oclaw/uds-auth/test/session-persistence.test.js
oliver df97c5e042
Some checks are pending
ci / test (push) Waiting to run
ci / test-postgresql (push) Waiting to run
fix(uds-auth): emergency login workspaces, Desktop key prompts, persistent sessions
Emergency (fallback / sealed-box) admins lost the workspace sidebar and saw
"sign-in failed / add API key" on DSH Desktop because the remote.mux opens
anonymously at boot and every early call was rejected terminally.

- gateway: anonymous workspace/follow reaches dsh-acl's empty baseline;
  anonymous streams are parked until the carrier aborts instead of failing;
  anonymous workspace/initializeDefault answers "nothing created"
- request-auth: a dead UDS_SESSION cookie no longer shadows a valid WS ticket
  or bridge (sync + async variants used by all callers)
- dsh-acl: /api/* waits (bounded 15s) for the gateway ACL during Host startup
  instead of 403, so the Desktop welcome read no longer fails
- desktop-bootstrap: key/account projection is best-effort per reference
- client: emit connection/reset after login so boot-time caches (settings
  describe mirror -> Settings > Models) re-read under the real principal
- sessions: absolute lifetime fixed at 7 days (was min(ttl, 7d) = 30 min);
  bridge expiry slides with its session; MemoryStore persisted to
  sessions.json (bearer hash only, userData AES-256-GCM sealed)
- README: session lifetime/persistence and DSH compatibility notes

Also includes previously uncommitted uds-auth 0.3.x work in this tree.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-12 02:11:09 +08:00

129 lines
4.4 KiB
JavaScript

import { test } from 'node:test'
import assert from 'node:assert/strict'
import { mkdtemp, readFile, writeFile, rm } from 'node:fs/promises'
import { tmpdir } from 'node:os'
import { join } from 'node:path'
import { MemoryStore } from '../lib/session/memory-store.js'
import { createSessionStore } from '../lib/session/factory.js'
const quiet = { info() {}, warn() {} }
async function freshDir() {
return mkdtemp(join(tmpdir(), 'uds-sessions-'))
}
async function openStore(dir) {
const store = new MemoryStore({ file: join(dir, 'sessions.json'), dataDir: dir, logger: quiet })
await store.init()
return store
}
test('sessions survive a Host restart (emergency login stays logged in)', async () => {
const dir = await freshDir()
try {
const a = await openStore(dir)
const { bearer, sessionId } = await a.create({
empNo: 'administrator',
authMode: 'local-admin-unlock',
displayName: 'Local Admin',
}, 1800)
await a.flush()
await a.clear()
const b = await openStore(dir)
const row = b.getByBearerSync(bearer)
assert.equal(row?.sessionId, sessionId)
assert.equal(row?.empNo, 'administrator')
assert.equal(row?.kind, 'sealed_box')
assert.equal(row?.userData.displayName, 'Local Admin')
assert.equal((await b.getProfile('administrator'))?.displayName, 'Local Admin')
assert.equal(b.getByBearerSync('f'.repeat(64)), null)
await b.clear()
} finally {
await rm(dir, { recursive: true, force: true })
}
})
test('disk holds only the bearer hash; userData (UAC token) is encrypted', async () => {
const dir = await freshDir()
try {
const a = await openStore(dir)
const { bearer } = await a.create({ empNo: '1001', token: 'UAC-SECRET-TOKEN', email: 'x@example.test' }, 1800)
await a.flush()
const disk = await readFile(join(dir, 'sessions.json'), 'utf-8')
assert.equal(disk.includes(bearer), false, 'raw bearer never written')
assert.equal(disk.includes('UAC-SECRET-TOKEN'), false, 'token not in clear')
assert.equal(disk.includes('x@example.test'), false, 'profile fields not in clear')
await a.clear()
} finally {
await rm(dir, { recursive: true, force: true })
}
})
test('expired and tampered rows are dropped on load', async () => {
const dir = await freshDir()
try {
const a = await openStore(dir)
const live = await a.create({ empNo: 'u1' }, 1800)
const dead = await a.create({ empNo: 'u2' }, 1800)
const forged = await a.create({ empNo: 'u3' }, 1800)
await a.flush()
await a.clear()
const file = join(dir, 'sessions.json')
const data = JSON.parse(await readFile(file, 'utf-8'))
for (const row of data.sessions) {
if (row.sessionId === dead.sessionId) row.expiresAt = Date.now() - 1
if (row.sessionId === forged.sessionId) row.userData = row.userData.slice(0, -4) + 'AAAA'
}
await writeFile(file, JSON.stringify(data))
const b = await openStore(dir)
assert.ok(b.getByBearerSync(live.bearer))
assert.equal(b.getByBearerSync(dead.bearer), null)
assert.equal(b.getByBearerSync(forged.bearer), null)
await b.clear()
} finally {
await rm(dir, { recursive: true, force: true })
}
})
test('revocation (logout) is persisted', async () => {
const dir = await freshDir()
try {
const a = await openStore(dir)
const { bearer } = await a.create({ empNo: 'administrator', authMode: 'fallback-password' }, 1800)
await a.revokeBearer(bearer)
await a.flush()
await a.clear()
const b = await openStore(dir)
assert.equal(b.getByBearerSync(bearer), null)
await b.clear()
} finally {
await rm(dir, { recursive: true, force: true })
}
})
test('factory wires persistence; no file configured keeps pure in-memory behavior', async () => {
const dir = await freshDir()
try {
const persisted = await createSessionStore({ storeType: 'memory' }, {
file: join(dir, 'sessions.json'), dataDir: dir, logger: quiet,
})
const { bearer } = await persisted.create({ empNo: 'u1' }, 1800)
await persisted.flush()
await persisted.clear()
const again = await createSessionStore({ storeType: 'memory' }, {
file: join(dir, 'sessions.json'), dataDir: dir, logger: quiet,
})
assert.ok(again.getByBearerSync(bearer))
await again.clear()
const plain = await createSessionStore({ storeType: 'memory' })
await plain.create({ empNo: 'u1' }, 1800)
await plain.flush()
await plain.clear()
} finally {
await rm(dir, { recursive: true, force: true })
}
})