import assert from 'node:assert/strict'; import { describe, it } from 'node:test'; import { bearerAuth, pathSecret } from '../src/http/auth.ts'; function run(headers: Record): { status?: number; passed: boolean } { const middleware = bearerAuth('correct-horse-battery-staple'); let status: number | undefined; let passed = false; const req = { get: (name: string) => headers[name.toLowerCase()] } as never; const res = { setHeader() {}, status(code: number) { status = code; return this; }, json() { return this; }, } as never; middleware(req, res, () => { passed = true; }); return { status, passed }; } describe('bearerAuth', () => { it('accepts the exact token', () => { assert.equal(run({ authorization: 'Bearer correct-horse-battery-staple' }).passed, true); }); it('accepts it via x-api-key, for connector UIs without an Authorization field', () => { assert.equal(run({ 'x-api-key': 'correct-horse-battery-staple' }).passed, true); }); it('is case-insensitive about the scheme but not the token', () => { assert.equal(run({ authorization: 'bearer correct-horse-battery-staple' }).passed, true); assert.equal(run({ authorization: 'Bearer CORRECT-HORSE-BATTERY-STAPLE' }).passed, false); }); it('rejects a missing, empty, wrong or truncated token with 401', () => { for (const headers of [ {}, { authorization: '' }, { authorization: 'Bearer ' }, { authorization: 'Bearer wrong' }, { authorization: 'Bearer correct-horse-battery-stapl' }, { authorization: 'Bearer correct-horse-battery-staple-extra' }, { authorization: 'Basic correct-horse-battery-staple' }, ]) { const result = run(headers as Record); assert.equal(result.passed, false, `should reject ${JSON.stringify(headers)}`); assert.equal(result.status, 401); } }); }); describe('pathSecret', () => { const secret = 'a'.repeat(40) + 'B-_9'; function visit(presented: unknown): { status?: number; passed: boolean } { const middleware = pathSecret(secret); let status: number | undefined; let passed = false; const req = { params: { secret: presented } } as never; const res = { status(code: number) { status = code; return this; }, json() { return this; }, } as never; middleware(req, res, () => { passed = true; }); return { status, passed }; } it('lets the exact secret through', () => { assert.equal(visit(secret).passed, true); }); it('answers anything else like an unknown path, not like a refused login', () => { for (const presented of [undefined, '', 'mcp', secret.slice(0, -1), `${secret}x`, secret.toUpperCase()]) { const result = visit(presented); assert.equal(result.passed, false, `should reject ${JSON.stringify(presented)}`); assert.equal(result.status, 404); } }); });