-
Notifications
You must be signed in to change notification settings - Fork 0
/
middleware_test.go
100 lines (92 loc) · 3.07 KB
/
middleware_test.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
package api
import (
"fmt"
"net/http"
"net/http/httptest"
"testing"
"time"
"github.com/gin-gonic/gin"
"github.com/hhow09/simple_bank/api/middlewares"
"github.com/hhow09/simple_bank/constants"
"github.com/hhow09/simple_bank/token"
"github.com/stretchr/testify/require"
)
const (
authPath = "/auth"
)
func addAuth(t *testing.T, request *http.Request, tokenMaker token.Maker, authType string, username string, duration time.Duration) {
token, err := tokenMaker.CreateToken(username, duration)
require.NoError(t, err)
authHeader := fmt.Sprintf("%s %s", authType, token)
request.Header.Set(constants.AuthHeaderKey, authHeader)
}
func TestAuthMiddleware(t *testing.T) {
testCases := []struct {
name string
setupAuth func(t *testing.T, request *http.Request, tokenMaker token.Maker)
checkResponse func(t *testing.T, recorder *httptest.ResponseRecorder)
}{
{
name: "OK",
setupAuth: func(t *testing.T, request *http.Request, tokenMaker token.Maker) {
addAuth(t, request, tokenMaker, constants.AuthTypeBearer, "user", time.Minute)
},
checkResponse: func(t *testing.T, recorder *httptest.ResponseRecorder) {
require.Equal(t, recorder.Code, http.StatusOK)
},
},
{
name: "No Auth",
setupAuth: func(t *testing.T, request *http.Request, tokenMaker token.Maker) {
},
checkResponse: func(t *testing.T, recorder *httptest.ResponseRecorder) {
require.Equal(t, recorder.Code, http.StatusUnauthorized)
},
},
{
name: "Unsupported Auth Type",
setupAuth: func(t *testing.T, request *http.Request, tokenMaker token.Maker) {
addAuth(t, request, tokenMaker, "unsupported", "user", time.Minute)
},
checkResponse: func(t *testing.T, recorder *httptest.ResponseRecorder) {
require.Equal(t, recorder.Code, http.StatusUnauthorized)
},
},
{
name: "Invalid Auth Format",
setupAuth: func(t *testing.T, request *http.Request, tokenMaker token.Maker) {
addAuth(t, request, tokenMaker, "", "user", time.Minute)
},
checkResponse: func(t *testing.T, recorder *httptest.ResponseRecorder) {
require.Equal(t, recorder.Code, http.StatusUnauthorized)
},
},
{
name: "Expired Token",
setupAuth: func(t *testing.T, request *http.Request, tokenMaker token.Maker) {
addAuth(t, request, tokenMaker, constants.AuthTypeBearer, "user", -time.Minute)
},
checkResponse: func(t *testing.T, recorder *httptest.ResponseRecorder) {
require.Equal(t, recorder.Code, http.StatusUnauthorized)
},
},
}
for i := range testCases {
tc := testCases[i]
t.Run(tc.name, func(t *testing.T) {
server := newTestServer(t, nil)
//setup simple test route
authMiddleware := middlewares.NewAuthMiddleware(server.tokenMaker)
server.router.GET(authPath, authMiddleware.Handler(), func(ctx *gin.Context) {
//simple response
ctx.JSON(http.StatusOK, gin.H{})
})
recorder := httptest.NewRecorder()
request, err := http.NewRequest(http.MethodGet, authPath, nil)
require.NoError(t, err)
tc.setupAuth(t, request, server.tokenMaker)
server.router.ServeHTTP(recorder, request)
tc.checkResponse(t, recorder)
})
}
}