Wildcard origins follow the shell-glob convention: **. for apex+any depth, *. for one level
'**.example.com' covers the apex and subdomains at any depth;
'*.example.com' covers exactly one subdomain level (neither apex nor
deeper) — analogous to permission scope wildcards, and sidestepping the
DNS/TLS/nginx ambiguity around '*.'. This also allows excluding the apex
where wanted. The seeded/default entry becomes '**.{rp-id}' (init,
add-domain, legacy empty-origins conversion, branch-era '*' sanitize
rewrite).
This commit is contained in:
@@ -82,13 +82,13 @@ test.describe('Multi-domain E2E', () => {
|
||||
const domains = await list.json()
|
||||
expect(domains.map((r: any) => r.rp_id).sort()).toEqual(['localhost', 'test.localhost'])
|
||||
const localhostDomain = domains.find((r: any) => r.rp_id === 'localhost')
|
||||
expect(localhostDomain.origins).toEqual({ '*.localhost': true })
|
||||
expect(localhostDomain.origins).toEqual({ '**.localhost': true })
|
||||
|
||||
// Add a related origin (unrelated domain) to the localhost domain —
|
||||
// same origins table; classification is derived from the rp-id
|
||||
const patch = await page.request.patch(`${baseUrl}/auth/api/admin/domains/localhost`, {
|
||||
headers,
|
||||
data: { rp_name: '', origins: { '*.localhost': true, 'app.example.com': true } },
|
||||
data: { rp_name: '', origins: { '**.localhost': true, 'app.example.com': true } },
|
||||
})
|
||||
expect(patch.ok()).toBeTruthy()
|
||||
|
||||
@@ -109,7 +109,7 @@ test.describe('Multi-domain E2E', () => {
|
||||
// Restore: back to the pristine seeded state for later tests
|
||||
const restore = await page.request.patch(`${baseUrl}/auth/api/admin/domains/localhost`, {
|
||||
headers,
|
||||
data: { rp_name: '', origins: { '*.localhost': true } },
|
||||
data: { rp_name: '', origins: { '**.localhost': true } },
|
||||
})
|
||||
expect(restore.ok()).toBeTruthy()
|
||||
const after = await page.request.get(`${baseUrl}/.well-known/webauthn`)
|
||||
@@ -138,7 +138,7 @@ test.describe('Multi-domain E2E', () => {
|
||||
// *.localhost hostname to loopback, so the auth host is reachable.
|
||||
const patch = await page.request.patch(`${baseUrl}/auth/api/admin/domains/test.localhost`, {
|
||||
headers,
|
||||
data: { rp_name: '', origins: { [`http://${authHost}`]: { auth_host: true }, '*.test.localhost': true } },
|
||||
data: { rp_name: '', origins: { [`http://${authHost}`]: { auth_host: true }, '**.test.localhost': true } },
|
||||
})
|
||||
expect(patch.ok()).toBeTruthy()
|
||||
|
||||
@@ -168,7 +168,7 @@ test.describe('Multi-domain E2E', () => {
|
||||
// test.localhost, and an empty table would allow nothing)
|
||||
const restore = await page.request.patch(`${baseUrl}/auth/api/admin/domains/test.localhost`, {
|
||||
headers,
|
||||
data: { rp_name: '', origins: { '*.test.localhost': true } },
|
||||
data: { rp_name: '', origins: { '**.test.localhost': true } },
|
||||
})
|
||||
expect(restore.ok()).toBeTruthy()
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user