test(config): make the identity-key test fail when the key is accepted

TestLoadRejectsAuthSourceIdentityKey is the guard against a config line
identity = true making a third-party source's UUIDs trusted as-is. Its
fixture had no prefix, so Load failed on the prefix rule and the test
passed on that error. With the unknown-key check in decodeConfig
disabled, the test still passed.

The fixture now carries a valid prefix, the error must mention unknown
keys and identity, and LoadNano is checked alongside Load. With the
unknown-key check disabled, both loaders now fail the test; the old
version of the test passes against the same change.
This commit is contained in:
flyemoji committed 2026-09-22 13:36:29 +09:00
1 parent 30b4e1dfb2
commit e0ad78af98
1 file changed
+17 -8
+17 -8
View File
@@ -233,19 +233,28 @@ url = "https://guild.example.net/sessionserver/session/minecraft/hasJoined"
// is no identity/trusted field on AuthSourceConfig, so an attempt to set one is an unknown
// key and Load rejects it loudly. A config can therefore never mint a source whose
// self-asserted UUIDs are trusted verbatim — the impersonation hole stays closed.
//
// The source is otherwise valid, so the only thing left to reject is the identity key itself:
// with a missing prefix the prefix rule would fail first and hide a loader that accepts it.
func TestLoadRejectsAuthSourceIdentityKey(t *testing.T) {
_, err := config.Load(writeTOML(t, `
const source = `
[[auth_source]]
tag = "evil"
prefix = "EV"
url = "https://evil.example.net/hasJoined"
identity = true
`
_, errFull := config.Load(writeTOML(t, `
[server]
root_domain = "mc.example.net"
[database]
url = "postgres://felis@db/felis"
[[auth_source]]
tag = "evil"
url = "https://evil.example.net/hasJoined"
identity = true
`))
if err == nil {
t.Fatal("expected error for an identity= key on [[auth_source]]")
`+source))
_, errNano := config.LoadNano(writeTOML(t, source))
for loader, err := range map[string]error{"Load": errFull, "LoadNano": errNano} {
if err == nil || !strings.Contains(err.Error(), "unknown keys") || !strings.Contains(err.Error(), "identity") {
t.Errorf("%s: err = %v, want the identity key rejected as unknown", loader, err)
}
}
}