File
Blob: tests/client/social-sign-in.test.ts
| 1 | import { describe, expect, it } from "vitest"; |
| 2 | |
| 3 | import { buildSocialSignInRequest } from "@/client/lib/social"; |
| 4 | |
| 5 | // The body shape sent to /api/sign-in/social. The contract is: |
| 6 | // - turnstileToken is always required and round-trips verbatim. |
| 7 | // - oauth_query is forwarded as a top-level field if and only if the user |
| 8 | // came from an RP-initiated /authorize redirect. |
| 9 | // - The wrapper handler attaches `additionalData.oauth_query` server-side |
| 10 | // so oauth-provider's before-hook can capture it into oAuthState; the |
| 11 | // client-facing body keeps oauth_query at the top level so the wrapper |
| 12 | // has explicit ownership of the upstream Better Auth shape. |
| 13 | describe("buildSocialSignInRequest", () => { |
| 14 | it("omits oauth_query when there is no signed query", () => { |
| 15 | const body = buildSocialSignInRequest({ |
| 16 | provider: "github", |
| 17 | callbackURL: "/account", |
| 18 | errorCallbackURL: "/sign-in?error=social_unavailable", |
| 19 | turnstileToken: "tk-abc", |
| 20 | oauthQuery: null, |
| 21 | }); |
| 22 | expect(body).toEqual({ |
| 23 | provider: "github", |
| 24 | callbackURL: "/account", |
| 25 | errorCallbackURL: "/sign-in?error=social_unavailable", |
| 26 | turnstileToken: "tk-abc", |
| 27 | }); |
| 28 | expect("oauth_query" in body).toBe(false); |
| 29 | }); |
| 30 | |
| 31 | it("forwards oauth_query at the top level when present", () => { |
| 32 | const oauthQuery = "client_id=abc&response_type=code&state=xyz&sig=signed"; |
| 33 | const body = buildSocialSignInRequest({ |
| 34 | provider: "google", |
| 35 | callbackURL: "/account", |
| 36 | errorCallbackURL: "/sign-in?error=social_unavailable", |
| 37 | turnstileToken: "tk-xyz", |
| 38 | oauthQuery, |
| 39 | }); |
| 40 | expect(body.provider).toBe("google"); |
| 41 | expect(body.callbackURL).toBe("/account"); |
| 42 | expect(body.errorCallbackURL).toBe("/sign-in?error=social_unavailable"); |
| 43 | expect(body.turnstileToken).toBe("tk-xyz"); |
| 44 | expect(body.oauth_query).toBe(oauthQuery); |
| 45 | }); |
| 46 | |
| 47 | it("treats empty-string oauthQuery as none", () => { |
| 48 | const body = buildSocialSignInRequest({ |
| 49 | provider: "github", |
| 50 | callbackURL: "/account", |
| 51 | errorCallbackURL: "/sign-in", |
| 52 | turnstileToken: "tk-empty", |
| 53 | oauthQuery: "", |
| 54 | }); |
| 55 | expect(body.oauth_query).toBeUndefined(); |
| 56 | }); |
| 57 | }); |