fix: only catalog hosts are jump targets (v1.19.0)
isManagedHost() treated a missing metadata.managed flag as permission, so any host the SSO merely discovered -- an unpromoted Proxmox guest, a UniFi client -- was offered in the TUI picker and accepted by the username grammar. Replaced with isCatalogHost(), mirroring the rule the SSO Directory's own listing applies: a resource carrying discovery_sources but never promoted is excluded; hand-created hosts and promoted ones are included; an explicit managed:false is always excluded. The two copies of this rule have now drifted apart once. If a third consumer needs it, hoist it into @simpleworkjs/directory-schema rather than copying again. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -70,6 +70,25 @@ test('allHosts fetches the whole host inventory with no group filter', async ()
|
||||
assert.deepStrictEqual(hosts.map((h) => h.id).sort(), ['1', '2']);
|
||||
});
|
||||
|
||||
// Only catalog content is a jump target. Discovery writes `discovery_sources`;
|
||||
// promoting to the catalog sets `managed: true`. An unpromoted Proxmox VM was
|
||||
// reaching the picker because the filter defaulted `managed`-less hosts to true.
|
||||
test('drops auto-discovered hosts that were never promoted', async () => {
|
||||
clearCache();
|
||||
const user = { uid: 'frank', dn: 'd' };
|
||||
const fetchImpl = stubFetch({
|
||||
frank: [
|
||||
{ id: '1', kind: 'host', slug: 'host_web01' }, // hand-made: no discovery_sources
|
||||
{ id: '2', kind: 'host', slug: 'vm-101', metadata: { discovery_sources: ['proxmox'] } }, // discovered, unpromoted
|
||||
{ id: '3', kind: 'host', slug: 'vm-102', metadata: { discovery_sources: ['proxmox'], managed: true } }, // promoted
|
||||
{ id: '4', kind: 'host', slug: 'host_db', metadata: { discovery_sources: ['manual'] } }, // manual source counts as catalog
|
||||
{ id: '5', kind: 'host', slug: 'host_off', metadata: { managed: false } }, // explicitly out
|
||||
],
|
||||
});
|
||||
const hosts = await accessibleHosts(user, { fetchImpl });
|
||||
assert.deepStrictEqual(hosts.map((h) => h.id).sort(), ['1', '3', '4']);
|
||||
});
|
||||
|
||||
test('a bare-array response (envelope drift) returns empty list', async () => {
|
||||
clearCache();
|
||||
const user = { uid: 'dave', dn: 'd' };
|
||||
|
||||
Reference in New Issue
Block a user