Files
Reactive-Resume/apps/server/src/mcp/auth.test.ts
T
Amruth Pillai 9a803305c8 fix: address verified v6 app findings
Fix authentication recovery, account imports, application tracking, resume
editing and exports, sharing, API contracts, provider selection, and private
local attachments. Preserve authored content during PDF pagination.

Update guides, generated OpenAPI output, and translation catalogs to match
verified behavior and documented constraints.

Validation: 1,019 tests passed; 12 database/OAuth integration tests skipped.
Ten affected package typechecks, production build, Biome, and package
boundaries passed.
2026-09-30 06:15:09 +02:00

25 lines
1.1 KiB
TypeScript

import { beforeEach, expect, it, vi } from "vitest";
const resolve = vi.hoisted(() => vi.fn());
vi.mock("@reactive-resume/api/context", () => ({ resolveUserFromRequestHeaders: resolve }));
import { AuthError, authenticateRequest } from "./auth";
beforeEach(() => resolve.mockReset());
it("resolves MCP credentials through the shared API auth policy without accepting cookies", async () => {
resolve.mockResolvedValue({ id: "user-1" });
await authenticateRequest(
new Request("https://resume.example/mcp", {
headers: { authorization: "Bearer valid-token", "x-api-key": "expired-key", cookie: "session=browser" },
}),
);
const headers = resolve.mock.calls[0]?.[0] as Headers;
expect(headers.get("authorization")).toBe("Bearer valid-token");
expect(headers.get("x-api-key")).toBe("expired-key");
expect(headers.has("cookie")).toBe(false);
});
it("rejects requests when shared credential resolution finds no user", async () => {
resolve.mockResolvedValue(null);
await expect(authenticateRequest(new Request("https://resume.example/mcp"))).rejects.toBeInstanceOf(AuthError);
});