const jwt = require("jsonwebtoken"); const { generateToken, verifyToken } = require("../../app/utils/jwt.util"); describe("access JWT", () => { test("contains only session security claims and validates issuer/audience", () => { const token = generateToken({ userId: "usr-1", sessionId: "sid-1", tokenVersion: 3 }); const payload = verifyToken(token); expect(payload).toMatchObject({ sub: "usr-1", sid: "sid-1", tokenVersion: 3, iss: "zumri-api", aud: "zumri-clients" }); expect(payload.password).toBeUndefined(); }); test("rejects the wrong issuer and audience", () => { const token = jwt.sign({ sid: "sid", tokenVersion: 0 }, process.env.JWT_SECRET, { algorithm: "HS256", subject: "usr", issuer: "attacker", audience: "wrong", expiresIn: "1m" }); expect(() => verifyToken(token)).toThrow(); }); test("rejects expired and malformed tokens", () => { const expired = jwt.sign({ sid: "sid", tokenVersion: 0 }, process.env.JWT_SECRET, { algorithm: "HS256", subject: "usr", issuer: "zumri-api", audience: "zumri-clients", expiresIn: -1 }); expect(() => verifyToken(expired)).toThrow(); expect(() => verifyToken("not-a-token")).toThrow(); }); });