import { exports } from "cloudflare:workers"; import { describe, expect, it } from "vitest"; import { ISSUER } from "./helpers"; const SELF = exports.default; describe("OIDC discovery + JWKS", () => { it("/.well-known/openid-configuration advertises RS256 and the required endpoints", async () => { const res = await SELF.fetch(`${ISSUER}/.well-known/openid-configuration`); expect(res.status).toBe(200); const config = (await res.json()) as Record; expect(config.issuer).toBe(ISSUER); expect(config.authorization_endpoint).toBe(`${ISSUER}/api/auth/oauth2/authorize`); expect(config.token_endpoint).toBe(`${ISSUER}/api/auth/oauth2/token`); expect(config.jwks_uri).toBe(`${ISSUER}/api/auth/jwks`); expect(config.id_token_signing_alg_values_supported).toContain("RS256"); expect(config.code_challenge_methods_supported).toContain("S256"); expect(config.subject_types_supported).toContain("public"); expect(config.scopes_supported).toEqual(expect.arrayContaining(["openid", "email", "profile"])); }); it("/.well-known/oauth-authorization-server responds with the same shape", async () => { const res = await SELF.fetch(`${ISSUER}/.well-known/oauth-authorization-server`); expect(res.status).toBe(200); const config = (await res.json()) as Record; expect(config.issuer).toBe(ISSUER); expect(config.token_endpoint).toBe(`${ISSUER}/api/auth/oauth2/token`); }); it("/api/auth/jwks returns a single RS256 RSA key with kid", async () => { const res = await SELF.fetch(`${ISSUER}/api/auth/jwks`); expect(res.status).toBe(200); const body = (await res.json()) as { keys: Array> }; expect(body.keys.length).toBeGreaterThanOrEqual(1); const key = body.keys[0]; expect(key.alg).toBe("RS256"); expect(key.kty).toBe("RSA"); expect(key.kid).toBeTruthy(); expect(key.n).toBeTruthy(); expect(key.e).toBe("AQAB"); }); });