Files
summercms/admin/tests/state/useAuth.test.ts
Jakub Zych 1c2a66df45 test(10-05): bring every SPA module, composable and component under Vitest
- 41 unit and component suites under admin/tests/{app,state,shell,list,form,relation,views,ui}
  covering states and a11y roles; every src module is imported by a test
- typed fixture helper assigns each JSON fixture to its generated OpenAPI type
- fix: iconFor ignores inherited object members such as "constructor"
- fix: field controls import ./control instead of the registry (import cycle
  left a renderer unregistered depending on module load order)
- fix: dropdown shows the placeholder for an unknown stored value next to an emptyOption
- fix: list announces a failed schema load even when the rows arrive after it
- tailwind no longer scans admin/tests; boardwalk/dist rebuilt
2026-09-27 17:53:57 +02:00

142 lines
5.8 KiB
TypeScript

import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest'
import { clearUser, currentUser, login, logout, me, useAuth } from '../../src/state/useAuth'
import { navigation, setNavigation } from '../../src/state/useNavigation'
import { setSettings, settings } from '../../src/state/useSettings'
import { navigationFixture, settingsFixture } from '../fixtures/typed'
import { API, mockApi, profile, requestsTo, resetState } from '../helpers'
const loginOk = (expiresIn: unknown) => ({ body: { data: { token_type: 'cookie', expires_in: expiresIn }, meta: {} } })
const refreshOk = { body: { data: { token_type: 'cookie', expires_in: 50 }, meta: {} } }
const unauthorized = { status: 401, body: { error: { code: 'unauthenticated', message: 'no', details: {} } } }
beforeEach(() => {
resetState()
})
afterEach(() => {
clearUser()
vi.useRealTimers()
})
describe('login', () => {
it('posts the credentials and schedules the proactive refresh at 80 percent', async () => {
vi.useFakeTimers()
const calls = mockApi({ [`POST ${API}/auth/login`]: loginOk(100), [`POST ${API}/auth/refresh`]: refreshOk })
expect(await login('dev', 'secret')).toBe(true)
const body = (await requestsTo(calls, 'POST', `${API}/auth/login`)[0]!.clone().json()) as Record<string, string>
expect(body).toEqual({ login: 'dev', password: 'secret' })
expect(useAuth().expiresIn.value).toBe(100)
await vi.advanceTimersByTimeAsync(79_999)
expect(requestsTo(calls, 'POST', `${API}/auth/refresh`)).toHaveLength(0)
await vi.advanceTimersByTimeAsync(1)
expect(requestsTo(calls, 'POST', `${API}/auth/refresh`)).toHaveLength(1)
// The refresh reschedules from its own lifetime (50 s -> 40 s).
expect(useAuth().expiresIn.value).toBe(50)
await vi.advanceTimersByTimeAsync(40_000)
expect(requestsTo(calls, 'POST', `${API}/auth/refresh`)).toHaveLength(2)
})
it('answers false on rejected credentials and schedules nothing', async () => {
vi.useFakeTimers()
const calls = mockApi({ [`POST ${API}/auth/login`]: unauthorized, [`POST ${API}/auth/refresh`]: refreshOk })
expect(await login('dev', 'bad')).toBe(false)
await vi.advanceTimersByTimeAsync(10_000_000)
expect(requestsTo(calls, 'POST', `${API}/auth/refresh`)).toHaveLength(0)
})
it.each([0, -5, 'soon', null])('schedules no refresh for the lifetime %j', async (expiresIn) => {
vi.useFakeTimers()
const calls = mockApi({ [`POST ${API}/auth/login`]: loginOk(expiresIn), [`POST ${API}/auth/refresh`]: refreshOk })
expect(await login('dev', 'secret')).toBe(true)
await vi.advanceTimersByTimeAsync(10_000_000)
expect(requestsTo(calls, 'POST', `${API}/auth/refresh`)).toHaveLength(0)
})
})
describe('me and clearUser', () => {
it('loads the profile, and clears it on 401', async () => {
mockApi({ [`GET ${API}/auth/me`]: { body: profile } })
expect((await me())?.login).toBe('dev')
expect(currentUser.value?.role?.name).toBe('Developer')
mockApi({ [`GET ${API}/auth/me`]: unauthorized })
expect(await me()).toBeNull()
expect(currentUser.value).toBeNull()
})
it('clearUser forgets the user and cancels the pending refresh', async () => {
vi.useFakeTimers()
const calls = mockApi({
[`GET ${API}/auth/me`]: { body: profile },
[`POST ${API}/auth/login`]: loginOk(10),
[`POST ${API}/auth/refresh`]: refreshOk,
})
await login('dev', 'secret')
await me()
clearUser()
expect(currentUser.value).toBeNull()
expect(useAuth().expiresIn.value).toBeNull()
await vi.advanceTimersByTimeAsync(60_000)
expect(requestsTo(calls, 'POST', `${API}/auth/refresh`)).toHaveLength(0)
})
})
describe('logout (T-10-23)', () => {
async function signedIn(logoutRoute: Parameters<typeof mockApi>[0][string] | 'throw') {
const routes: Parameters<typeof mockApi>[0] = { [`GET ${API}/auth/me`]: { body: profile } }
if (logoutRoute !== 'throw') {
routes[`POST ${API}/auth/logout`] = logoutRoute
}
const calls = mockApi(routes)
await me()
setNavigation(navigationFixture.data)
setSettings(settingsFixture.list.data)
if (logoutRoute === 'throw') {
vi.spyOn(globalThis, 'fetch').mockRejectedValue(new TypeError('offline'))
}
return calls
}
it.each([
['succeeds', { body: { data: { status: 'logged_out' }, meta: {} } }],
['answers 500', { status: 500, body: { error: { code: 'server', message: 'x', details: {} } } }],
['fails on the network', 'throw' as const],
])('clears the user, navigation and settings and routes to login when the call %s', async (_label, route) => {
const calls = await signedIn(route)
const router = { replace: vi.fn().mockResolvedValue(undefined) }
await logout(router)
expect(currentUser.value).toBeNull()
expect(navigation.value).toEqual([])
expect(settings.value).toEqual([])
expect(router.replace).toHaveBeenCalledWith({ name: 'login' })
if (route !== 'throw') {
const posted = requestsTo(calls, 'POST', `${API}/auth/logout`)
expect(posted).toHaveLength(1)
expect(posted[0]!.headers.get('X-Requested-With')).toBe('XMLHttpRequest')
}
})
it('works without a router and swallows a failed navigation', async () => {
await signedIn({ body: { data: { status: 'logged_out' }, meta: {} } })
await expect(logout()).resolves.toBeUndefined()
expect(currentUser.value).toBeNull()
await signedIn({ body: { data: { status: 'logged_out' }, meta: {} } })
await expect(logout({ replace: vi.fn().mockRejectedValue(new Error('aborted')) })).resolves.toBeUndefined()
expect(currentUser.value).toBeNull()
})
it('exposes the session API through useAuth', () => {
const auth = useAuth()
expect(auth.user).toBe(currentUser)
expect(auth.login).toBe(login)
expect(auth.logout).toBe(logout)
expect(auth.me).toBe(me)
expect(auth.clearUser).toBe(clearUser)
})
})