import assert from 'node:assert/strict'; import { describe, it } from 'node:test'; import { bearerAuth } from '../src/http/auth.ts'; function run(headers: Record): { status?: number; passed: boolean } { const middleware = bearerAuth('correct-horse-battery-staple'); let status: number | undefined; let passed = false; const req = { get: (name: string) => headers[name.toLowerCase()] } as never; const res = { setHeader() {}, status(code: number) { status = code; return this; }, json() { return this; }, } as never; middleware(req, res, () => { passed = true; }); return { status, passed }; } describe('bearerAuth', () => { it('accepts the exact token', () => { assert.equal(run({ authorization: 'Bearer correct-horse-battery-staple' }).passed, true); }); it('accepts it via x-api-key, for connector UIs without an Authorization field', () => { assert.equal(run({ 'x-api-key': 'correct-horse-battery-staple' }).passed, true); }); it('is case-insensitive about the scheme but not the token', () => { assert.equal(run({ authorization: 'bearer correct-horse-battery-staple' }).passed, true); assert.equal(run({ authorization: 'Bearer CORRECT-HORSE-BATTERY-STAPLE' }).passed, false); }); it('rejects a missing, empty, wrong or truncated token with 401', () => { for (const headers of [ {}, { authorization: '' }, { authorization: 'Bearer ' }, { authorization: 'Bearer wrong' }, { authorization: 'Bearer correct-horse-battery-stapl' }, { authorization: 'Bearer correct-horse-battery-staple-extra' }, { authorization: 'Basic correct-horse-battery-staple' }, ]) { const result = run(headers as Record); assert.equal(result.passed, false, `should reject ${JSON.stringify(headers)}`); assert.equal(result.status, 401); } }); });