Skip to content
File

Blob: tests/worker/auth-secret.test.ts

typescript45 lines
1import { env } from "cloudflare:workers";
2import { describe, expect, it } from "vitest";
3 
4import { makeAuth } from "@/worker/auth";
5 
6import { ISSUER } from "./helpers";
7 
8const overrides = { baseURL: ISSUER, issuer: ISSUER };
9 
10const withSecret = (secret: string): Env => ({ ...env, BETTER_AUTH_SECRET: secret }) as Env;
11 
12describe("makeAuth — BETTER_AUTH_SECRET validation", () => {
13 it("throws when the secret is empty", () => {
14 expect(() => makeAuth(withSecret(""), overrides)).toThrow(/BETTER_AUTH_SECRET/);
15 });
16 
17 it("throws on the dev placeholder", () => {
18 expect(() => makeAuth(withSecret("replace-me-with-64-hex-chars"), overrides)).toThrow(/BETTER_AUTH_SECRET/);
19 });
20 
21 it("throws on a 32-char hex string (too short)", () => {
22 expect(() => makeAuth(withSecret("0".repeat(32)), overrides)).toThrow(/BETTER_AUTH_SECRET/);
23 });
24 
25 it("throws on 64 chars containing non-hex letters", () => {
26 expect(() => makeAuth(withSecret("g".repeat(64)), overrides)).toThrow(/BETTER_AUTH_SECRET/);
27 });
28 
29 it("throws when the value is whitespace-only after trim", () => {
30 expect(() => makeAuth(withSecret(" "), overrides)).toThrow(/BETTER_AUTH_SECRET/);
31 });
32 
33 it("accepts 64 lowercase hex characters", () => {
34 expect(() => makeAuth(withSecret("a".repeat(64)), overrides)).not.toThrow();
35 });
36 
37 it("accepts 64 uppercase hex characters (case-insensitive per OPERATOR rule)", () => {
38 expect(() => makeAuth(withSecret("A".repeat(64)), overrides)).not.toThrow();
39 });
40 
41 it("accepts a mixed-case hex value with surrounding whitespace", () => {
42 expect(() => makeAuth(withSecret(` ${"aB".repeat(32)} `), overrides)).not.toThrow();
43 });
44});