first commit

This commit is contained in:
2026-10-03 10:44:29 +08:00
parent f373cb8d37
commit bcf3d3769c
58 changed files with 4313 additions and 487 deletions
+62
View File
@@ -0,0 +1,62 @@
// 外部測試套件:見 jwks_test.go 開頭說明。
package oidc_test
import (
"encoding/json"
"net/http"
"net/http/httptest"
"testing"
"alterminal/internal/oidc"
)
// Discovery 文件應揭露本服務的全部端點與能力。
func TestDiscoveryHandler(t *testing.T) {
rec := httptest.NewRecorder()
oidc.DiscoveryHandler(testIssuer)(rec, httptest.NewRequest(http.MethodGet, "/.well-known/openid-configuration", nil))
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200", rec.Code)
}
if cc := rec.Header().Get("Cache-Control"); cc != "public, max-age=3600" {
t.Errorf("Cache-Control = %q, want public, max-age=3600", cc)
}
var doc map[string]any
if err := json.Unmarshal(rec.Body.Bytes(), &doc); err != nil {
t.Fatalf("解析 Discovery 文件: %v", err)
}
endpoints := map[string]string{
"issuer": testIssuer,
"authorization_endpoint": testIssuer + "/authorize",
"token_endpoint": testIssuer + "/token",
"userinfo_endpoint": testIssuer + "/userinfo",
"jwks_uri": testIssuer + "/.well-known/jwks.json",
}
for field, want := range endpoints {
got, _ := doc[field].(string)
if got != want {
t.Errorf("%s = %q, want %q", field, got, want)
}
}
lists := map[string][]string{
"scopes_supported": {"email", "offline_access", "openid", "profile"},
"response_types_supported": {"code"},
"grant_types_supported": {"authorization_code", "refresh_token"},
"subject_types_supported": {"public"},
"id_token_signing_alg_values_supported": {"RS256"},
"token_endpoint_auth_methods_supported": {"client_secret_basic", "client_secret_post", "none"},
"code_challenge_methods_supported": {"S256"},
}
for field, want := range lists {
got, _ := doc[field].([]any)
if len(got) != len(want) {
t.Errorf("%s = %v, want %v", field, got, want)
continue
}
for i, w := range want {
if got[i] != w {
t.Errorf("%s[%d] = %v, want %v", field, i, got[i], w)
}
}
}
}