package oidc import ( "strings" "testing" ) // normalizeScope 應拆解、去重並排序 scope。 func TestNormalizeScope(t *testing.T) { tests := []struct { name string scope string want string }{ {"空字串", "", ""}, {"多餘空白", " openid profile ", "openid profile"}, {"去除重複", "profile openid profile", "openid profile"}, {"排序", "email openid", "email openid"}, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { if got := strings.Join(normalizeScope(tt.scope), " "); got != tt.want { t.Fatalf("normalizeScope(%q) = %q, want %q", tt.scope, got, tt.want) } }) } } // scopeCovered 判斷請求 scope 是否全數涵蓋於已同意集合。 func TestScopeCovered(t *testing.T) { tests := []struct { name string granted string requested string want bool }{ {"完全相同", "openid profile", "openid profile", true}, {"請求子集", "openid profile email", "openid email", true}, {"請求超出", "openid", "openid email", false}, {"完全無關", "openid", "profile", false}, {"空請求", "openid", "", true}, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { if got := scopeCovered(tt.granted, tt.requested); got != tt.want { t.Fatalf("scopeCovered(%q, %q) = %v, want %v", tt.granted, tt.requested, got, tt.want) } }) } } // sha256Token 輸出長度應為 43 字元(32 bytes 的 base64url)。 func TestSha256Token(t *testing.T) { got := sha256Token("test") if len(got) != 43 { t.Fatalf("SHA-256 base64url 長度 = %d, want 43", len(got)) } if sha256Token("test") != got { t.Fatal("同一輸入應得相同雜湊") } if sha256Token("other") == got { t.Fatal("不同輸入應得不同雜湊") } }