fix: fall back to enroll token when pilot tunnel JWT is rejected (#1566)

* fix: fall back to enroll token when pilot tunnel JWT is rejected

On HTTP 401/404 upgrade rejection, delete stale pilot.jwt and retry with SENCHO_ENROLL_TOKEN.

* test: import pilot agent module after DATA_DIR is set in fallback test

The auth-fallback test statically imported pilot/agent, which freezes its
pilot.jwt path from DATA_DIR at module load, before setupTestDb redirects
DATA_DIR to a writable temp dir. On the Linux CI runner the path resolved
to a non-writable /app/data, so persistToken silently failed and the
round-trip assertion read null. Import the module dynamically in beforeAll
after setupTestDb, matching the sibling unit test.

* fix: remove unexpected-response listener that blocked pilot reconnect

The ws library skips abortHandshake when an unexpected-response listener
exists, so error and close never fire and the agent hangs in CONNECTING.
Detect auth rejection via the abortHandshake error message instead; the
close handler already performs enroll-token fallback and reconnect.
This commit is contained in:
Anso
2026-07-05 01:03:09 -04:00
committed by GitHub
parent fdbc1b1ebb
commit c677b8bb66
6 changed files with 368 additions and 11 deletions
@@ -33,6 +33,7 @@ describe('PilotAgent loopback auth injection', () => {
primaryUrl: 'http://primary.invalid',
loopbackPort: 1,
initialToken: 'irrelevant-for-this-test',
enrollToken: null,
enrolling: false,
});
mintHeader = (agent as unknown as { getLoopbackAuthHeader: () => string | null }).getLoopbackAuthHeader.bind(agent);