release: NX9-WG v1.0.0
This commit is contained in:
1 parent
c8a9b7cde6
commit
4dfe42fe68
42 files changed
+4689
-336
No files matched your search
@@ -253,3 +253,54 @@ async fn test_auth_service_api_tokens() {
|
||||
"revoked token must fail authentication"
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn test_auth_service_logout_invalidates_session_and_is_idempotent() {
|
||||
let store = Store::connect_in_memory().await.expect("connect");
|
||||
store.migrate().await.expect("migrate");
|
||||
|
||||
let config = AppConfig::default();
|
||||
let opts = BootstrapOptions {
|
||||
cli_password: Some("AdminSecret123!".to_string()),
|
||||
..Default::default()
|
||||
};
|
||||
bootstrap_admin(&store, &config, &opts)
|
||||
.await
|
||||
.expect("bootstrap");
|
||||
|
||||
let auth = AuthService::new(store);
|
||||
|
||||
// Create 2 sessions
|
||||
let s1 = auth
|
||||
.login("admin", "AdminSecret123!", Some("10.0.0.1"), None)
|
||||
.await
|
||||
.expect("login 1");
|
||||
let s2 = auth
|
||||
.login("admin", "AdminSecret123!", Some("10.0.0.2"), None)
|
||||
.await
|
||||
.expect("login 2");
|
||||
|
||||
assert!(auth.authenticate_session(&s1.id).await.is_ok());
|
||||
assert!(auth.authenticate_session(&s2.id).await.is_ok());
|
||||
|
||||
// Logout session 1
|
||||
auth.logout(&s1.id, Some("10.0.0.1"))
|
||||
.await
|
||||
.expect("logout s1");
|
||||
|
||||
// Session 1 is invalidated; Session 2 remains valid
|
||||
assert!(
|
||||
auth.authenticate_session(&s1.id).await.is_err(),
|
||||
"s1 must be rejected after logout"
|
||||
);
|
||||
assert!(
|
||||
auth.authenticate_session(&s2.id).await.is_ok(),
|
||||
"s2 must remain valid"
|
||||
);
|
||||
|
||||
// Repeated logout of s1 is safe/idempotent
|
||||
assert!(
|
||||
auth.logout(&s1.id, Some("10.0.0.1")).await.is_ok(),
|
||||
"repeated logout must be safe and idempotent"
|
||||
);
|
||||
}
|
||||
Reference in new issue
Block a user