Public Access
Options, JWT bearer validation, the /meta and .well-known endpoints, and a dev compose stack with Keycloak. Verified end to end: compose up, migrate, run, both discovery endpoints return correct payloads, and readiness reports the schema current. Configuration: - Strongly-typed options for Server, Oidc, Relay and Sync, all ValidateOnStart. A self-hosted server that boots half-configured and fails later per-request is far harder to diagnose than one that refuses to start and names the bad setting. - Cross-field validation the annotations cannot express: relay needs a WebSocketUrl when enabled, idle timeout must be under max session duration, item payload cap under batch cap. - Startup warnings for combinations that are individually valid but dangerous together: RequireHttpsMetadata false outside Development, and AllowEmailLinking (which turns any token bearing a victim's email into account takeover, hence default false). Auth: - JwtBearer with ClockSkew cut to 30s from the 5-minute default; five minutes of slack on a credential granting vault ciphertext access is more than any clock needs. - IncludeErrorDetails off, and a FallbackPolicy so an endpoint without an explicit policy still requires a caller rather than silently being public. Discovery, per ADR 0002: - /api/v1/meta reports versions, features and push caps. - /.well-known/dodossh-configuration is the onboarding story: the user types one server URL and the client discovers OIDC authority, client id, scopes and relay endpoint. Two environment problems found by actually running the stack: - PostgreSQL 18 changed its data mount point. Mounting /var/lib/postgresql/data — correct through 17 — makes the image refuse to start; 18+ wants a single mount at /var/lib/postgresql with the cluster in a subdirectory. - Keycloak moved to host port 18080. An unrelated Apache Tomcat on this machine holds 127.0.0.1:8080, and a loopback-specific bind beats Docker's 0.0.0.0 publish for "localhost". It presents as Keycloak 404ing every realm while its own log says the import succeeded, which is a genuinely misleading failure. Also: CA1848 is enforced, not advisory — warnings are errors, so the .editorconfig comment claiming otherwise was wrong. Startup and health logging now uses [LoggerMessage]. And a clean rebuild is back to zero warnings; the incremental build had been hiding 40 in test projects (banned Guid.NewGuid, an obsolete Testcontainers constructor, and two analyzer families that are genuinely noise under a test host). Verified: 0 warnings on a clean rebuild, 122 tests pass, format clean.
61 lines
2.1 KiB
C#
61 lines
2.1 KiB
C#
using DodoSSH.Infrastructure;
|
|
using Microsoft.EntityFrameworkCore;
|
|
using Testcontainers.PostgreSql;
|
|
using Xunit;
|
|
|
|
namespace DodoSSH.Infrastructure.Tests;
|
|
|
|
/// <summary>
|
|
/// One PostgreSQL container per test assembly, migrated once.
|
|
/// </summary>
|
|
/// <remarks>
|
|
/// A container per test would dominate the runtime. Tests that write must therefore use distinct
|
|
/// identifiers rather than assuming an empty database.
|
|
/// </remarks>
|
|
public sealed class PostgresFixture : IAsyncLifetime
|
|
{
|
|
// Image passed to the constructor: the parameterless overload is obsolete in
|
|
// Testcontainers 4.13 and pinning the tag here keeps the test image in step with the one
|
|
// deploy/docker-compose.dev.yml uses.
|
|
private readonly PostgreSqlContainer container = new PostgreSqlBuilder("postgres:18-alpine")
|
|
.WithDatabase("dodossh")
|
|
.WithUsername("postgres")
|
|
.WithPassword("test")
|
|
.Build();
|
|
|
|
/// <summary>Connection string for the running container.</summary>
|
|
public string ConnectionString => container.GetConnectionString();
|
|
|
|
/// <inheritdoc />
|
|
public async ValueTask InitializeAsync()
|
|
{
|
|
await container.StartAsync();
|
|
|
|
await using var context = CreateContext();
|
|
await context.Database.MigrateAsync();
|
|
}
|
|
|
|
/// <inheritdoc />
|
|
public async ValueTask DisposeAsync() => await container.DisposeAsync();
|
|
|
|
/// <summary>Creates a context against the container.</summary>
|
|
public DodoDbContext CreateContext()
|
|
{
|
|
var options = new DbContextOptionsBuilder<DodoDbContext>()
|
|
.UseNpgsql(ConnectionString, npgsql =>
|
|
npgsql.MigrationsHistoryTable("__EFMigrationsHistory", DodoDbContext.SchemaName))
|
|
.UseSnakeCaseNamingConvention()
|
|
.Options;
|
|
|
|
return new DodoDbContext(options);
|
|
}
|
|
}
|
|
|
|
/// <summary>Shares one container across every test class in the assembly.</summary>
|
|
[CollectionDefinition(Name)]
|
|
public sealed class PostgresCollection : ICollectionFixture<PostgresFixture>
|
|
{
|
|
/// <summary>Collection name.</summary>
|
|
public const string Name = "postgres";
|
|
}
|