Close the last three UI leftovers: shared staff HTML, cookie domain, stock Swagger label.
Some checks are pending
offline / test (push) Waiting to run

verae-staff-ui holds one review template for CS and access-staff.
Staff cookies take STAFF_COOKIE_DOMAIN for a reverse-proxy host.
/docs stays vendor Swagger with an integrator banner only.
This commit is contained in:
George Lambert 2026-09-11 18:22:57 -04:00
parent b68fefdea8
commit d8efffe8be
23 changed files with 368 additions and 44 deletions

View file

@ -1,6 +1,6 @@
import { test } from 'node:test';
import assert from 'node:assert/strict';
import { sessionToken, cookieOk, headerOk } from '../src/token.js';
import { sessionToken, cookieOk, headerOk, cookieHeader } from '../src/token.js';
test('cookie matches HMAC of staff key', () => {
const tok = sessionToken();
@ -9,3 +9,11 @@ test('cookie matches HMAC of staff key', () => {
assert.equal(cookieOk({ headers: { cookie: 'staff_session=nope' } }), false);
assert.equal(headerOk({ headers: { 'x-staff-key': process.env.STAFF_KEY || 'admin-dev-key' } }), true);
});
test('cookie Domain is optional', () => {
delete process.env.STAFF_COOKIE_DOMAIN;
assert.equal(cookieHeader().includes('Domain='), false);
process.env.STAFF_COOKIE_DOMAIN = '.example.com';
assert.match(cookieHeader(), /Domain=\.example.com/);
delete process.env.STAFF_COOKIE_DOMAIN;
});