77 lines
2.4 KiB
TypeScript
77 lines
2.4 KiB
TypeScript
import { describe, it, expect, beforeEach, afterEach, vi } from 'vitest';
|
|
|
|
describe('backend runtime configuration', () => {
|
|
const OLD_ENV = process.env;
|
|
|
|
beforeEach(() => {
|
|
vi.resetModules();
|
|
process.env = { ...OLD_ENV };
|
|
delete process.env.JWT_SECRET;
|
|
delete process.env.JWT_REFRESH_SECRET;
|
|
delete process.env.BACKEND_CORS_ORIGINS;
|
|
});
|
|
|
|
afterEach(() => {
|
|
process.env = OLD_ENV;
|
|
});
|
|
|
|
it('keeps dev auth defaults outside production', async () => {
|
|
const configuration = (await import('./configuration')).default;
|
|
|
|
expect(configuration().auth).toMatchObject({
|
|
jwtSecret: 'dev-jwt-secret-change-in-production',
|
|
jwtRefreshSecret: 'dev-refresh-secret-change-in-production',
|
|
});
|
|
});
|
|
|
|
it('parses backend CORS origins from comma-separated env', async () => {
|
|
process.env.BACKEND_CORS_ORIGINS = 'https://app.example.com, http://localhost:5173 ';
|
|
const configuration = (await import('./configuration')).default;
|
|
|
|
expect(configuration().cors.origins).toEqual([
|
|
'https://app.example.com',
|
|
'http://localhost:5173',
|
|
]);
|
|
});
|
|
|
|
it('rejects production defaults for JWT secrets', async () => {
|
|
const { assertSafeProductionConfig } = await import('../main');
|
|
|
|
expect(() =>
|
|
assertSafeProductionConfig({
|
|
nodeEnv: 'production',
|
|
jwtSecret: 'dev-jwt-secret-change-in-production',
|
|
jwtRefreshSecret: 'custom-refresh-secret',
|
|
corsOrigins: ['https://app.example.com'],
|
|
}),
|
|
).toThrow('JWT_SECRET must be set to a non-default value in production');
|
|
});
|
|
|
|
it('rejects production credentialed CORS without explicit origins', async () => {
|
|
const { assertSafeProductionConfig } = await import('../main');
|
|
|
|
expect(() =>
|
|
assertSafeProductionConfig({
|
|
nodeEnv: 'production',
|
|
jwtSecret: 'custom-access-secret',
|
|
jwtRefreshSecret: 'custom-refresh-secret',
|
|
corsOrigins: [],
|
|
}),
|
|
).toThrow('BACKEND_CORS_ORIGINS must contain at least one origin in production');
|
|
});
|
|
|
|
it('allows development with reflected CORS', async () => {
|
|
const { buildCorsOrigin } = await import('../main');
|
|
|
|
expect(buildCorsOrigin('development', [])).toBe(true);
|
|
});
|
|
|
|
it('uses explicit production CORS origins', async () => {
|
|
const { buildCorsOrigin } = await import('../main');
|
|
|
|
expect(buildCorsOrigin('production', ['https://app.example.com'])).toEqual([
|
|
'https://app.example.com',
|
|
]);
|
|
});
|
|
});
|