import { env, exports } from "cloudflare:workers"; import { beforeAll, describe, expect, it } from "vitest"; import { makeAuth } from "@/worker/auth"; import { ISSUER, signInForCookie } from "./helpers"; const SELF = exports.default; const credential = { email: "jwt-surface-tester@example.com", password: "correct-horse-battery-staple", name: "JWT Surface Tester", }; describe("JWT plugin surface", () => { let cookie: string; beforeAll(async () => { const auth = makeAuth(env, { baseURL: ISSUER, issuer: ISSUER }); await auth.api.signUpEmail({ body: credential, asResponse: false }); cookie = await signInForCookie(credential.email, credential.password, "10.71.0.1"); }); it("404s GET /api/auth/token even with a valid session cookie", async () => { const res = await SELF.fetch(`${ISSUER}/api/auth/token`, { method: "GET", headers: { cookie }, }); expect(res.status).toBe(404); // Body must not be a JWT either: the trap returns plain text. const body = await res.text(); expect(body).toBe("Not Found"); }); it("does not emit set-auth-jwt on /api/auth/get-session", async () => { const res = await SELF.fetch(`${ISSUER}/api/auth/get-session`, { method: "GET", headers: { cookie }, }); expect(res.status).toBe(200); expect(res.headers.get("set-auth-jwt")).toBeNull(); }); it("still serves /api/auth/jwks publicly (OIDC discovery surface preserved)", async () => { const res = await SELF.fetch(`${ISSUER}/api/auth/jwks`); expect(res.status).toBe(200); const body = (await res.json()) as { keys?: Array<{ kty?: string; alg?: string }> }; expect(Array.isArray(body.keys)).toBe(true); expect(body.keys?.[0]?.alg).toBe("RS256"); }); });