fix(auth) : keep Guide sessions beyond Sudloh token expiry
This commit is contained in:
@@ -1,7 +1,6 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const session = vi.fn();
|
||||
const validate = vi.fn();
|
||||
const handler = vi.fn(async () => Response.json({ passed: true }));
|
||||
|
||||
vi.mock("server-only", () => ({}));
|
||||
@@ -10,7 +9,6 @@ vi.mock("@/lib/auth/server", () => ({
|
||||
getAuth: () => ({ api: { getSession: session }, handler }),
|
||||
isSudlohOidcEnabled: () => true,
|
||||
}));
|
||||
vi.mock("@/lib/auth/sudloh", () => ({ validateSudlohSession: validate }));
|
||||
|
||||
const { GET, POST } = await import("./route");
|
||||
|
||||
@@ -19,30 +17,27 @@ beforeEach(() => {
|
||||
process.env.BETTER_AUTH_URL = "https://guide.sudloh.com";
|
||||
process.env.SUDLOH_OIDC_ONLY = "true";
|
||||
session.mockResolvedValue({ user: { id: "user-1" }, session: { id: "session-1" } });
|
||||
validate.mockResolvedValue(false);
|
||||
});
|
||||
|
||||
describe("Better Auth Sudloh boundary", () => {
|
||||
it("returns no browser session after Sudloh revokes the bound token", async () => {
|
||||
it("lets Better Auth serve the local browser session", async () => {
|
||||
const response = await GET(new Request("https://guide.sudloh.com/api/auth/get-session"));
|
||||
expect(response.status).toBe(200);
|
||||
expect(await response.json()).toBeNull();
|
||||
expect(handler).not.toHaveBeenCalled();
|
||||
expect(await response.json()).toEqual({ passed: true });
|
||||
expect(handler).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
it("denies other account endpoints but permits the OIDC callback", async () => {
|
||||
const denied = await GET(new Request("https://guide.sudloh.com/api/auth/list-sessions"));
|
||||
expect(denied.status).toBe(401);
|
||||
it("permits the OIDC callback", async () => {
|
||||
const callback = await GET(new Request("https://guide.sudloh.com/api/auth/callback/sudloh?code=code"));
|
||||
expect(callback.status).toBe(200);
|
||||
});
|
||||
|
||||
it("denies Better Auth mutations with a revoked local session", async () => {
|
||||
it("passes mutations to Better Auth for local session checks", async () => {
|
||||
const response = await POST(new Request("https://guide.sudloh.com/api/auth/admin/create-user", {
|
||||
method: "POST", headers: { Origin: "https://guide.sudloh.com", "Content-Type": "application/json" },
|
||||
body: JSON.stringify({ password: "example-password" }),
|
||||
}));
|
||||
expect(response.status).toBe(401);
|
||||
expect(handler).not.toHaveBeenCalled();
|
||||
expect(response.status).toBe(200);
|
||||
expect(handler).toHaveBeenCalledOnce();
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user