Some checks are pending
offline / test (push) Waiting to run
Signup registers/binds a Verae central user and stores veraeUserId. Public access stays the zappier API key. Chain JWTs stay server-side behind tokenRef. Authz, billing, and jobs.watch carry veraeUserId.
27 lines
925 B
JavaScript
27 lines
925 B
JavaScript
import { describe, it } from 'node:test';
|
|
import assert from 'node:assert/strict';
|
|
import { stableVeraeUserId } from '../../src/lib/identity.js';
|
|
import { issueTokenRef, resolveTokenRef } from '../../src/store/tokenRefs.js';
|
|
import { useTempStore } from '../helpers.js';
|
|
|
|
describe('verae identity', () => {
|
|
it('stableVeraeUserId is deterministic and not a JWT', () => {
|
|
const a = stableVeraeUserId('Ada@Example.com');
|
|
const b = stableVeraeUserId('ada@example.com');
|
|
assert.equal(a, b);
|
|
assert.match(a, /^vu_[0-9a-f]{16}$/);
|
|
assert.doesNotMatch(a, /eyJ/);
|
|
});
|
|
|
|
it('tokenRef resolves tenant and is not a Verae JWT', () => {
|
|
const ctx = useTempStore();
|
|
try {
|
|
const ref = issueTokenRef('tenant-1');
|
|
assert.match(ref, /^tref_/);
|
|
assert.equal(resolveTokenRef(ref), 'tenant-1');
|
|
assert.doesNotMatch(ref, /mock-jwt|eyJ/);
|
|
} finally {
|
|
ctx.cleanup();
|
|
}
|
|
});
|
|
});
|