Files
familysync/apps/api/tests/auth/devBypass.test.ts
T
Lucas Berger 03e953158a fix(13-02): eliminate all ESLint violations — pnpm lint exits 0
- eslint.config.js: disable React Compiler rules (v7 flat.recommended enables
  them; codebase does not use the Compiler); add e2e/ to disableTypeChecked
  block; promote exhaustive-deps to error
- API broker: remove redundant as-casts (outboxWorker, poller, reminderScheduler,
  expand, sync, vevent, spike); add targeted ical.js no-unsafe-assignment/argument
  disables with justifying comments inside try blocks
- API routes/sse.ts: fix no-misused-promises on async writeSSE callback with
  void+IIFE+catch pattern
- API routes/lists.ts: let → const for updateValues
- API tests: remove unused imports (beforeEach, eq, vi); rename unused vars
  with _ prefix; remove unused lastActiveId assignment
- PWA components: void navigate() and void queryClient.invalidateQueries() on
  all fire-and-forget call sites; fix CalendarShell explicit-type-casts;
  Couldn't → HTML entity
- PWA test files: as unknown as Response for partial mock objects; string | null
  type annotation on mockLastSyncedUid; remove async from test callbacks without
  await; act(() => {}) not await act(async () => {}) for sync ops
- sw.ts: restructure Notification.data?.url access as let+if so disable
  comments land on the exact violation lines; void self.skipWaiting()
2026-06-11 20:23:38 -04:00

97 lines
3.1 KiB
TypeScript

/**
* devAuthBypass() middleware — unit tests.
*
* Tests the three behavioral cases:
* 1. NODE_ENV='production' → pure passthrough (hard guard), regardless of DEV_AUTH_BYPASS
* 2. NODE_ENV!='production' + DEV_AUTH_BYPASS unset → passthrough (no user injected)
* 3. NODE_ENV!='production' + DEV_AUTH_BYPASS='true' → DEV_USER injected into context
*/
import { describe, it, expect, afterEach } from 'vitest'
import { Hono } from 'hono'
// We import after env manipulation since devAuthBypass() reads env vars at call time.
// Each test resets the module registry via vi.resetModules() to re-evaluate the function
// with the current process.env values.
describe('devAuthBypass middleware', () => {
const originalNodeEnv = process.env.NODE_ENV
const originalBypassFlag = process.env.DEV_AUTH_BYPASS
afterEach(() => {
// Restore env after each test
process.env.NODE_ENV = originalNodeEnv
if (originalBypassFlag === undefined) {
delete process.env.DEV_AUTH_BYPASS
} else {
process.env.DEV_AUTH_BYPASS = originalBypassFlag
}
})
it('is a pure passthrough in production (NODE_ENV=production), even when DEV_AUTH_BYPASS=true', async () => {
process.env.NODE_ENV = 'production'
process.env.DEV_AUTH_BYPASS = 'true'
// Import after env setup
const { devAuthBypass } = await import('../../src/auth/devBypass.js')
const app = new Hono()
app.use('/api/*', devAuthBypass())
let capturedUser: unknown = undefined
app.get('/api/test', (c) => {
capturedUser = c.get('user')
return c.json({ ok: true })
})
const res = await app.request('/api/test')
expect(res.status).toBe(200)
// Hard guard: user must NOT be injected in production
expect(capturedUser).toBeUndefined()
})
it('is a passthrough when NODE_ENV!=production and DEV_AUTH_BYPASS is not set', async () => {
process.env.NODE_ENV = 'test'
delete process.env.DEV_AUTH_BYPASS
const { devAuthBypass } = await import('../../src/auth/devBypass.js')
const app = new Hono()
app.use('/api/*', devAuthBypass())
let capturedUser: unknown = undefined
app.get('/api/test', (c) => {
capturedUser = c.get('user')
return c.json({ ok: true })
})
const res = await app.request('/api/test')
expect(res.status).toBe(200)
expect(capturedUser).toBeUndefined()
})
it('injects DEV_USER when NODE_ENV!=production and DEV_AUTH_BYPASS=true', async () => {
process.env.NODE_ENV = 'test'
process.env.DEV_AUTH_BYPASS = 'true'
const { devAuthBypass, DEV_USER } = await import('../../src/auth/devBypass.js')
const app = new Hono()
app.use('/api/*', devAuthBypass())
let capturedUser: unknown = undefined
app.get('/api/test', (c) => {
capturedUser = c.get('user')
return c.json({ ok: true })
})
const res = await app.request('/api/test')
expect(res.status).toBe(200)
// User must be the fixed DEV_USER
expect(capturedUser).toBeDefined()
expect(capturedUser).toEqual(DEV_USER)
expect((capturedUser as typeof DEV_USER).displayName).toBe('Dev User')
expect((capturedUser as typeof DEV_USER).oidcSub).toBe('dev-user')
})
})