File
Blob: tests/worker/lib/auth-cookie.test.ts
| 1 | import { describe, expect, it } from "vitest"; |
| 2 | import { Hono } from "hono"; |
| 3 | |
| 4 | import { SESSION_HINT_COOKIE } from "@/shared/auth"; |
| 5 | import { REFRESH_COOKIE_MAX_AGE } from "@/worker/lib/constants"; |
| 6 | import { REFRESH_COOKIE, clearRefreshCookie, setRefreshCookie } from "@/worker/lib/auth"; |
| 7 | |
| 8 | describe("auth cookie helpers", () => { |
| 9 | it("sets refresh and session hint cookies with the expected flags", async () => { |
| 10 | const app = new Hono(); |
| 11 | |
| 12 | app.get("/", (c) => { |
| 13 | setRefreshCookie(c, "refresh-token"); |
| 14 | return c.text("ok"); |
| 15 | }); |
| 16 | |
| 17 | const res = await app.request("http://test/"); |
| 18 | |
| 19 | expect(res.headers.getSetCookie()).toEqual([ |
| 20 | `${REFRESH_COOKIE}=refresh-token; Max-Age=${REFRESH_COOKIE_MAX_AGE}; Path=/; HttpOnly; Secure; SameSite=Strict`, |
| 21 | `${SESSION_HINT_COOKIE}=1; Max-Age=${REFRESH_COOKIE_MAX_AGE}; Path=/; Secure; SameSite=Strict`, |
| 22 | ]); |
| 23 | }); |
| 24 | |
| 25 | it("clears refresh and session hint cookies with the expected flags", async () => { |
| 26 | const app = new Hono(); |
| 27 | |
| 28 | app.get("/", (c) => { |
| 29 | clearRefreshCookie(c); |
| 30 | return c.text("ok"); |
| 31 | }); |
| 32 | |
| 33 | const res = await app.request("http://test/"); |
| 34 | |
| 35 | expect(res.headers.getSetCookie()).toEqual([ |
| 36 | `${REFRESH_COOKIE}=; Max-Age=0; Path=/; HttpOnly; Secure; SameSite=Strict`, |
| 37 | `${SESSION_HINT_COOKIE}=; Max-Age=0; Path=/; Secure; SameSite=Strict`, |
| 38 | ]); |
| 39 | }); |
| 40 | }); |