File
Blob: tests/worker/auth-secret.test.ts
| 1 | import { env } from "cloudflare:workers"; |
| 2 | import { describe, expect, it } from "vitest"; |
| 3 | |
| 4 | import { makeAuth } from "@/worker/auth"; |
| 5 | |
| 6 | import { ISSUER } from "./helpers"; |
| 7 | |
| 8 | const overrides = { baseURL: ISSUER, issuer: ISSUER }; |
| 9 | |
| 10 | const withSecret = (secret: string): Env => ({ ...env, BETTER_AUTH_SECRET: secret }) as Env; |
| 11 | |
| 12 | describe("makeAuth — BETTER_AUTH_SECRET validation", () => { |
| 13 | it("throws when the secret is empty", () => { |
| 14 | expect(() => makeAuth(withSecret(""), overrides)).toThrow(/BETTER_AUTH_SECRET/); |
| 15 | }); |
| 16 | |
| 17 | it("throws on the dev placeholder", () => { |
| 18 | expect(() => makeAuth(withSecret("replace-me-with-64-hex-chars"), overrides)).toThrow(/BETTER_AUTH_SECRET/); |
| 19 | }); |
| 20 | |
| 21 | it("throws on a 32-char hex string (too short)", () => { |
| 22 | expect(() => makeAuth(withSecret("0".repeat(32)), overrides)).toThrow(/BETTER_AUTH_SECRET/); |
| 23 | }); |
| 24 | |
| 25 | it("throws on 64 chars containing non-hex letters", () => { |
| 26 | expect(() => makeAuth(withSecret("g".repeat(64)), overrides)).toThrow(/BETTER_AUTH_SECRET/); |
| 27 | }); |
| 28 | |
| 29 | it("throws when the value is whitespace-only after trim", () => { |
| 30 | expect(() => makeAuth(withSecret(" "), overrides)).toThrow(/BETTER_AUTH_SECRET/); |
| 31 | }); |
| 32 | |
| 33 | it("accepts 64 lowercase hex characters", () => { |
| 34 | expect(() => makeAuth(withSecret("a".repeat(64)), overrides)).not.toThrow(); |
| 35 | }); |
| 36 | |
| 37 | it("accepts 64 uppercase hex characters (case-insensitive per OPERATOR rule)", () => { |
| 38 | expect(() => makeAuth(withSecret("A".repeat(64)), overrides)).not.toThrow(); |
| 39 | }); |
| 40 | |
| 41 | it("accepts a mixed-case hex value with surrounding whitespace", () => { |
| 42 | expect(() => makeAuth(withSecret(` ${"aB".repeat(32)} `), overrides)).not.toThrow(); |
| 43 | }); |
| 44 | }); |