fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -300,6 +300,17 @@ test("rejects non-HTTPS issuer configuration and a discovery issuer mismatch", a
|
||||
}
|
||||
});
|
||||
|
||||
test("enforces the exact shared OIDC client-secret boundary", () => {
|
||||
expect(() => createOidcProtocol({
|
||||
issuer, clientId, clientSecret: "s".repeat(4096), callbackUrl,
|
||||
scopes: ["openid"], groupsClaim: "groups",
|
||||
})).not.toThrow();
|
||||
expect(() => createOidcProtocol({
|
||||
issuer, clientId, clientSecret: "s".repeat(4097), callbackUrl,
|
||||
scopes: ["openid"], groupsClaim: "groups",
|
||||
})).toThrow(OidcProtocolError);
|
||||
});
|
||||
|
||||
test.each([
|
||||
["authorization", { authorization_endpoint: "http://127.0.0.1/authorize" }],
|
||||
["token", { token_endpoint: "http://127.0.0.1/token" }],
|
||||
|
||||
Reference in New Issue
Block a user