File
Blob: test/util/oidcFake.ts
| 1 | import * as oidc from "openid-client"; |
| 2 | |
| 3 | import type { OidcProvider } from "@/worker/auth/oidc"; |
| 4 | |
| 5 | // Minimal fake provider: openid-client's `Configuration` consults the |
| 6 | // metadata it was built with. We construct a Configuration from a hand- |
| 7 | // rolled metadata object so unit tests do not need a real discovery |
| 8 | // document or live network. This keeps the worker-test seam aligned with |
| 9 | // production: production uses the real `oidc.discovery`; tests preload an |
| 10 | // equivalent shape directly into the cache. |
| 11 | export function fakeProvider(args: { |
| 12 | authorizationEndpoint: string; |
| 13 | tokenEndpoint: string; |
| 14 | jwksUri: string; |
| 15 | issuer?: string; |
| 16 | }): OidcProvider { |
| 17 | const issuer = args.issuer ?? "https://fake.local"; |
| 18 | const configuration = new oidc.Configuration( |
| 19 | { |
| 20 | issuer, |
| 21 | authorization_endpoint: args.authorizationEndpoint, |
| 22 | token_endpoint: args.tokenEndpoint, |
| 23 | jwks_uri: args.jwksUri, |
| 24 | response_types_supported: ["code"], |
| 25 | }, |
| 26 | "test-client-id", |
| 27 | { |
| 28 | client_id: "test-client-id", |
| 29 | client_secret: "test-secret", |
| 30 | }, |
| 31 | oidc.ClientSecretPost("test-secret") |
| 32 | ); |
| 33 | return { configuration }; |
| 34 | } |