Bind each customer to a Verae userId for hop tracing
Some checks are pending
offline / test (push) Waiting to run
Some checks are pending
offline / test (push) Waiting to run
Signup registers/binds a Verae central user and stores veraeUserId. Public access stays the zappier API key. Chain JWTs stay server-side behind tokenRef. Authz, billing, and jobs.watch carry veraeUserId.
This commit is contained in:
parent
1b199ca4d4
commit
345aeeead9
79 changed files with 703 additions and 95 deletions
27
packages/verae-zapier-middleware/test/unit/identity.test.js
Normal file
27
packages/verae-zapier-middleware/test/unit/identity.test.js
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
import { describe, it } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import { stableVeraeUserId } from '../../src/lib/identity.js';
|
||||
import { issueTokenRef, resolveTokenRef } from '../../src/store/tokenRefs.js';
|
||||
import { useTempStore } from '../helpers.js';
|
||||
|
||||
describe('verae identity', () => {
|
||||
it('stableVeraeUserId is deterministic and not a JWT', () => {
|
||||
const a = stableVeraeUserId('Ada@Example.com');
|
||||
const b = stableVeraeUserId('ada@example.com');
|
||||
assert.equal(a, b);
|
||||
assert.match(a, /^vu_[0-9a-f]{16}$/);
|
||||
assert.doesNotMatch(a, /eyJ/);
|
||||
});
|
||||
|
||||
it('tokenRef resolves tenant and is not a Verae JWT', () => {
|
||||
const ctx = useTempStore();
|
||||
try {
|
||||
const ref = issueTokenRef('tenant-1');
|
||||
assert.match(ref, /^tref_/);
|
||||
assert.equal(resolveTokenRef(ref), 'tenant-1');
|
||||
assert.doesNotMatch(ref, /mock-jwt|eyJ/);
|
||||
} finally {
|
||||
ctx.cleanup();
|
||||
}
|
||||
});
|
||||
});
|
||||
Loading…
Add table
Add a link
Reference in a new issue