| 69 | // Run a block with the SSO env vars swapped out, restoring them afterwards so |
| 70 | // the booted instance's request-time config reads stay consistent. |
| 71 | const withSsoEnv = <T>(overrides: Record<string, string | undefined>, run: () => T): T => { |
| 72 | const saved = Object.fromEntries(SSO_ENV_KEYS.map((k) => [k, process.env[k]])); |
| 73 | for (const key of SSO_ENV_KEYS) { |
| 74 | const value = overrides[key]; |
| 75 | if (value === undefined) delete process.env[key]; |
| 76 | else process.env[key] = value; |
| 77 | } |
| 78 | // oxlint-disable-next-line executor/no-try-catch-or-throw -- boundary: env save/restore around config reads must restore on assertion failure |
| 79 | try { |
| 80 | return run(); |
| 81 | } finally { |
| 82 | for (const key of SSO_ENV_KEYS) { |
| 83 | const value = saved[key]; |
| 84 | if (value === undefined) delete process.env[key]; |
| 85 | else process.env[key] = value; |
| 86 | } |
| 87 | } |
| 88 | }; |
| 89 | |
| 90 | describe("sso config resolution", () => { |
| 91 | it("normalizes the domain allowlist (trim, lowercase, strip @, drop empties)", () => { |