9d3d431416
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
23 lines
1.2 KiB
JavaScript
23 lines
1.2 KiB
JavaScript
const jwt = require("jsonwebtoken");
|
|
const { generateToken, verifyToken } = require("../../app/utils/jwt.util");
|
|
|
|
describe("access JWT", () => {
|
|
test("contains only session security claims and validates issuer/audience", () => {
|
|
const token = generateToken({ userId: "usr-1", sessionId: "sid-1", tokenVersion: 3 });
|
|
const payload = verifyToken(token);
|
|
expect(payload).toMatchObject({ sub: "usr-1", sid: "sid-1", tokenVersion: 3, iss: "zumri-api", aud: "zumri-clients" });
|
|
expect(payload.password).toBeUndefined();
|
|
});
|
|
|
|
test("rejects the wrong issuer and audience", () => {
|
|
const token = jwt.sign({ sid: "sid", tokenVersion: 0 }, process.env.JWT_SECRET, { algorithm: "HS256", subject: "usr", issuer: "attacker", audience: "wrong", expiresIn: "1m" });
|
|
expect(() => verifyToken(token)).toThrow();
|
|
});
|
|
|
|
test("rejects expired and malformed tokens", () => {
|
|
const expired = jwt.sign({ sid: "sid", tokenVersion: 0 }, process.env.JWT_SECRET, { algorithm: "HS256", subject: "usr", issuer: "zumri-api", audience: "zumri-clients", expiresIn: -1 });
|
|
expect(() => verifyToken(expired)).toThrow();
|
|
expect(() => verifyToken("not-a-token")).toThrow();
|
|
});
|
|
});
|