yavsc/src/Yavsc.Tests.Shared/Yavsc.Tests.Shared.csproj

26 lines
1.1 KiB
XML
Raw Normal View History

<Project Sdk="Microsoft.NET.Sdk">
<PropertyGroup>
2026-08-23 18:34:34 +01:00
<TargetFramework>net10.0</TargetFramework>
<ImplicitUsings>enable</ImplicitUsings>
<Nullable>enable</Nullable>
<IsPackable>false</IsPackable>
<RootNamespace>Yavsc.Tests.Shared</RootNamespace>
<!--
Shared library of test fixtures (WebHostFixture, auth bypass,
etc.) consumed by both Yavsc.Org.Tests and Yavsc.Blogs.Tests.
Not a test project itself: no xUnit, no test runner, no
TestSdk. The consumer projects own the test execution and
inherit from the shared base classes.
-->
<AssemblyVersion>1.1.0.0</AssemblyVersion>
<FileVersion>1.1.0.0</FileVersion>
<InformationalVersion>1.1.0-beta.1+1.Branch.release-1.0.8-rc1.Sha.1167169aa89e1bf25290e9a152d27b357a500ab3</InformationalVersion>
<Version>1.1.0-beta.1</Version>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.AspNetCore.Hosting" />
<PackageReference Include="Microsoft.AspNetCore.Mvc.Testing" />
test(blogs): real JwtBearer in fixture, drop X-Test-Role bypass Wire the Blogs integration test host with a real AddJwtBearer (HS256, IssuerSigningKey shared with the new TestTokenIssuer) and the production BlogScope policy verbatim, instead of the TestAuthPolicyProvider / AllowAllAuthorizationService / NoopAuthHandler stack that short-circuited every authorization check. Why: BlogSpotService.Modify calls IAuthorizationService.AuthorizeAsync(user, blog, EditPermission); the previous AllowAllAuthorizationService stub made that a no-op, so the tests could not exercise the real ownership chain and any change in PermissionHandler would silently slip through. The new test host registers the real PermissionHandler, so a PUT that succeeds (204) is now proof that PermissionHandler.IsOwner accepted the request — i.e. the JWT's sub matched the post's AuthorId, end-to-end. Notes for future-me: - JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear() is called once on the first Issue() to keep the 'sub' claim literal; without it UserHelpers.GetUserId (which reads 'sub') gets ClaimTypes.NameIdentifier instead, returns null, and the owner check fails for every PUT. The companion options.MapInboundClaims = false on the validation pipeline keeps both sides in sync. - Production still uses AddYavscJwtBearer against the OIDC authority; the test-only HS256 path is local to the test process and never crosses a network boundary. Coverage: - GetBlog_returns_401_when_no_token_is_provided — anonymous request, real policy fails closed. - PutBlog_with_valid_token_and_owner_returns_204_and_Get_ reflects_update — POST then PUT then GET, all behind a real JWT, asserting 204 + list contains the updated title. Packages added to Directory.Packages.props at 8.2.1 to match what Microsoft.AspNetCore.Authentication.JwtBearer 10.0.9 already transitively pulls in (no version drift).
2026-07-06 23:29:51 +01:00
<PackageReference Include="Microsoft.IdentityModel.Tokens" />
<PackageReference Include="System.IdentityModel.Tokens.Jwt" />
</ItemGroup>
2026-08-22 16:58:08 +01:00
</Project>