Skip to content
File

Blob: tests/client/social-sign-in.test.ts

typescript58 lines
1import { describe, expect, it } from "vitest";
2 
3import { buildSocialSignInRequest } from "@/client/lib/social";
4 
5// The body shape sent to /api/sign-in/social. The contract is:
6// - turnstileToken is always required and round-trips verbatim.
7// - oauth_query is forwarded as a top-level field if and only if the user
8// came from an RP-initiated /authorize redirect.
9// - The wrapper handler attaches `additionalData.oauth_query` server-side
10// so oauth-provider's before-hook can capture it into oAuthState; the
11// client-facing body keeps oauth_query at the top level so the wrapper
12// has explicit ownership of the upstream Better Auth shape.
13describe("buildSocialSignInRequest", () => {
14 it("omits oauth_query when there is no signed query", () => {
15 const body = buildSocialSignInRequest({
16 provider: "github",
17 callbackURL: "/account",
18 errorCallbackURL: "/sign-in?error=social_unavailable",
19 turnstileToken: "tk-abc",
20 oauthQuery: null,
21 });
22 expect(body).toEqual({
23 provider: "github",
24 callbackURL: "/account",
25 errorCallbackURL: "/sign-in?error=social_unavailable",
26 turnstileToken: "tk-abc",
27 });
28 expect("oauth_query" in body).toBe(false);
29 });
30 
31 it("forwards oauth_query at the top level when present", () => {
32 const oauthQuery = "client_id=abc&response_type=code&state=xyz&sig=signed";
33 const body = buildSocialSignInRequest({
34 provider: "google",
35 callbackURL: "/account",
36 errorCallbackURL: "/sign-in?error=social_unavailable",
37 turnstileToken: "tk-xyz",
38 oauthQuery,
39 });
40 expect(body.provider).toBe("google");
41 expect(body.callbackURL).toBe("/account");
42 expect(body.errorCallbackURL).toBe("/sign-in?error=social_unavailable");
43 expect(body.turnstileToken).toBe("tk-xyz");
44 expect(body.oauth_query).toBe(oauthQuery);
45 });
46 
47 it("treats empty-string oauthQuery as none", () => {
48 const body = buildSocialSignInRequest({
49 provider: "github",
50 callbackURL: "/account",
51 errorCallbackURL: "/sign-in",
52 turnstileToken: "tk-empty",
53 oauthQuery: "",
54 });
55 expect(body.oauth_query).toBeUndefined();
56 });
57});