package auth import ( "context" "testing" ) func TestStubHashPoolRoundTrip(t *testing.T) { p := NewStubHashPool() h, err := p.Hash(context.Background(), PasswordLogin, "secret") if err != nil { t.Fatal(err) } ok, err := p.Verify(context.Background(), PasswordLogin, "secret", h) if err != nil || !ok { t.Fatalf("verify: ok=%v err=%v", ok, err) } ok, _ = p.Verify(context.Background(), PasswordLogin, "wrong", h) if ok { t.Fatal("expected mismatch") } } func TestStubSessionTokenPrefix(t *testing.T) { s := NewStubSessionTokens() tok, hash, err := s.Issue(context.Background()) if err != nil { t.Fatal(err) } if !s.LooksLikeSessionToken(tok) { t.Fatalf("token %q should look like session", tok) } if len(hash) != 32 { t.Fatalf("hash len %d", len(hash)) } } func TestStubAPITokenPrefix(t *testing.T) { s := NewStubAPITokens() tok, _, err := s.Issue(context.Background()) if err != nil { t.Fatal(err) } if !s.LooksLikeAPIToken(tok) { t.Fatalf("token %q should look like api", tok) } } func TestStubLoginLocksFailRecord(t *testing.T) { l := NewStubLoginLocks() locked, _ := l.Fail(LockKey{Kind: LockLoginEndpointIP, EndpointID: "a", IP: "1.2.3.4"}) if locked { t.Fatal("stub should not lock") } l.ClearEndpoint("a") if len(l.Cleared) != 1 || l.Cleared[0] != "a" { t.Fatalf("cleared=%v", l.Cleared) } }