Files
PnvPanel/backend/tests/PnvPanel.Application.Tests/Auth/GetCurrentUserQueryHandlerTests.cs
T
Leonid Pershin 8067be3c35
CI / Backend (build + test) (push) Successful in 1m17s
CI / Frontend (lint + typecheck + build) (push) Successful in 35s
Implement rate limiting and enhance authentication flow
- Added rate limiting configuration for authentication endpoints, allowing customizable request limits via environment variables.
- Updated authentication flow to utilize HttpRequest for cookie management, ensuring secure handling of refresh tokens.
- Introduced a new endpoint to retrieve user subscription details.
- Enhanced the handling of Telegram bot token validation to prevent errors with empty tokens.
- Updated the application to serialize enums as strings for better documentation and compatibility with TypeScript.
- Improved test coverage for new features and adjustments in command handlers.
2026-07-02 12:40:23 +03:00

60 lines
2.3 KiB
C#

using NSubstitute;
using PnvPanel.Application.Auth;
using PnvPanel.Application.Auth.Me;
using PnvPanel.Application.Common.Interfaces;
using PnvPanel.Application.Tests.TestSupport;
using Xunit;
namespace PnvPanel.Application.Tests.Auth;
public class GetCurrentUserQueryHandlerTests
{
private readonly IIdentityService _identityService = Substitute.For<IIdentityService>();
[Fact]
public async Task Handle_Unauthenticated_ReturnsUnauthorized()
{
var handler = new GetCurrentUserQueryHandler(_identityService, FakeCurrentUser.Anonymous());
var result = await handler.Handle(new GetCurrentUserQuery(), CancellationToken.None);
Assert.False(result.IsSuccess);
Assert.Equal(AuthErrors.Unauthorized, result.Error);
}
[Fact]
public async Task Handle_ProfileMissing_ReturnsUnauthorized()
{
var userId = Guid.NewGuid();
_identityService.GetProfileAsync(userId, Arg.Any<CancellationToken>()).Returns((CurrentUserProfile?)null);
var handler = new GetCurrentUserQueryHandler(_identityService, FakeCurrentUser.Authenticated(userId));
var result = await handler.Handle(new GetCurrentUserQuery(), CancellationToken.None);
Assert.False(result.IsSuccess);
Assert.Equal(AuthErrors.Unauthorized, result.Error);
}
[Fact]
public async Task Handle_AuthenticatedWithProfile_ReturnsCurrentUserDto()
{
var userId = Guid.NewGuid();
var profile = new CurrentUserProfile(userId, "alice", Guid.NewGuid(), "user", true, false, 3, "sub-token");
_identityService.GetProfileAsync(userId, Arg.Any<CancellationToken>()).Returns(profile);
_identityService.GetTelegramLinkInfoAsync(userId, Arg.Any<CancellationToken>())
.Returns(new TelegramLinkInfo(true, 42, "alice_tg"));
var handler = new GetCurrentUserQueryHandler(_identityService, FakeCurrentUser.Authenticated(userId, "alice"));
var result = await handler.Handle(new GetCurrentUserQuery(), CancellationToken.None);
Assert.True(result.IsSuccess);
Assert.Equal(userId, result.Value.Id);
Assert.Equal("alice", result.Value.UserName);
Assert.Equal("user", result.Value.Role);
Assert.True(result.Value.IsActivated);
Assert.True(result.Value.TelegramLinked);
}
}