test(auth, api): ensure bearer token is case-insensitive

This commit is contained in:
dswbx
2026-03-28 10:33:24 +01:00
parent 4121597fa2
commit 9219bf3b3c
2 changed files with 29 additions and 0 deletions
+6
View File
@@ -70,4 +70,10 @@ describe("Api", async () => {
expect(params.token_transport).toBe("header"); expect(params.token_transport).toBe("header");
expect(params.host).toBe("http://another.com"); expect(params.host).toBe("http://another.com");
}); });
it("should extract tokens case insensitive", async () => {
const token = await sign({ sub: "test" }, "1234");
expect(new Api({ headers: new Headers({ Authorization: `Bearer ${token}` }) }).getAuthState().token).toBe(token);
expect(new Api({ headers: new Headers({ Authorization: `bearer ${token}` }) }).getAuthState().token).toBe(token);
})
}); });
+23
View File
@@ -38,4 +38,27 @@ describe("Authenticator", async () => {
expect(cookie).toStartWith("auth="); expect(cookie).toStartWith("auth=");
expect(cookie).toEndWith("HttpOnly; Secure; SameSite=Strict"); expect(cookie).toEndWith("HttpOnly; Secure; SameSite=Strict");
}); });
test("bearer token is case insensitive", async () => {
const auth = new Authenticator({}, null as any, {
jwt: {
secret: "secret",
fields: ["sub"],
},
cookie: {
sameSite: "strict",
},
});
const token = await auth.jwt({ sub: "test" });
const res = await auth.resolveAuthFromRequest(new Headers({
Authorization: `Bearer ${token}`,
}));
expect((res as any).sub).toBe("test")
const res2 = await auth.resolveAuthFromRequest(new Headers({
Authorization: `bearer ${token}`,
}));
expect((res2 as any).sub).toBe("test")
})
}); });