// Point the DB at a closed port before requiring the auth layer: session.service // (used by one test below) pulls in the users model → db pool at load, and an idle // pool would keep this process alive. None of these tests touch the database. process.env.JWT_SECRET = process.env.JWT_SECRET || 'test-secret' process.env.DB_HOST = '127.0.0.1' process.env.DB_PORT = '59999' const { test, after } = require('node:test') const assert = require('node:assert/strict') const crypto = require('crypto') const ssoState = require('../src/auth/ssoState') const db = require('../src/utils/db') after(() => db.close()) test('createTx → verifyTx round-trips the flow payload', () => { const tx = ssoState.createTx({ provider: 'google', mode: 'login', returnTo: '/admin/posts' }) assert.ok(tx.nonce && tx.verifier && tx.codeChallenge && tx.txToken) const payload = ssoState.verifyTx(tx.txToken, tx.nonce) assert.ok(payload) assert.equal(payload.provider, 'google') assert.equal(payload.mode, 'login') assert.equal(payload.returnTo, '/admin/posts') assert.equal(payload.verifier, tx.verifier) }) test('codeChallenge is the S256 hash of the verifier', () => { const tx = ssoState.createTx({ provider: 'discord', mode: 'login' }) const expected = crypto.createHash('sha256').update(tx.verifier).digest('base64url') assert.equal(tx.codeChallenge, expected) }) test('verifyTx rejects a mismatched / tampered nonce', () => { const tx = ssoState.createTx({ provider: 'google', mode: 'login' }) assert.equal(ssoState.verifyTx(tx.txToken, 'wrong-nonce'), null) assert.equal(ssoState.verifyTx(tx.txToken, null), null) assert.equal(ssoState.verifyTx(null, tx.nonce), null) }) test('verifyTx rejects a non-tx token', () => { const token = require('../src/auth/token') const notTx = token.signToken({ id: 1, username: 'a', role: 'admin' }) assert.equal(ssoState.verifyTx(notTx, 'anything'), null) }) test('createTotpPending → verifyTotpPending round-trips the SSO 2FA context', () => { const pending = ssoState.createTotpPending({ userId: 7, provider: 'google', authMethod: 'google', returnTo: '/admin/posts' }) const payload = ssoState.verifyTotpPending(pending) assert.ok(payload) assert.equal(payload.id, 7) assert.equal(payload.provider, 'google') assert.equal(payload.authMethod, 'google') assert.equal(payload.returnTo, '/admin/posts') assert.equal(payload.stage, 'totp') }) test('a pending-TOTP token is NOT accepted as a session (stage + kind reject it)', () => { const sessionService = require('../src/auth/session.service') const pending = ssoState.createTotpPending({ userId: 7, provider: 'google', authMethod: 'google' }) assert.equal(sessionService.decodeIdentity(pending), null) }) test('verifyTotpPending rejects a plain session and a bare TOTP challenge', () => { const token = require('../src/auth/token') assert.equal(ssoState.verifyTotpPending(token.signToken({ id: 1, username: 'a', role: 'admin' })), null) assert.equal(ssoState.verifyTotpPending(token.signTotpChallenge({ id: 1 })), null) assert.equal(ssoState.verifyTotpPending(null), null) })