import { beforeEach, describe, expect, it, vi } from "vitest"; const session = vi.fn(); const handler = vi.fn(async () => Response.json({ passed: true })); vi.mock("server-only", () => ({})); vi.mock("better-auth/next-js", () => ({ toNextJsHandler: () => ({ GET: handler }) })); vi.mock("@/lib/auth/server", () => ({ getAuth: () => ({ api: { getSession: session }, handler }), isSudlohOidcEnabled: () => true, })); const { GET, POST } = await import("./route"); beforeEach(() => { vi.clearAllMocks(); process.env.BETTER_AUTH_URL = "https://guide.sudloh.com"; process.env.SUDLOH_OIDC_ONLY = "true"; session.mockResolvedValue({ user: { id: "user-1" }, session: { id: "session-1" } }); }); describe("Better Auth Sudloh boundary", () => { it("lets Better Auth serve the local browser session", async () => { const response = await GET(new Request("https://guide.sudloh.com/api/auth/get-session")); expect(response.status).toBe(200); expect(await response.json()).toEqual({ passed: true }); expect(handler).toHaveBeenCalledOnce(); }); it("permits the OIDC callback", async () => { const callback = await GET(new Request("https://guide.sudloh.com/api/auth/callback/sudloh?code=code")); expect(callback.status).toBe(200); }); it("passes mutations to Better Auth for local session checks", async () => { const response = await POST(new Request("https://guide.sudloh.com/api/auth/admin/create-user", { method: "POST", headers: { Origin: "https://guide.sudloh.com", "Content-Type": "application/json" }, body: JSON.stringify({ password: "example-password" }), })); expect(response.status).toBe(200); expect(handler).toHaveBeenCalledOnce(); }); });