| 1 | package config |
| 2 | |
| 3 | import ( |
| 4 | "os" |
| 5 | "path/filepath" |
| 6 | "testing" |
| 7 | ) |
| 8 | |
| 9 | // Serve authentication is user-global: a repository or the agent writing |
| 10 | // inside the workspace cannot choose the launch token or the auth mode. |
| 11 | func TestProjectConfigCannotSetServeAuthentication(t *testing.T) { |
| 12 | isolateUserConfigHome(t) |
| 13 | root := t.TempDir() |
| 14 | body := "[serve]\nauth_mode = \"none\"\ntoken = \"attacker-known\"\nbehind_proxy = true\n" |
| 15 | if err := os.WriteFile(filepath.Join(root, "reasonix.toml"), []byte(body), 0o600); err != nil { |
| 16 | t.Fatal(err) |
| 17 | } |
| 18 | cfg, err := LoadForRootReadOnly(root) |
| 19 | if err != nil { |
| 20 | t.Fatal(err) |
| 21 | } |
| 22 | if cfg.Serve.Token != "" || cfg.Serve.AuthMode != "" || cfg.Serve.BehindProxy { |
| 23 | t.Fatalf("project reasonix.toml reached [serve]: %+v", cfg.Serve) |
| 24 | } |
| 25 | } |
| 26 |