Files
preauth/tests/Unit/ConfigBagRemoteUserTest.php
T
lyra 9ad54f8e2a
Sync GitHub / sync (push) Successful in 7s
Tests / test (pull_request) Successful in 58s
feat: configurable Remote-User header (design consideration 1.2)
Add REMOTE_USER env var with four modes:
- session (default): sends session id, backward-compatible
- static: sends a fixed string (REMOTE_USER_STATIC)
- mapped: looks up session id in REMOTE_USER_MAP
- none: omits the header entirely

New RemoteUserMode enum, ConfigBag parsing/validation, and
StringTrait::authSuccessResponse resolves the header value based
on the configured mode. AcceptListener now receives ConfigBag as
a constructor dependency.

Addresses design consideration 1.2 (Remote-User header value is
user-controlled) from DESIGN_CONSIDERATIONS.md.

241 tests pass, 0 cs-fixer violations.
2026-08-11 22:48:52 -04:00

90 lines
2.5 KiB
PHP

<?php
declare(strict_types=1);
namespace App\Tests\Unit;
use App\ConfigBag;
use App\Enum\RemoteUserMode;
use App\Tests\Support\TotpTestHelper;
use PHPUnit\Framework\TestCase;
final class ConfigBagRemoteUserTest extends TestCase
{
use TotpTestHelper;
public function testDefaultRemoteUserModeIsSession(): void
{
$config = $this->makeConfig();
self::assertSame(RemoteUserMode::Session, $config->remoteUserMode());
}
public function testStaticMode(): void
{
$config = $this->makeConfig(remoteUserMode: 'static', remoteUserStatic: 'authenticated');
self::assertSame(RemoteUserMode::Static, $config->remoteUserMode());
self::assertSame('authenticated', $config->remoteUserStatic());
}
public function testMappedMode(): void
{
$config = $this->makeConfig(remoteUserMode: 'mapped', remoteUserMap: 'alice:admin,bob:user');
self::assertSame(RemoteUserMode::Mapped, $config->remoteUserMode());
self::assertSame(['alice' => 'admin', 'bob' => 'user'], $config->remoteUserMap());
}
public function testNoneMode(): void
{
$config = $this->makeConfig(remoteUserMode: 'none');
self::assertSame(RemoteUserMode::None, $config->remoteUserMode());
}
public function testInvalidModeFallsBackToSession(): void
{
$config = $this->makeConfig(remoteUserMode: 'invalid-mode');
self::assertSame(RemoteUserMode::Session, $config->remoteUserMode());
}
public function testEmptyMapReturnsEmptyArray(): void
{
$config = $this->makeConfig(remoteUserMode: 'mapped', remoteUserMap: '');
self::assertSame([], $config->remoteUserMap());
}
public function testMapParsesWithWhitespace(): void
{
$config = $this->makeConfig(
remoteUserMode: 'mapped',
remoteUserMap: ' alice : admin , bob : user ',
);
self::assertSame(['alice' => 'admin', 'bob' => 'user'], $config->remoteUserMap());
}
public function testMapIgnoresInvalidEntries(): void
{
$config = $this->makeConfig(
remoteUserMode: 'mapped',
remoteUserMap: 'alice:admin,noColon,bob:user',
);
self::assertSame(['alice' => 'admin', 'bob' => 'user'], $config->remoteUserMap());
}
public function testMapPreservesColonsInValue(): void
{
$config = $this->makeConfig(
remoteUserMode: 'mapped',
remoteUserMap: 'alice:admin:extra',
);
self::assertSame(['alice' => 'admin:extra'], $config->remoteUserMap());
}
}