|
| 1 | +import request from 'supertest'; |
| 2 | +import { describe, it, expect, beforeAll, vi, afterAll } from 'vitest'; |
| 3 | + |
| 4 | +vi.unmock('../../src/models/authEvents.js'); |
| 5 | +vi.unmock('../../src/models/sessions.js'); |
| 6 | +vi.unmock('../../src/models/users.js'); |
| 7 | +vi.unmock('../../src/models/systemConfig.js'); |
| 8 | +vi.unmock('../../src/models/credentials.js'); |
| 9 | +vi.unmock('../../src/models/magicLinks.js'); |
| 10 | +vi.unmock('../../src/services/sessionService.js'); |
| 11 | +vi.unmock('../../src/services/authEventService.js'); |
| 12 | +vi.unmock('../../src/models'); |
| 13 | +vi.unmock('../../src/services/messagingService.js'); |
| 14 | +vi.unmock('../../src/lib/cookie.js'); |
| 15 | +vi.unmock('../../src/lib/token.js'); |
| 16 | +vi.unmock('../../src/middleware/attachAuthMiddleware.js'); |
| 17 | +vi.unmock('../../src/middleware/verifyCookieAuth.js'); |
| 18 | + |
| 19 | +vi.unmock('../../src/config/getSystemConfig.js'); |
| 20 | +vi.unmock('../../src/utils/utils.js'); |
| 21 | +vi.unmock('../../src/utils/otp.js'); |
| 22 | +vi.unmock('../../src/utils/token.js'); |
| 23 | +vi.unmock('../../src/utils/cookie.js'); |
| 24 | +vi.unmock('../../src/utils/secretStore.js'); |
| 25 | + |
| 26 | +vi.unmock('bcrypt-ts'); |
| 27 | + |
| 28 | +let app: any; |
| 29 | + |
| 30 | +beforeAll(async () => { |
| 31 | + vi.stubEnv('NODE_ENV', 'test'); |
| 32 | + vi.stubEnv('AUTH_MODE', 'web'); |
| 33 | + |
| 34 | + vi.stubEnv('DB_DIALECT', 'postgres'); |
| 35 | + vi.stubEnv('DB_HOST', 'localhost'); |
| 36 | + vi.stubEnv('DB_PORT', '5432'); |
| 37 | + vi.stubEnv('DB_NAME', 'seamless_auth_test'); |
| 38 | + vi.stubEnv('DB_USER', 'myuser'); |
| 39 | + vi.stubEnv('DB_PASSWORD', 'mypassword'); |
| 40 | + |
| 41 | + vi.stubEnv('ISSUER', 'test-issuer'); |
| 42 | + vi.stubEnv('APP_ID', 'test-app'); |
| 43 | + vi.stubEnv('APP_ORIGIN', 'http://localhost'); |
| 44 | + |
| 45 | + vi.stubEnv('JWKS_ACTIVE_KIDe', 'dev-main'); |
| 46 | + vi.stubEnv('API_SERVICE_TOKEN', 'service-token'); |
| 47 | + |
| 48 | + vi.stubEnv('DEFAULT_ROLES', 'user'); |
| 49 | + vi.stubEnv('AVAILABLE_ROLES', 'user,admin'); |
| 50 | + vi.stubEnv('ACCESS_TOKEN_TTL', '15m'); |
| 51 | + vi.stubEnv('REFRESH_TOKEN_TTL', '1h'); |
| 52 | + vi.stubEnv('RATE_LIMIT', '100'); |
| 53 | + vi.stubEnv('DELAY_AFTER', '50'); |
| 54 | + vi.stubEnv('RPID', 'localhost'); |
| 55 | + vi.stubEnv('ORIGINS', 'http://localhost'); |
| 56 | + vi.stubEnv('APP_NAME', 'TestApp'); |
| 57 | + |
| 58 | + const { initializeModels } = await import('../../src/models'); |
| 59 | + const models = await initializeModels(); |
| 60 | + |
| 61 | + await models.sequelize.sync({ force: true }); |
| 62 | + |
| 63 | + const { bootstrapSystemConfig } = await import('../../src/config/bootstrapSystemConfig'); |
| 64 | + await bootstrapSystemConfig(); |
| 65 | + |
| 66 | + const { createApp } = await import('../../src/app'); |
| 67 | + app = await createApp(); |
| 68 | +}); |
| 69 | + |
| 70 | +afterAll(() => { |
| 71 | + vi.unstubAllEnvs(); |
| 72 | +}); |
| 73 | + |
