67 lines
1.6 KiB
Go
67 lines
1.6 KiB
Go
package auth
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestHashVerifyPassword(t *testing.T) {
|
|
hash, err := HashPassword("everypublish-2026")
|
|
if err != nil {
|
|
t.Fatalf("hash: %v", err)
|
|
}
|
|
if !strings.HasPrefix(hash, "$argon2id$") {
|
|
t.Fatalf("bad hash format: %s", hash)
|
|
}
|
|
ok, err := VerifyPassword("everypublish-2026", hash)
|
|
if err != nil || !ok {
|
|
t.Fatalf("verify should pass: ok=%v err=%v", ok, err)
|
|
}
|
|
ok, err = VerifyPassword("wrong-pass", hash)
|
|
if err != nil || ok {
|
|
t.Fatalf("verify should fail: ok=%v err=%v", ok, err)
|
|
}
|
|
}
|
|
|
|
func TestJWTAccessRoundTrip(t *testing.T) {
|
|
secret := "test-secret"
|
|
token, err := IssueAccess(secret, 42, 7, "user", "owner")
|
|
if err != nil {
|
|
t.Fatalf("issue: %v", err)
|
|
}
|
|
claims, err := ParseAccess(secret, token)
|
|
if err != nil {
|
|
t.Fatalf("parse: %v", err)
|
|
}
|
|
if claims.UID != 42 || claims.WorkspaceID != 7 || claims.MemberRole != "owner" {
|
|
t.Fatalf("claims mismatch: %+v", claims)
|
|
}
|
|
}
|
|
|
|
func TestJWTAccessExpired(t *testing.T) {
|
|
secret := "test-secret"
|
|
claims := AccessClaims{UID: 1, RegisteredClaims: jwtRegisteredExpired()}
|
|
token, err := signExpired(secret, claims)
|
|
if err != nil {
|
|
t.Fatalf("sign: %v", err)
|
|
}
|
|
if _, err = ParseAccess(secret, token); err == nil {
|
|
t.Fatal("expired token should fail")
|
|
}
|
|
}
|
|
|
|
func TestJWTRefreshRoundTrip(t *testing.T) {
|
|
secret := "test-secret"
|
|
token, err := IssueRefresh(secret, 9, "jti-1")
|
|
if err != nil {
|
|
t.Fatalf("issue: %v", err)
|
|
}
|
|
claims, err := ParseRefresh(secret, token)
|
|
if err != nil {
|
|
t.Fatalf("parse: %v", err)
|
|
}
|
|
if claims.UID != 9 || claims.JTI != "jti-1" {
|
|
t.Fatalf("claims mismatch: %+v", claims)
|
|
}
|
|
}
|