forked from QuantumNous/new-api
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathapi.test.ts
More file actions
120 lines (104 loc) · 3.53 KB
/
Copy pathapi.test.ts
File metadata and controls
120 lines (104 loc) · 3.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
/*
Copyright (C) 2023-2026 QuantumNous
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as
published by the Free Software Foundation, either version 3 of the
License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
For commercial licensing, please contact support@quantumnous.com
*/
import assert from 'node:assert/strict'
import { describe, test } from 'node:test'
import type { RefreshOutcome } from '@/lib/api'
import type { AuthBundle } from '@/stores/auth-store'
import { executeLogout } from './api'
const bundle: AuthBundle = {
access_token: 'access-token',
token_type: 'Bearer',
access_expires_at: 1_900_000_000,
user: { id: 1, username: 'test-user', role: 1 },
session: {
sid: 'session-b',
current: true,
login_method: 'password',
ip: '127.0.0.1',
user_agent: 'test',
created_at: 1,
last_active_at: 1,
expires_at: 1_900_000_000,
},
}
function mismatchError() {
return {
isAxiosError: true,
response: {
status: 409,
data: { code: 'AUTH_SESSION_MISMATCH' },
},
}
}
describe('logout coordination', () => {
test('returns an unsuccessful response without pretending to sign out', async () => {
let refreshCount = 0
const result = await executeLogout({
getExpectedSID: () => 'session-a',
request: async () => ({ success: false, message: 'not revoked' }),
refresh: async () => {
refreshCount += 1
return { kind: 'anonymous' }
},
})
assert.deepEqual(result, { success: false, message: 'not revoked' })
assert.equal(refreshCount, 0)
})
test('recovers a cookie mismatch and retries with the refreshed SID', async () => {
let sid = 'session-a'
const requestedSIDs: Array<string | undefined> = []
const result = await executeLogout({
getExpectedSID: () => sid,
request: async (expectedSID) => {
requestedSIDs.push(expectedSID)
if (requestedSIDs.length === 1) throw mismatchError()
return { success: true, message: '' }
},
refresh: async () => {
sid = bundle.session.sid
return { kind: 'authenticated', bundle }
},
})
assert.deepEqual(result, { success: true, message: '' })
assert.deepEqual(requestedSIDs, ['session-a', 'session-b'])
})
test('treats a mismatch that refresh confirms anonymous as signed out', async () => {
const result = await executeLogout({
getExpectedSID: () => 'session-a',
request: async () => {
throw mismatchError()
},
refresh: async () => ({ kind: 'anonymous' }),
})
assert.deepEqual(result, { success: true, message: '' })
})
test('preserves the active session when mismatch recovery is temporary', async () => {
const originalError = mismatchError()
const transient: RefreshOutcome = {
kind: 'transient_error',
error: new Error('offline'),
}
await assert.rejects(
executeLogout({
getExpectedSID: () => 'session-a',
request: async () => {
throw originalError
},
refresh: async () => transient,
}),
(error) => error === originalError
)
})
})