4e21ca937a
Deploy Documentation / deploy (push) Has been cancelled
Canary / Prepare Version (push) Has been cancelled
Canary / build-cli (push) Has been cancelled
Canary / Upload Install Script (push) Has been cancelled
Canary / bundle-desktop (push) Has been cancelled
Canary / bundle-desktop-intel (push) Has been cancelled
Canary / bundle-desktop-linux (push) Has been cancelled
Canary / bundle-desktop-windows (push) Has been cancelled
Canary / bundle-desktop-windows-cuda (push) Has been cancelled
Canary / Release (push) Has been cancelled
Unused Dependencies / machete (push) Has been cancelled
CI / changes (push) Has been cancelled
CI / Check Rust Code Format (push) Has been cancelled
CI / Build and Test Rust Project (push) Has been cancelled
CI / Build Rust Project on Windows (push) Has been cancelled
CI / Check MSRV (push) Has been cancelled
CI / Lint Rust Code (push) Has been cancelled
CI / Check Generated Schemas are Up-to-Date (push) Has been cancelled
CI / Test and Lint Electron Desktop App (push) Has been cancelled
CI / H5 Plaza Tests and Build (push) Has been cancelled
Live Provider Tests / check-fork (push) Has been cancelled
Live Provider Tests / changes (push) Has been cancelled
Live Provider Tests / Build Binary (push) Has been cancelled
Live Provider Tests / Smoke Tests (push) Has been cancelled
Live Provider Tests / Smoke Tests (Code Execution) (push) Has been cancelled
Live Provider Tests / Compaction Tests (push) Has been cancelled
Live Provider Tests / goose server HTTP integration tests (push) Has been cancelled
Publish Ask AI Bot Docker Image / docker (push) Has been cancelled
Publish Docker Image / docker (push) Has been cancelled
Scorecard supply-chain security / Scorecard analysis (push) Has been cancelled
Fork goose with custom MCP widgets, platform extensions (aider, git, web, search), MindSpace H5 backend/frontend, Plaza/Ops UIs, and deploy scripts for tkmind.cn. Co-authored-by: Cursor <cursoragent@cursor.com>
39 lines
1.2 KiB
JavaScript
39 lines
1.2 KiB
JavaScript
import assert from 'node:assert/strict';
|
|
import test from 'node:test';
|
|
import {
|
|
AUTH_COOKIE,
|
|
createAuthManager,
|
|
parseCookies,
|
|
sessionCookie,
|
|
} from './auth.mjs';
|
|
|
|
test('auth manager issues, verifies, and revokes sessions', () => {
|
|
const auth = createAuthManager({ password: 'secret', ttlMs: 1_000 });
|
|
const login = auth.login('secret', '127.0.0.1', 100);
|
|
|
|
assert.equal(login.ok, true);
|
|
assert.equal(auth.verify(login.token, 200), true);
|
|
auth.revoke(login.token);
|
|
assert.equal(auth.verify(login.token, 300), false);
|
|
});
|
|
|
|
test('auth manager rate limits repeated failures', () => {
|
|
const auth = createAuthManager({
|
|
password: 'secret',
|
|
maxFailures: 2,
|
|
failureWindowMs: 1_000,
|
|
});
|
|
|
|
assert.equal(auth.login('wrong', 'client', 100).ok, false);
|
|
assert.equal(auth.login('wrong', 'client', 200).ok, false);
|
|
assert.equal(auth.login('secret', 'client', 300).retryAfterMs, 800);
|
|
assert.equal(auth.login('secret', 'client', 1_200).ok, true);
|
|
});
|
|
|
|
test('cookie helpers preserve opaque tokens', () => {
|
|
const cookie = sessionCookie('a/b+c', true);
|
|
assert.match(cookie, /HttpOnly/);
|
|
assert.match(cookie, /Secure/);
|
|
assert.equal(parseCookies(cookie)[AUTH_COOKIE], 'a/b+c');
|
|
});
|