[grade=B] feat(auth): onboard missing credentials into encrypted vault
This commit is contained in:
@@ -50,6 +50,17 @@ describe('TOTP session cookie scope', () => {
|
||||
expect(cookie).not.toMatch(/(?:^|;)\s*Domain=/i);
|
||||
});
|
||||
|
||||
test('host-bound SSO token can only be redeemed on its intended service host', () => {
|
||||
const session = buildSession();
|
||||
const wrongHostToken = session.createHandoffToken('plex.sami');
|
||||
expect(session.redeemHandoffToken(wrongHostToken, 'chat.sami')).toBe(false);
|
||||
expect(session.redeemHandoffToken(wrongHostToken, 'plex.sami')).toBe(false);
|
||||
|
||||
const correctHostToken = session.createHandoffToken('plex.sami');
|
||||
expect(session.redeemHandoffToken(correctHostToken, 'plex.sami')).toBe(true);
|
||||
expect(session.redeemHandoffToken(correctHostToken, 'plex.sami')).toBe(false);
|
||||
});
|
||||
|
||||
test('logout clears the host-only secure cookie', () => {
|
||||
const session = buildSession();
|
||||
const headers = {};
|
||||
|
||||
Reference in New Issue
Block a user