1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
|
import { describe, it, expect } from "bun:test";
import app from "../app";
const HAS_DB = Boolean(process.env.DATABASE_URL);
function generateToken(): string {
const bytes = crypto.getRandomValues(new Uint8Array(32));
return (
"glc_" +
Array.from(bytes)
.map((b) => b.toString(16).padStart(2, "0"))
.join("")
);
}
async function hashToken(token: string): Promise<string> {
const data = new TextEncoder().encode(token);
const hash = await crypto.subtle.digest("SHA-256", data);
return Array.from(new Uint8Array(hash))
.map((b) => b.toString(16).padStart(2, "0"))
.join("");
}
describe("api tokens — generation format", () => {
it("emits a glc_-prefixed token", () => {
const t = generateToken();
expect(t.startsWith("glc_")).toBe(true);
});
it("emits 32 bytes (64 hex chars) of entropy after the prefix", () => {
const t = generateToken();
expect(t.length).toBe("glc_".length + 64);
expect(/^glc_[0-9a-f]{64}$/.test(t)).toBe(true);
});
it("emits unique tokens on repeated calls", () => {
const a = generateToken();
const b = generateToken();
const c = generateToken();
expect(a).not.toBe(b);
expect(b).not.toBe(c);
expect(a).not.toBe(c);
});
});
describe("api tokens — hashing contract (store-the-hash-never-the-value)", () => {
it("produces a deterministic SHA-256 hex digest", async () => {
const token = "glc_" + "a".repeat(64);
const h1 = await hashToken(token);
const h2 = await hashToken(token);
expect(h1).toBe(h2);
expect(/^[0-9a-f]{64}$/.test(h1)).toBe(true);
});
it("never returns the token itself in the hash", async () => {
const token = "glc_" + "b".repeat(64);
const h = await hashToken(token);
expect(h).not.toBe(token);
expect(h).not.toContain("glc_");
});
it("produces distinct hashes for distinct tokens", async () => {
const a = await hashToken("glc_" + "c".repeat(64));
const b = await hashToken("glc_" + "d".repeat(64));
expect(a).not.toBe(b);
});
it("matches the hash the auth middleware looks up (sha256Hex shape)", async () => {
const token = "glc_" + "e".repeat(64);
const { sha256Hex } = await import("../lib/oauth");
expect(await hashToken(token)).toBe(await sha256Hex(token));
});
it("derives a display prefix of the first 12 chars (`glc_` + 8 hex)", () => {
const token = generateToken();
const prefix = token.slice(0, 12);
expect(prefix.startsWith("glc_")).toBe(true);
expect(prefix.length).toBe(12);
expect(token.length - prefix.length).toBeGreaterThanOrEqual(56);
});
});
describe("api tokens — /settings/tokens auth guard", () => {
it("GET /settings/tokens without a session → redirect to /login", async () => {
const res = await app.request("/settings/tokens");
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
it("POST /settings/tokens (create) without a session → redirect to /login", async () => {
const res = await app.request("/settings/tokens", {
method: "POST",
headers: { "content-type": "application/x-www-form-urlencoded" },
body: new URLSearchParams({ name: "CI pipeline", scopes: "repo" }),
});
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
it("POST /settings/tokens/:id/delete (revoke) without a session → redirect to /login", async () => {
const res = await app.request(
"/settings/tokens/00000000-0000-0000-0000-000000000000/delete",
{ method: "POST" }
);
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
});
describe("api tokens — /api/user/tokens contract", () => {
it("GET /api/user/tokens without a session → redirect to /login", async () => {
const res = await app.request("/api/user/tokens");
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
it("GET /api/user/tokens rejects an invalid glc_ bearer with 401 JSON", async () => {
const res = await app.request("/api/user/tokens", {
headers: { authorization: "Bearer glc_deadbeefdeadbeefdeadbeef" },
});
expect(res.status).toBe(401);
const body = await res.json().catch(() => null);
expect(body && typeof body.error === "string").toBe(true);
});
it("GET /api/user/tokens rejects an invalid glct_ (OAuth) bearer with 401 JSON", async () => {
const res = await app.request("/api/user/tokens", {
headers: { authorization: "Bearer glct_notrealoauthtoken1234" },
});
expect(res.status).toBe(401);
});
});
describe("api tokens — expiry enforcement (via middleware)", () => {
it("a well-formed but unknown glc_ token gets 401, not 500", async () => {
const fakeToken = "glc_" + "f".repeat(64);
const res = await app.request("/api/user/tokens", {
headers: { authorization: `Bearer ${fakeToken}` },
});
expect(res.status).toBe(401);
if (HAS_DB) {
const body = await res.json();
expect(body.error).toMatch(/invalid|expired/i);
}
});
it("a glc_ token shorter than the generator length still rejects cleanly", async () => {
const res = await app.request("/api/user/tokens", {
headers: { authorization: "Bearer glc_short" },
});
expect(res.status).toBe(401);
});
});
|