84 lines
2.9 KiB
Erlang
84 lines
2.9 KiB
Erlang
-module(admin_handler_refresh_tests).
|
||
-include_lib("eunit/include/eunit.hrl").
|
||
-include("records.hrl").
|
||
|
||
-define(TABLES, [admin, admin_audit, auth_session, ticket]).
|
||
-define(ADMIN_ID, <<"adm_test_1">>).
|
||
|
||
setup() ->
|
||
eh_test_support:start_mnesia(),
|
||
eh_test_support:ensure_tables(?TABLES),
|
||
_ = mnesia:add_table_index(auth_session, #auth_session.family_id),
|
||
_ = mnesia:add_table_index(auth_session, #auth_session.subject_id),
|
||
eh_test_support:ensure_jwt(),
|
||
catch ets:new(eventhub_counters, [named_table, public, set, {write_concurrency, true}]),
|
||
eh_test_support:seed_admin(#{id => ?ADMIN_ID, role => admin}),
|
||
ok.
|
||
|
||
cleanup(_) ->
|
||
eh_test_support:unload_cowboy(),
|
||
eh_test_support:delete_tables(?TABLES),
|
||
eh_test_support:stop_mnesia(),
|
||
ok.
|
||
|
||
admin_refresh_test_() ->
|
||
{foreach, fun setup/0, fun cleanup/1, [
|
||
{"POST refresh – success", {timeout, 60, fun test_refresh_ok/0}},
|
||
{"POST refresh – invalid token", {timeout, 60, fun test_refresh_invalid/0}},
|
||
{"POST refresh – missing field", {timeout, 60, fun test_refresh_missing_field/0}},
|
||
{"POST refresh – invalid JSON", {timeout, 60, fun test_refresh_invalid_json/0}},
|
||
{"GET refresh – method not allowed", {timeout, 60, fun test_wrong_method/0}}
|
||
]}.
|
||
|
||
test_refresh_ok() ->
|
||
{ok, _Access, Refresh} = logic_auth_session:issue_admin_tokens(?ADMIN_ID, <<"admin">>),
|
||
{Status, _, Body} = eh_test_support:call(admin_handler_refresh, #{
|
||
method => <<"POST">>,
|
||
path => <<"/v1/admin/refresh">>,
|
||
auth => none,
|
||
body => jsx:encode(#{<<"refresh_token">> => Refresh})
|
||
}),
|
||
?assertEqual(200, Status),
|
||
Resp = jsx:decode(Body, [return_maps]),
|
||
?assert(is_map_key(<<"token">>, Resp)),
|
||
?assert(is_map_key(<<"refresh_token">>, Resp)),
|
||
NewRefresh = maps:get(<<"refresh_token">>, Resp),
|
||
?assertNotEqual(Refresh, NewRefresh),
|
||
{ok, _, _} = eventhub_auth:verify_admin_token(maps:get(<<"token">>, Resp)).
|
||
|
||
test_refresh_invalid() ->
|
||
{Status, _, Body} = eh_test_support:call(admin_handler_refresh, #{
|
||
method => <<"POST">>,
|
||
path => <<"/v1/admin/refresh">>,
|
||
auth => none,
|
||
body => jsx:encode(#{<<"refresh_token">> => <<"not-a-valid-token">>})
|
||
}),
|
||
?assertEqual(401, Status),
|
||
#{<<"error">> := _} = jsx:decode(Body, [return_maps]).
|
||
|
||
test_refresh_missing_field() ->
|
||
{Status, _, _} = eh_test_support:call(admin_handler_refresh, #{
|
||
method => <<"POST">>,
|
||
path => <<"/v1/admin/refresh">>,
|
||
auth => none,
|
||
body => jsx:encode(#{<<"token">> => <<"x">>})
|
||
}),
|
||
?assertEqual(400, Status).
|
||
|
||
test_refresh_invalid_json() ->
|
||
{Status, _, _} = eh_test_support:call(admin_handler_refresh, #{
|
||
method => <<"POST">>,
|
||
path => <<"/v1/admin/refresh">>,
|
||
auth => none,
|
||
body => <<"not-json">>
|
||
}),
|
||
?assertEqual(400, Status).
|
||
|
||
test_wrong_method() ->
|
||
{Status, _, _} = eh_test_support:call(admin_handler_refresh, #{
|
||
method => <<"GET">>,
|
||
path => <<"/v1/admin/refresh">>,
|
||
auth => none
|
||
}),
|
||
?assertEqual(405, Status).
|