관리자 서버 진단에 lease 상태와 영속 장애 이력 추가

This commit is contained in:
2026-09-09 23:36:16 +00:00
parent 9c73085353
commit a00f46dfc8
19 changed files with 627 additions and 43 deletions
@@ -435,6 +435,35 @@ describe('admin profile navigation API', () => {
});
});
describe('runtime diagnostics authorization', () => {
it('allows the scoped administrator and rejects another profile scope', async () => {
const harness = await buildCaller(
async () => {
throw new Error('not used');
},
{ adminRoles: ['admin.profiles.runtime:che:2'], firstUserIsAdmin: false }
);
await expect(harness.caller.admin.profiles.diagnostics({ profileName: 'che:2' })).resolves.toMatchObject({
profileName: 'che:2',
incidents: [],
});
await expect(harness.caller.admin.profiles.diagnostics({ profileName: 'kwe:2' })).rejects.toMatchObject({
code: 'FORBIDDEN',
});
});
it('rejects users without profile administration permission', async () => {
const harness = await buildCaller(
async () => {
throw new Error('not used');
},
{ adminRoles: [], firstUserIsAdmin: false }
);
await expect(harness.caller.admin.profiles.diagnostics({ profileName: 'che:2' })).rejects.toMatchObject({
code: 'FORBIDDEN',
});
});
});
describe('admin scenario catalog API', () => {
it('marks scenario zero as the current selectable scenario', async () => {
const harness = await buildCaller(
@@ -174,6 +174,36 @@ const postTrpc = async (
};
describe('admin security over HTTP transport', () => {
it('protects runtime diagnostics at the HTTP authentication and profile scope boundaries', async () => {
const harness = await createHarness(['admin.profiles.runtime:che:default']);
const input = { profileName: 'che:default' };
expect((await postTrpc(harness.baseUrl, 'admin.profiles.diagnostics', input)).response.status).toBe(401);
expect(
(await postTrpc(harness.baseUrl, 'admin.profiles.diagnostics', input, harness.adminSessionToken)).response
.status
).toBe(200);
expect(
(
await postTrpc(
harness.baseUrl,
'admin.profiles.diagnostics',
{ profileName: 'kwe:default' },
harness.adminSessionToken
)
).response.status
).toBe(403);
expect(
(
await postTrpc(
harness.baseUrl,
'admin.profiles.diagnostics',
{ profileName: '' },
harness.adminSessionToken
)
).response.status
).toBe(400);
});
it('accepts query input from a POST JSON body but still rejects a mutation sent as GET', async () => {
const harness = await createHarness();