Skip to content
File

Blob: tests/worker/jwt-surface.test.ts

typescript53 lines
1import { env, exports } from "cloudflare:workers";
2import { beforeAll, describe, expect, it } from "vitest";
3 
4import { makeAuth } from "@/worker/auth";
5 
6import { ISSUER, signInForCookie } from "./helpers";
7 
8const SELF = exports.default;
9 
10const credential = {
11 email: "jwt-surface-tester@example.com",
12 password: "correct-horse-battery-staple",
13 name: "JWT Surface Tester",
14};
15 
16describe("JWT plugin surface", () => {
17 let cookie: string;
18 
19 beforeAll(async () => {
20 const auth = makeAuth(env, { baseURL: ISSUER, issuer: ISSUER });
21 await auth.api.signUpEmail({ body: credential, asResponse: false });
22 cookie = await signInForCookie(credential.email, credential.password, "10.71.0.1");
23 });
24 
25 it("404s GET /api/auth/token even with a valid session cookie", async () => {
26 const res = await SELF.fetch(`${ISSUER}/api/auth/token`, {
27 method: "GET",
28 headers: { cookie },
29 });
30 expect(res.status).toBe(404);
31 // Body must not be a JWT either: the trap returns plain text.
32 const body = await res.text();
33 expect(body).toBe("Not Found");
34 });
35 
36 it("does not emit set-auth-jwt on /api/auth/get-session", async () => {
37 const res = await SELF.fetch(`${ISSUER}/api/auth/get-session`, {
38 method: "GET",
39 headers: { cookie },
40 });
41 expect(res.status).toBe(200);
42 expect(res.headers.get("set-auth-jwt")).toBeNull();
43 });
44 
45 it("still serves /api/auth/jwks publicly (OIDC discovery surface preserved)", async () => {
46 const res = await SELF.fetch(`${ISSUER}/api/auth/jwks`);
47 expect(res.status).toBe(200);
48 const body = (await res.json()) as { keys?: Array<{ kty?: string; alg?: string }> };
49 expect(Array.isArray(body.keys)).toBe(true);
50 expect(body.keys?.[0]?.alg).toBe("RS256");
51 });
52});