diff --git a/src/Yavsc.Org.Tests/Controllers/ClientControllerCollectionTests.cs b/src/Yavsc.Org.Tests/Controllers/ClientControllerCollectionTests.cs index 352f25f9..59f4747e 100644 --- a/src/Yavsc.Org.Tests/Controllers/ClientControllerCollectionTests.cs +++ b/src/Yavsc.Org.Tests/Controllers/ClientControllerCollectionTests.cs @@ -76,10 +76,12 @@ public class ClientControllerCollectionTests : IClassFixture[Authorize("AdministratorOnly")] (and any other policy /// requiring a role) is satisfied by sending an /// X-Test-Role: Administrator header, without a real login. +/// Also injects a middleware that promotes the same header into a +/// real on HttpContext.User so +/// that user code reading User.GetUserId() sees a logged-in +/// identity. /// public class TestWebApplicationFactory : WebApplicationFactory { @@ -33,5 +40,38 @@ public class TestWebApplicationFactory : WebApplicationFactory // becomes irrelevant: any GetPolicyAsync call is routed here. services.AddSingleton(); }); + + // Promote the X-Test-Role header to an authenticated identity + // on the request, so anything that reads User.GetUserId() (or + // any other claim-based helper) downstream sees a logged-in + // user. The policy provider above only short-circuits + // [Authorize(...)] checks; it does not touch HttpContext.User. + builder.Configure(app => + { + app.Use(InjectTestUser); + }); + } + + private static RequestDelegate InjectTestUser(RequestDelegate next) + { + return async ctx => + { + var role = ctx.Request.Headers[TestAuthPolicyProvider.HeaderName].ToString(); + if (!string.IsNullOrEmpty(role) && + (ctx.User.Identity is null || !ctx.User.Identity.IsAuthenticated)) + { + var identity = new ClaimsIdentity( + new[] + { + new Claim( + "http://schemas.microsoft.com/ws/2008/06/identity/claims/role", + role), + new Claim(ClaimTypes.NameIdentifier, "test-user"), + }, + authenticationType: "TestAuth"); + ctx.User = new ClaimsPrincipal(identity); + } + await next(ctx); + }; } } diff --git a/src/Yavsc.Org.Tests/Yavsc.Org.Tests.csproj b/src/Yavsc.Org.Tests/Yavsc.Org.Tests.csproj index f2106a88..c1d7faf1 100644 --- a/src/Yavsc.Org.Tests/Yavsc.Org.Tests.csproj +++ b/src/Yavsc.Org.Tests/Yavsc.Org.Tests.csproj @@ -64,10 +64,25 @@ <_YavscOrgStaticAssetsDir>$(MSBuildProjectDirectory)\..\Yavsc.Org\bin\$(Configuration)\$(TargetFramework) + <_YavscOrgStaticAssetsFiles Include="$(_YavscOrgStaticAssetsDir)\Yavsc.Org.staticwebassets.*.json" />