fix: survive an unconfigured identity provider
Auth.js refuses to build a provider with no issuer, and that refusal takes down the whole auth layer — including reading a session that already exists. A missing or misspelled AUTH_AUTHENTIK_ISSUER would therefore lock everyone out of an otherwise healthy application, and explain itself only as a stack trace in the logs. The provider is now registered only when its three settings are present. Sessions stay readable either way, and the sign-in page says which variables are missing instead of offering a button that fails. Found by the first CI run, which has no .env to inherit from: every signed-in test failed at once, looking exactly like a broken cookie. The local suite had been passing on variables Playwright was quietly inheriting from the development environment — so the E2E server is now given explicit placeholders rather than whatever happens to be around. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
@@ -72,6 +72,12 @@ export default defineConfig({
|
||||
AUTH_URL: BASE_URL,
|
||||
AUTH_SECRET: E2E_AUTH_SECRET,
|
||||
AUTHENTIK_ADMIN_GROUP: 'horaires-admins',
|
||||
// Placeholders, never contacted: the suite mints its own session cookie.
|
||||
// They exist so the provider builds and the sign-in page renders its
|
||||
// normal button — CI has no .env to inherit these from.
|
||||
AUTH_AUTHENTIK_ID: 'e2e-client-id',
|
||||
AUTH_AUTHENTIK_SECRET: 'e2e-client-secret',
|
||||
AUTH_AUTHENTIK_ISSUER: 'https://auth.example.test/application/o/e2e/',
|
||||
// The translation service is stubbed per-test; never called for real.
|
||||
TRANSLATION_API_URL: '',
|
||||
TRANSLATION_API_KEY: '',
|
||||
|
||||
Reference in New Issue
Block a user