fix(11-06): send Cache-Control: no-cache, private on the jwt.auth 401

The recorded PHP 401 for a missing bearer (realtime token no-bearer
case) carries Laravel's default Cache-Control header; the Go guard's
401 omitted it, so the replay failed on header.Cache-Control.
This commit is contained in:
Jakub Zych
2026-09-30 13:31:55 +02:00
parent 9ecbf74a22
commit 5382947ef8
3 changed files with 7 additions and 1 deletions

View File

@@ -99,6 +99,9 @@ func TestMiddlewareStatusBodies(t *testing.T) {
if rec.Header().Get("X-Hit") != "" {
t.Fatal("handler ran")
}
if got := rec.Header().Get("Cache-Control"); got != "no-cache, private" {
t.Fatalf("Cache-Control = %q", got)
}
var body map[string]any
if err := json.Unmarshal(rec.Body.Bytes(), &body); err != nil {
t.Fatal(err)