File
Blob: tests/worker/oidc-discovery.test.ts
| 1 | import { exports } from "cloudflare:workers"; |
| 2 | import { describe, expect, it } from "vitest"; |
| 3 | |
| 4 | import { ISSUER } from "./helpers"; |
| 5 | |
| 6 | const SELF = exports.default; |
| 7 | |
| 8 | describe("OIDC discovery + JWKS", () => { |
| 9 | it("/.well-known/openid-configuration advertises RS256 and the required endpoints", async () => { |
| 10 | const res = await SELF.fetch(`${ISSUER}/.well-known/openid-configuration`); |
| 11 | expect(res.status).toBe(200); |
| 12 | const config = (await res.json()) as Record<string, unknown>; |
| 13 | |
| 14 | expect(config.issuer).toBe(ISSUER); |
| 15 | expect(config.authorization_endpoint).toBe(`${ISSUER}/api/auth/oauth2/authorize`); |
| 16 | expect(config.token_endpoint).toBe(`${ISSUER}/api/auth/oauth2/token`); |
| 17 | expect(config.jwks_uri).toBe(`${ISSUER}/api/auth/jwks`); |
| 18 | expect(config.id_token_signing_alg_values_supported).toContain("RS256"); |
| 19 | expect(config.code_challenge_methods_supported).toContain("S256"); |
| 20 | expect(config.subject_types_supported).toContain("public"); |
| 21 | expect(config.scopes_supported).toEqual(expect.arrayContaining(["openid", "email", "profile"])); |
| 22 | }); |
| 23 | |
| 24 | it("/.well-known/oauth-authorization-server responds with the same shape", async () => { |
| 25 | const res = await SELF.fetch(`${ISSUER}/.well-known/oauth-authorization-server`); |
| 26 | expect(res.status).toBe(200); |
| 27 | const config = (await res.json()) as Record<string, unknown>; |
| 28 | expect(config.issuer).toBe(ISSUER); |
| 29 | expect(config.token_endpoint).toBe(`${ISSUER}/api/auth/oauth2/token`); |
| 30 | }); |
| 31 | |
| 32 | it("/api/auth/jwks returns a single RS256 RSA key with kid", async () => { |
| 33 | const res = await SELF.fetch(`${ISSUER}/api/auth/jwks`); |
| 34 | expect(res.status).toBe(200); |
| 35 | const body = (await res.json()) as { keys: Array<Record<string, string>> }; |
| 36 | expect(body.keys.length).toBeGreaterThanOrEqual(1); |
| 37 | const key = body.keys[0]; |
| 38 | expect(key.alg).toBe("RS256"); |
| 39 | expect(key.kty).toBe("RSA"); |
| 40 | expect(key.kid).toBeTruthy(); |
| 41 | expect(key.n).toBeTruthy(); |
| 42 | expect(key.e).toBe("AQAB"); |
| 43 | }); |
| 44 | }); |