import { env } from "cloudflare:workers"; import { describe, expect, it } from "vitest"; import { makeAuth } from "@/worker/auth"; import { ISSUER } from "./helpers"; const overrides = { baseURL: ISSUER, issuer: ISSUER }; const withSecret = (secret: string): Env => ({ ...env, BETTER_AUTH_SECRET: secret }) as Env; describe("makeAuth — BETTER_AUTH_SECRET validation", () => { it("throws when the secret is empty", () => { expect(() => makeAuth(withSecret(""), overrides)).toThrow(/BETTER_AUTH_SECRET/); }); it("throws on the dev placeholder", () => { expect(() => makeAuth(withSecret("replace-me-with-64-hex-chars"), overrides)).toThrow(/BETTER_AUTH_SECRET/); }); it("throws on a 32-char hex string (too short)", () => { expect(() => makeAuth(withSecret("0".repeat(32)), overrides)).toThrow(/BETTER_AUTH_SECRET/); }); it("throws on 64 chars containing non-hex letters", () => { expect(() => makeAuth(withSecret("g".repeat(64)), overrides)).toThrow(/BETTER_AUTH_SECRET/); }); it("throws when the value is whitespace-only after trim", () => { expect(() => makeAuth(withSecret(" "), overrides)).toThrow(/BETTER_AUTH_SECRET/); }); it("accepts 64 lowercase hex characters", () => { expect(() => makeAuth(withSecret("a".repeat(64)), overrides)).not.toThrow(); }); it("accepts 64 uppercase hex characters (case-insensitive per OPERATOR rule)", () => { expect(() => makeAuth(withSecret("A".repeat(64)), overrides)).not.toThrow(); }); it("accepts a mixed-case hex value with surrounding whitespace", () => { expect(() => makeAuth(withSecret(` ${"aB".repeat(32)} `), overrides)).not.toThrow(); }); });