feat(auth): add remembered local login to the frontend
This commit is contained in:
@@ -0,0 +1,57 @@
|
||||
import { http, HttpResponse } from "msw";
|
||||
import { afterEach, beforeEach, expect, test } from "vitest";
|
||||
import { apiFetch } from "../api/client";
|
||||
import { queryClient } from "../app/queryClient";
|
||||
import { server } from "../test/msw";
|
||||
import { useSessionStore } from "../store/sessionStore";
|
||||
import { clearAuthState, getAuthState, setAuthState } from "./authState";
|
||||
|
||||
const userA = {
|
||||
issuer: "local", subject: "user-a", roles: ["user"] as const, permissions: ["session.use"], isAdmin: false,
|
||||
csrfToken: "a".repeat(43), session: null,
|
||||
};
|
||||
const userB = { ...userA, subject: "user-b", csrfToken: "b".repeat(43) };
|
||||
|
||||
beforeEach(() => {
|
||||
queryClient.clear();
|
||||
useSessionStore.getState().resetSession();
|
||||
clearAuthState();
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
queryClient.clear();
|
||||
useSessionStore.getState().resetSession();
|
||||
clearAuthState();
|
||||
});
|
||||
|
||||
function seedUserAData() {
|
||||
setAuthState(userA);
|
||||
queryClient.setQueryData(["sessions", "mine"], [{ id: "a-session" }]);
|
||||
useSessionStore.getState().applyEvent({ type: "text_delta", text: "A transcript" });
|
||||
}
|
||||
|
||||
test("an ordinary API 401 scrubs A data before B can log in", async () => {
|
||||
server.use(http.get("/api/ordinary-expiry", () => new HttpResponse(null, { status: 401 })));
|
||||
seedUserAData();
|
||||
|
||||
await expect(apiFetch("/ordinary-expiry")).rejects.toMatchObject({ status: 401 });
|
||||
expect(getAuthState()).toBeNull();
|
||||
expect(queryClient.getQueryData(["sessions", "mine"])).toBeUndefined();
|
||||
expect(useSessionStore.getState().transcript).toEqual([]);
|
||||
|
||||
setAuthState(userB);
|
||||
expect(getAuthState()).toMatchObject({ subject: "user-b" });
|
||||
expect(queryClient.getQueryData(["sessions", "mine"])).toBeUndefined();
|
||||
expect(useSessionStore.getState().transcript).toEqual([]);
|
||||
});
|
||||
|
||||
test("logout followed by B login cannot retain A cache or live transcript", () => {
|
||||
seedUserAData();
|
||||
|
||||
clearAuthState();
|
||||
setAuthState(userB);
|
||||
|
||||
expect(getAuthState()).toMatchObject({ subject: "user-b" });
|
||||
expect(queryClient.getQueryData(["sessions", "mine"])).toBeUndefined();
|
||||
expect(useSessionStore.getState().transcript).toEqual([]);
|
||||
});
|
||||
Reference in New Issue
Block a user