File
Blob: tests/client/lib/session-bootstrap.test.ts
| 1 | import { describe, expect, it } from "vitest"; |
| 2 | import { SESSION_HINT_COOKIE } from "@/shared/auth"; |
| 3 | import { getSessionBootstrapStrategy, hasSessionRefreshHint } from "@/client/lib/session-bootstrap"; |
| 4 | |
| 5 | const HINT = `${SESSION_HINT_COOKIE}=1`; |
| 6 | |
| 7 | describe("session bootstrap", () => { |
| 8 | it("detects the session hint cookie", () => { |
| 9 | expect(hasSessionRefreshHint(`${SESSION_HINT_COOKIE}=1`)).toBe(true); |
| 10 | expect(hasSessionRefreshHint(`foo=bar; ${SESSION_HINT_COOKIE}=1`)).toBe(true); |
| 11 | }); |
| 12 | |
| 13 | it("ignores missing or falsey session hint cookies", () => { |
| 14 | expect(hasSessionRefreshHint("")).toBe(false); |
| 15 | expect(hasSessionRefreshHint("foo=bar")).toBe(false); |
| 16 | expect(hasSessionRefreshHint(`${SESSION_HINT_COOKIE}=0`)).toBe(false); |
| 17 | }); |
| 18 | |
| 19 | it("skips bootstrap refresh when there is no local user or session hint", () => { |
| 20 | expect(getSessionBootstrapStrategy("/", false, "")).toBe("skip"); |
| 21 | expect(getSessionBootstrapStrategy("/login", false, "")).toBe("skip"); |
| 22 | expect(getSessionBootstrapStrategy("/invite/test-token", false, "")).toBe("skip"); |
| 23 | expect(getSessionBootstrapStrategy("/s/share-token", false, "")).toBe("skip"); |
| 24 | expect(getSessionBootstrapStrategy("/shared-with-me", false, "")).toBe("skip"); |
| 25 | }); |
| 26 | |
| 27 | it("runs background refresh when a cached user exists", () => { |
| 28 | expect(getSessionBootstrapStrategy("/", true, "")).toBe("background"); |
| 29 | expect(getSessionBootstrapStrategy("/profile", true, "")).toBe("background"); |
| 30 | }); |
| 31 | |
| 32 | it("runs background refresh on public routes when only the session hint exists", () => { |
| 33 | expect(getSessionBootstrapStrategy("/", false, HINT)).toBe("background"); |
| 34 | expect(getSessionBootstrapStrategy("/login", false, HINT)).toBe("background"); |
| 35 | }); |
| 36 | |
| 37 | it("blocks invite acceptance when the session hint exists without a cached user", () => { |
| 38 | expect(getSessionBootstrapStrategy("/invite/test-token", false, HINT)).toBe("block"); |
| 39 | }); |
| 40 | |
| 41 | it("blocks protected routes when the session hint exists without a cached user", () => { |
| 42 | expect(getSessionBootstrapStrategy("/shared-with-me", false, HINT)).toBe("block"); |
| 43 | expect(getSessionBootstrapStrategy("/profile", false, HINT)).toBe("block"); |
| 44 | expect(getSessionBootstrapStrategy("/workspace-slug", false, HINT)).toBe("block"); |
| 45 | }); |
| 46 | |
| 47 | it("forces block when the oidc=1 marker is present even with a stored user", () => { |
| 48 | expect(getSessionBootstrapStrategy("/", true, "", "?oidc=1")).toBe("block"); |
| 49 | expect(getSessionBootstrapStrategy("/workspaces", true, HINT, "?oidc=1")).toBe("block"); |
| 50 | expect(getSessionBootstrapStrategy("/invite/abc", true, HINT, "?accept=1&oidc=1")).toBe("block"); |
| 51 | }); |
| 52 | |
| 53 | it("ignores oidc=0 markers", () => { |
| 54 | expect(getSessionBootstrapStrategy("/", false, "")).toBe("skip"); |
| 55 | }); |
| 56 | }); |