后端移除: - SAML: auth/saml.go, handler/saml_handler.go, account_saml_settings_handler.go, model/account_saml_settings.go, model/saml_idp_config.go, repo/*.go - LDAP: auth/ldap.go, handler/ldap_handler.go, model/account_ldap_settings.go, repo/account_ldap_settings_repo.go - MFA: auth/mfa.go, handler/mfa_handler.go - auth_service: 移除 mfaService 依赖、MFARequired 字段、LoginWithMFA 方法 - auth_handler: 移除 LoginMFA handler、MFA 分支逻辑 - bootstrap: 移除 SAML/LDAP/MFA service 初始化和 handler 注册 - sso_middleware: 精简为仅支持 OIDC provider - router: 移除 SAML/LDAP/MFA 路由注册 - config: 移除 SAMLConfig/LDAPConfig struct 和 defaults 前端移除: - v3/login: 移除 MFA 验证流程和 SAML 登录入口 - v3/api/auth: 移除 MFA 响应处理 - v3/routes: 移除 SSO login 路由 - dashboard: 移除 MFA 设置页面、SAML 安全设置页面 - i18n: 移除 mfa.json - featureFlags: 移除 SAML feature flag .env.example / .env: 移除 SAML/LDAP 配置段
95 lines
2.9 KiB
JavaScript
95 lines
2.9 KiB
JavaScript
import { validateRouteAccess, isOnOnboardingView } from '../RouteHelper';
|
|
import { clearBrowserSessionCookies } from 'dashboard/store/utils/api';
|
|
import { replaceRouteWithReload } from '../CommonHelper';
|
|
import Cookies from 'js-cookie';
|
|
|
|
const next = vi.fn();
|
|
vi.mock('dashboard/store/utils/api', () => ({
|
|
clearBrowserSessionCookies: vi.fn(),
|
|
}));
|
|
vi.mock('../CommonHelper', () => ({ replaceRouteWithReload: vi.fn() }));
|
|
|
|
describe('#validateRouteAccess', () => {
|
|
beforeEach(() => {
|
|
vi.spyOn(Cookies, 'set');
|
|
});
|
|
|
|
afterEach(() => {
|
|
vi.restoreAllMocks();
|
|
});
|
|
|
|
it('reset cookies and continues to the login page if the SSO parameters are present', () => {
|
|
validateRouteAccess(
|
|
{
|
|
name: 'login',
|
|
query: { sso_auth_token: 'random_token', email: 'random@email.com' },
|
|
},
|
|
next
|
|
);
|
|
expect(clearBrowserSessionCookies).toHaveBeenCalledTimes(1);
|
|
expect(next).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it('ignore session and continue to the page if the ignoreSession is present in route definition', () => {
|
|
validateRouteAccess(
|
|
{
|
|
name: 'login',
|
|
meta: { ignoreSession: true },
|
|
},
|
|
next
|
|
);
|
|
expect(clearBrowserSessionCookies).not.toHaveBeenCalled();
|
|
expect(next).toHaveBeenCalledTimes(1);
|
|
});
|
|
|
|
it('redirects to dashboard if auth cookie is present', () => {
|
|
vi.spyOn(Cookies, 'get').mockReturnValueOnce(true);
|
|
|
|
validateRouteAccess({ name: 'login' }, next);
|
|
expect(clearBrowserSessionCookies).not.toHaveBeenCalled();
|
|
expect(replaceRouteWithReload).toHaveBeenCalledWith('/app/');
|
|
expect(next).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it('redirects to login if route is empty', () => {
|
|
validateRouteAccess({}, next);
|
|
expect(clearBrowserSessionCookies).not.toHaveBeenCalled();
|
|
expect(next).toHaveBeenCalledWith('/app/login');
|
|
});
|
|
|
|
it('allows routes that were previously restricted to enterprise installs', () => {
|
|
validateRouteAccess(
|
|
{ name: 'reset_password', meta: { requireEnterprise: true } },
|
|
next
|
|
);
|
|
expect(next).toHaveBeenCalledWith();
|
|
});
|
|
|
|
it('continues to the route in every other case', () => {
|
|
validateRouteAccess({ name: 'reset_password' }, next);
|
|
expect(clearBrowserSessionCookies).not.toHaveBeenCalled();
|
|
expect(next).toHaveBeenCalledWith();
|
|
});
|
|
});
|
|
|
|
describe('isOnOnboardingView', () => {
|
|
test('returns true for a route with onboarding name', () => {
|
|
const route = { name: 'onboarding_welcome' };
|
|
expect(isOnOnboardingView(route)).toBe(true);
|
|
});
|
|
|
|
test('returns false for a route without onboarding name', () => {
|
|
const route = { name: 'home' };
|
|
expect(isOnOnboardingView(route)).toBe(false);
|
|
});
|
|
|
|
test('returns false for a route with null name', () => {
|
|
const route = { name: null };
|
|
expect(isOnOnboardingView(route)).toBe(false);
|
|
});
|
|
|
|
test('returns false for an undefined route object', () => {
|
|
expect(isOnOnboardingView()).toBe(false);
|
|
});
|
|
});
|