fix: add main-process Alta session boundary
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
'use strict';
|
||||
|
||||
const test = require('node:test');
|
||||
const assert = require('node:assert/strict');
|
||||
const { SessionStore } = require('../src/session-store');
|
||||
|
||||
const SENTINEL = 'HERMES_SENTINEL_SECRET';
|
||||
|
||||
test('stores a canonical origin and cookie only in main-process memory', () => {
|
||||
const store = new SessionStore();
|
||||
store.establish('https://Tenant.AVASECURITY.com/', SENTINEL);
|
||||
|
||||
assert.deepEqual(store.describe(), {
|
||||
connected: true,
|
||||
origin: 'https://tenant.avasecurity.com',
|
||||
});
|
||||
assert.equal(JSON.stringify(store.describe()).includes(SENTINEL), false);
|
||||
|
||||
const session = store.requireSession();
|
||||
assert.equal(session.origin, 'https://tenant.avasecurity.com');
|
||||
assert.equal(session.cookie, SENTINEL);
|
||||
assert.equal(Object.isFrozen(session), true);
|
||||
});
|
||||
|
||||
test('rejects malformed and header-injecting cookies', () => {
|
||||
const store = new SessionStore();
|
||||
for (const cookie of ['', null, 12, 'secret\r\nX-Evil: yes', `x${'a'.repeat(4096)}`, 'abc\0def', 'token; injected=yes']) {
|
||||
assert.throws(() => store.establish('https://tenant.avasecurity.com', cookie), {
|
||||
code: 'INVALID_SESSION_COOKIE',
|
||||
});
|
||||
}
|
||||
assert.equal(store.describe().connected, false);
|
||||
});
|
||||
|
||||
test('does not replace a valid session when a new session is invalid', () => {
|
||||
const store = new SessionStore();
|
||||
store.establish('https://one.avasecurity.com', SENTINEL);
|
||||
assert.throws(() => store.establish('https://evil.example', 'replacement'));
|
||||
assert.equal(store.requireSession().origin, 'https://one.avasecurity.com');
|
||||
assert.equal(store.requireSession().cookie, SENTINEL);
|
||||
});
|
||||
|
||||
test('clear removes session references and dispose permanently closes the store', () => {
|
||||
const store = new SessionStore();
|
||||
store.establish('https://tenant.avigilon.com', SENTINEL);
|
||||
store.clear();
|
||||
|
||||
assert.deepEqual(store.describe(), { connected: false, origin: null });
|
||||
assert.throws(() => store.requireSession(), { code: 'NO_ALTA_SESSION' });
|
||||
|
||||
store.establish('https://tenant.avigilon.com', 'new-token');
|
||||
store.dispose();
|
||||
assert.deepEqual(store.describe(), { connected: false, origin: null });
|
||||
assert.throws(() => store.establish('https://tenant.avigilon.com', 'again'), {
|
||||
code: 'SESSION_STORE_DISPOSED',
|
||||
});
|
||||
assert.doesNotThrow(() => store.dispose());
|
||||
});
|
||||
Reference in New Issue
Block a user