test Login angepasst, return fail wenn formaDaten leer

This commit is contained in:
2025-10-17 12:12:07 +02:00
parent 01afbea9a3
commit 416118197b
2 changed files with 112 additions and 110 deletions

View File

@@ -1,6 +1,6 @@
import { dev } from '$app/environment';
import { loginUser, logoutUser } from '$lib/server/authService';
import { redirect } from '@sveltejs/kit';
import { fail, redirect } from '@sveltejs/kit';
import { ROUTE_NAMES } from '../index.js';
export const actions = {
@@ -8,9 +8,13 @@ export const actions = {
logout: (event) => logoutUser(event),
getVorgangByToken: async ({ request, cookies }) => {
const data = await request.formData();
const vorgangToken = data.get('vorgang-token') as string;
const vorgangToken = data.get('vorgang-token');
const vorgangPIN = data.get('vorgang-pin') as string;
if (!vorgangToken || !vorgangPIN) {
return fail(400, { message: 'Token oder PIN fehlen' });
}
const COOKIE_NAME = `token-${vorgangToken}`;
cookies.set(COOKIE_NAME, vorgangPIN, {
path: '/',

View File

@@ -1,16 +1,18 @@
import { describe, it, expect, vi } from 'vitest';
import { actions } from '$root/routes/anmeldung/+page.server';
import { load } from '$root/routes/(token-based)/+layout.server'
// import { actions } from '$root/routes/anmeldung/+page.server';
// import { load } from '$root/routes/(token-based)/+layout.server'
import { actions } from '../../src/routes/anmeldung/+page.server';
import { load } from '../../src/routes/(token-based)/+layout.server';
import { baseData } from '../fixtures';
import { ROUTE_NAMES } from '../../src/routes';
import { dev } from '$app/environment';
import { vorgangExists, vorgangPINValidation } from '$lib/server/vorgangService';
import { Redirect } from '@sveltejs/kit';
import type { Redirect } from '@sveltejs/kit';
vi.mock('$lib/server/vorgangService', () => ({
vorgangExists: vi.fn(),
vorgangPINValidation: vi.fn(),
vorgangPINValidation: vi.fn()
}));
describe('Vorgang Anzeige via Token', () => {
@@ -47,7 +49,7 @@ describe('Vorgang Anzeige via Token', () => {
expect(thrownRedirect?.location).toBe(ROUTE_NAMES.VORGANG(vorgObj.vorgangToken));
// Cookie wurde gesetzt
const COOKIE_NAME = `token-${vorgObj.vorgangToken}`
const COOKIE_NAME = `token-${vorgObj.vorgangToken}`;
expect(cookiesSet).toHaveBeenCalledWith(COOKIE_NAME, vorgObj.vorgangPIN, {
path: '/',
httpOnly: true,
@@ -58,40 +60,35 @@ describe('Vorgang Anzeige via Token', () => {
it('Schlägt fehl wenn keine Daten übergeben werden', async () => {
const formData = new FormData(); // no data
const mockRequest = {
formData: vi.fn().mockResolvedValue(formData)
};
const cookiesSet = vi.fn();
const event = {
request: mockRequest,
cookies: {
set: cookiesSet
}
};
const result = await actions.getVorgangByToken(event);
expect(result).toBeUndefined();
expect(result.status).toBe(400);
expect(result.data.message).toMatch(/fehlen|ungültig/i);
// Cookie wird nicht gesetzt
expect(cookiesSet).not.toHaveBeenCalled();
});
it.todo('Überprüfe was passiert, wenn Eingabe falsch, bzw. nicht im System passend gefunden');
});
describe('Teste Guard', () => {
it('Lese Cookie aus', async () => {
const vorgObj = baseData.vorgang;
const COOKIE_NAME = `token-${vorgObj.vorgangToken}`
const COOKIE_NAME = `token-${vorgObj.vorgangToken}`;
const cookiesGet = vi.fn().mockImplementation((key: string) => {
if (key === COOKIE_NAME) return vorgObj.vorgangPIN;
return undefined;
});
// mocked objects
const event = {
cookies: {
@@ -111,13 +108,12 @@ describe('Teste Guard', () => {
it('Kein Cookie gesetzt', async () => {
const vorgObj = baseData.vorgang;
const COOKIE_NAME = `token-${vorgObj.vorgangToken}`
const COOKIE_NAME = `token-${vorgObj.vorgangToken}`;
const cookiesGet = vi.fn().mockImplementation((key: string) => {
if (key === COOKIE_NAME) return vorgObj.vorgangPIN;
return undefined;
});
// mocked objects
const event = {
cookies: {
@@ -132,12 +128,14 @@ describe('Teste Guard', () => {
let thrownRedirect;
try {
await load(event);
throw new Error('Function did not throw')
throw new Error('Function did not throw');
} catch (e) {
thrownRedirect = e;
}
expect(thrownRedirect?.status).toBe(303);
expect(thrownRedirect?.location).toBe(ROUTE_NAMES.ANMELDUNG_VORGANG_PARAM(vorgObj.vorgangToken));
expect(thrownRedirect?.location).toBe(
ROUTE_NAMES.ANMELDUNG_VORGANG_PARAM(vorgObj.vorgangToken)
);
expect(cookiesGet).toHaveBeenCalledWith(COOKIE_NAME);
});