HH-437: harden production auth and tenant authorization (#84)

* HH-437 harden auth and account authorization

* HH-437 reject revoked platform access

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-21 19:13:10 +08:00
committed by GitHub
co-authored by rogee
parent 04c1654086
commit cf263d10b4
22 changed files with 442 additions and 90 deletions
+15
View File
@@ -111,6 +111,21 @@ func TestJWTValidateAccessTokenInvalid(t *testing.T) {
assert.Error(t, err)
}
func TestJWTValidationAcceptsPreviousSecretDuringRotation(t *testing.T) {
oldConfig := &config.JWTConfig{Secret: "4kM9sT2vX7qP1dR8nC5hL3wF6bJ0zYgU", ExpiryHours: 1, RefreshExpiryHours: 24}
user := &model.User{Base: model.Base{ID: 1}, Provider: "email"}
pair, err := NewJWTService(oldConfig).GenerateTokenPair(user, 10, "agent")
require.NoError(t, err)
rotated := NewJWTService(&config.JWTConfig{
Secret: "9pN2xR7mV4kD8sQ1cF6hT3wL5bJ0zYgU",
PreviousSecrets: []string{oldConfig.Secret},
})
claims, err := rotated.ValidateAccessToken(pair.AccessToken)
require.NoError(t, err)
assert.Equal(t, user.ID, claims.UserID)
}
func TestJWTValidateAccessTokenRefreshTokenRejected(t *testing.T) {
cfg := &config.JWTConfig{Secret: "testsecret", ExpiryHours: 1, RefreshExpiryHours: 24}
svc := NewJWTService(cfg)