// 外部測試套件:見 jwks_test.go 開頭說明。 package oidc_test import ( "encoding/json" "net/http" "net/http/httptest" "testing" "alterminal/internal/oidc" ) // Discovery 文件應揭露本服務的全部端點與能力。 func TestDiscoveryHandler(t *testing.T) { rec := httptest.NewRecorder() oidc.DiscoveryHandler(testIssuer)(rec, httptest.NewRequest(http.MethodGet, "/.well-known/openid-configuration", nil)) if rec.Code != http.StatusOK { t.Fatalf("status = %d, want 200", rec.Code) } if cc := rec.Header().Get("Cache-Control"); cc != "public, max-age=3600" { t.Errorf("Cache-Control = %q, want public, max-age=3600", cc) } var doc map[string]any if err := json.Unmarshal(rec.Body.Bytes(), &doc); err != nil { t.Fatalf("解析 Discovery 文件: %v", err) } endpoints := map[string]string{ "issuer": testIssuer, "authorization_endpoint": testIssuer + "/authorize", "token_endpoint": testIssuer + "/token", "userinfo_endpoint": testIssuer + "/userinfo", "jwks_uri": testIssuer + "/.well-known/jwks.json", } for field, want := range endpoints { got, _ := doc[field].(string) if got != want { t.Errorf("%s = %q, want %q", field, got, want) } } lists := map[string][]string{ "scopes_supported": {"email", "offline_access", "openid", "profile"}, "response_types_supported": {"code"}, "grant_types_supported": {"authorization_code", "refresh_token"}, "subject_types_supported": {"public"}, "id_token_signing_alg_values_supported": {"RS256"}, "token_endpoint_auth_methods_supported": {"client_secret_basic", "client_secret_post", "none"}, "code_challenge_methods_supported": {"S256"}, } for field, want := range lists { got, _ := doc[field].([]any) if len(got) != len(want) { t.Errorf("%s = %v, want %v", field, got, want) continue } for i, w := range want { if got[i] != w { t.Errorf("%s[%d] = %v, want %v", field, i, got[i], w) } } } }