| 74 | +it('full auth lifecycle works', async () => { |
| 75 | + const email = 'test@example.com'; |
| 76 | + const phone = '+14155552671'; |
| 77 | + |
| 78 | + const registerRes = await request(app).post('/registration/register').send({ email, phone }); |
| 79 | + |
| 80 | + expect(registerRes.status).toBe(200); |
| 81 | + |
| 82 | + const cookies = registerRes.headers['set-cookie']; |
| 83 | + expect(cookies).toBeDefined(); |
| 84 | + |
| 85 | + const otpRes = await request(app).get('/otp/generate-phone-otp').set('Cookie', cookies); |
| 86 | + |
| 87 | + expect(otpRes.status).toBe(200); |
| 88 | + |
| 89 | + const { User } = await import('../../src/models/users'); |
| 90 | + |
| 91 | + const user = await User.findOne({ where: { email } }); |
| 92 | + |
| 93 | + expect(user).toBeDefined(); |
| 94 | + const otp = user?.phoneVerificationToken; |
| 95 | + |
| 96 | + expect(otp).toBeDefined(); |
| 97 | + |
| 98 | + const verifyRes = await request(app) |
| 99 | + .post('/otp/verify-phone-otp') |
| 100 | + .set('Cookie', cookies) |
| 101 | + .send({ verificationToken: otp }); |
| 102 | + |
| 103 | + expect(verifyRes.status).toBe(200); |
| 104 | + |
| 105 | + const emailOtpRes = await request(app).get('/otp/generate-email-otp').set('Cookie', cookies); |
| 106 | + |
| 107 | + expect(emailOtpRes.status).toBe(200); |
| 108 | + |
| 109 | + await user?.reload(); |
| 110 | + const emailOtp = user?.emailVerificationToken; |
| 111 | + |
| 112 | + expect(emailOtp).toBeDefined(); |
| 113 | + |
| 114 | + const emailVerifyRes = await request(app) |
| 115 | + .post('/otp/verify-email-otp') |
| 116 | + .set('Cookie', cookies) |
| 117 | + .send({ verificationToken: emailOtp }); |
| 118 | + |
| 119 | + expect(emailVerifyRes.status).toBe(200); |
| 120 | + |
| 121 | + let authCookies = emailVerifyRes.headers['set-cookie']; |
| 122 | + expect(authCookies).toBeDefined(); |
| 123 | + |
| 124 | + const meRes = await request(app).get('/users/me').set('Cookie', authCookies); |
| 125 | + |
| 126 | + const maybeNewCookies = meRes.headers['set-cookie']; |
| 127 | + if (maybeNewCookies) { |
| 128 | + authCookies = maybeNewCookies; |
| 129 | + } |
| 130 | + |
| 131 | + expect(meRes.status).toBe(200); |
| 132 | + expect(Array.isArray(meRes.body.user)).toBeDefined(); |
| 133 | + |
| 134 | + const brokenCookies = (authCookies as unknown as string[]).filter( |
| 135 | + (c: string) => !c.includes('seamless_access'), |
| 136 | + ); |
| 137 | + |
| 138 | + expect(brokenCookies.some((c) => c.includes('seamless_refresh'))).toBe(true); |
| 139 | + |
| 140 | + const refreshRes = await request(app).get('/users/me').set('Cookie', brokenCookies); |
| 141 | + |
| 142 | + expect(refreshRes.status).toBe(200); |
| 143 | + |
| 144 | + const refreshedCookies = refreshRes.headers['set-cookie']; |
| 145 | + expect(refreshedCookies).toBeDefined(); |
| 146 | + |
| 147 | + authCookies = refreshedCookies; |
| 148 | + |
| 149 | + const logoutRes = await request(app).get('/logout').set('Cookie', authCookies); |
| 150 | + |
| 151 | + expect(logoutRes.status).toBe(200); |
| 152 | +}); |
0 commit comments