test(bouncer,cabana): cover admin refresh subject checks without a database

Quick 260927-q23 (CR-01), unit coverage that runs under -short.

- bouncer: TestRefreshAudienceForSubject covers active, pre/post cutoff,
  missing, nil provider, non-numeric sub, provider error, and proves
  token-only refusals never reach the provider
- bouncer: TestJWTGuardTokensValidAfter pins the unchanged "User not found"
  message and errors.Is(err, ErrSubjectRejected)
- cabana: TestPhase10Coverage subtest pins cookie expiry on subject
  refusals, no cookies over Bearer or on a provider error, and the
  post-cutoff success path
This commit is contained in:
Jakub Zych
2026-09-27 19:00:12 +02:00
parent be4a923f36
commit a13a1214cb
3 changed files with 261 additions and 0 deletions

View File

@@ -2,6 +2,7 @@ package bouncer
import (
"encoding/json"
"errors"
"net/http"
"net/http/httptest"
"testing"
@@ -107,6 +108,11 @@ func TestJWTGuardTokensValidAfter(t *testing.T) {
if _, err := NewJWTGuard(secret, cutoff, nil).Authenticate(req); err == nil || err.Error() != msgUserNotFound {
t.Fatalf("after cutoff: %v", err)
}
// The helper extraction keeps the guard's message and makes the refusal
// matchable, the same sentinel RefreshAudienceFor returns.
if _, err := NewJWTGuard(secret, cutoff, nil).Authenticate(req); err == nil || err.Error() != "User not found" || !errors.Is(err, ErrSubjectRejected) {
t.Fatalf("cutoff refusal = %v, want \"User not found\" matching ErrSubjectRejected", err)
}
open := memUsers{byID: map[uint]*Principal{1: {ID: 1, TokensValidAfter: time.Now().Add(-time.Hour)}}}
p, err := NewJWTGuard(secret, open, nil).Authenticate(req)