// Point the DB at a closed port BEFORE requiring anything that builds the pool, // so any stray DB path fails fast instead of holding the process open. The cases // here reject at requireAuth (no session token) before any query runs. process.env.DB_HOST = '127.0.0.1' process.env.DB_PORT = '59999' const { test, after } = require('node:test') const assert = require('node:assert/strict') const { startApp } = require('./_helper') const authRouter = require('../src/router/v1/auth/auth.routes') const db = require('../src/utils/db') after(() => db.close()) // The role-agnostic /auth/me/* self surface must be gated: every route sits behind // requireAuth (any role), so an unauthenticated caller gets 401 — never a 404 // (which would mean the route isn't mounted) and never a 200. test('/auth/me/account* rejects unauthenticated callers with 401', async () => { const app = await startApp((a) => a.use('/api/v1/auth', authRouter)) try { const calls = [ ['GET', '/api/v1/auth/me/account'], ['GET', '/api/v1/auth/me/account/identities'], ['PATCH', '/api/v1/auth/me/account/username', { username: 'someone' }], ['PATCH', '/api/v1/auth/me/account/password', { newPassword: 'abcd1234' }], ['POST', '/api/v1/auth/me/account/totp/setup'], ['POST', '/api/v1/auth/me/account/totp/enable', { code: '123456' }], ['DELETE', '/api/v1/auth/me/account/identities/google'], ] for (const [method, path, body] of calls) { const res = await fetch(app.url + path, { method, headers: body ? { 'Content-Type': 'application/json' } : {}, body: body ? JSON.stringify(body) : undefined, }) assert.equal(res.status, 401, `${method} ${path} should be 401, got ${res.status}`) } } finally { await app.close() } })