HH-437: harden production auth and tenant authorization (#84)
* HH-437 harden auth and account authorization * HH-437 reject revoked platform access --------- Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
@@ -111,6 +111,21 @@ func TestJWTValidateAccessTokenInvalid(t *testing.T) {
|
||||
assert.Error(t, err)
|
||||
}
|
||||
|
||||
func TestJWTValidationAcceptsPreviousSecretDuringRotation(t *testing.T) {
|
||||
oldConfig := &config.JWTConfig{Secret: "4kM9sT2vX7qP1dR8nC5hL3wF6bJ0zYgU", ExpiryHours: 1, RefreshExpiryHours: 24}
|
||||
user := &model.User{Base: model.Base{ID: 1}, Provider: "email"}
|
||||
pair, err := NewJWTService(oldConfig).GenerateTokenPair(user, 10, "agent")
|
||||
require.NoError(t, err)
|
||||
|
||||
rotated := NewJWTService(&config.JWTConfig{
|
||||
Secret: "9pN2xR7mV4kD8sQ1cF6hT3wL5bJ0zYgU",
|
||||
PreviousSecrets: []string{oldConfig.Secret},
|
||||
})
|
||||
claims, err := rotated.ValidateAccessToken(pair.AccessToken)
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, user.ID, claims.UserID)
|
||||
}
|
||||
|
||||
func TestJWTValidateAccessTokenRefreshTokenRejected(t *testing.T) {
|
||||
cfg := &config.JWTConfig{Secret: "testsecret", ExpiryHours: 1, RefreshExpiryHours: 24}
|
||||
svc := NewJWTService(cfg)
|
||||
|
||||
Reference in New Issue
Block a user