Run the instance in private mode when instance_url is not configured: the API rejects anonymous requests except the auth-bootstrap set (sign-in, token refresh, instance profile/settings, SSO providers, share-link access) plus first-run user creation, and the web UI redirects anonymous visitors to /auth instead of /explore. Setting instance_url keeps the current public behavior. Access tokens and personal access tokens are never gated. Enforcement lives in a shared Authorizer used by both the Connect interceptor and the gRPC-gateway middleware; the file server applies the same rule to public-memo attachments and avatars. Also merges the duplicated Authenticate/AuthenticateToUser token dispatch behind resolveBearer, dedups the AuthContext unauthenticated state, extracts the redirect decision into a pure shouldGatePrivateInstance helper, and prints the access mode at startup.
34 lines
1.2 KiB
Go
34 lines
1.2 KiB
Go
package auth
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
// TestAuthenticateNoCredentials covers the store-free paths: absent or malformed
|
|
// credentials must resolve to "unauthenticated" without touching the store.
|
|
// Token-valid paths are exercised by the API/fileserver integration tests.
|
|
func TestAuthenticateNoCredentials(t *testing.T) {
|
|
ctx := context.Background()
|
|
a := &Authenticator{secret: "test-secret"} // nil store: these paths never reach it.
|
|
|
|
t.Run("Authenticate returns nil without an Authorization header", func(t *testing.T) {
|
|
assert.Nil(t, a.Authenticate(ctx, ""))
|
|
})
|
|
t.Run("Authenticate returns nil for a malformed bearer token", func(t *testing.T) {
|
|
assert.Nil(t, a.Authenticate(ctx, "Bearer not-a-valid-jwt"))
|
|
})
|
|
|
|
t.Run("AuthenticateToUser returns nil without any credentials", func(t *testing.T) {
|
|
user, err := a.AuthenticateToUser(ctx, "", "")
|
|
assert.NoError(t, err)
|
|
assert.Nil(t, user)
|
|
})
|
|
t.Run("AuthenticateToUser returns nil for a malformed bearer and no cookie", func(t *testing.T) {
|
|
user, err := a.AuthenticateToUser(ctx, "Bearer not-a-valid-jwt", "")
|
|
assert.NoError(t, err)
|
|
assert.Nil(t, user)
|
|
})
|
|
}
|