makes GET /login return a 302
# to /api/auth/oidc/authorize (server-side, via web-layer middleware) so
# the SPA never renders. Loop-guards are built in — a Location or
# ?error= query on /login falls through to the SPA shell.
OXICLOUD_AUTH_POLICIES=auto_redirect_if_standalone_oidc
OXICLOUD_REQUIRE_VERIFIED_EMAIL=false