package auth import ( "encoding/json" "net/http" "net/http/httptest" "testing" ) func TestExchangeCodeAuthTokenFlow(t *testing.T) { mux := http.NewServeMux() mux.HandleFunc("/api/acepilot/zhanlu/authToken", func(w http.ResponseWriter, r *http.Request) { if r.Method != http.MethodPost { t.Errorf("method = %s", r.Method) } var in map[string]string _ = json.NewDecoder(r.Body).Decode(&in) if in["deputyAccountNumber"] != "dep-123" { t.Errorf("deputyAccountNumber = %q", in["deputyAccountNumber"]) } // plaintext profile (DecryptCredentialOrRaw fallback) writeTestJSON(w, map[string]any{"state": "OK", "body": map[string]any{ "email": "ssouser@example.com", "organization": "org", "team": "team", }}) }) ts := httptest.NewServer(mux) defer ts.Close() profile, err := ExchangeCode(&http.Client{}, ts.URL+"/api/acepilot/zhanlu/authToken", "dep-123", "3jw7woww2rvhla6k") if err != nil { t.Fatalf("ExchangeCode: %v", err) } if profile.Email != "ssouser@example.com" || profile.Organization != "org" || profile.Team != "team" { t.Fatalf("profile = %+v", profile) } } func TestExchangeCodeMissingFields(t *testing.T) { mux := http.NewServeMux() mux.HandleFunc("/x", func(w http.ResponseWriter, r *http.Request) { writeTestJSON(w, map[string]any{"state": "OK", "body": map[string]any{}}) }) ts := httptest.NewServer(mux) defer ts.Close() if _, err := ExchangeCode(&http.Client{}, ts.URL+"/x", "dep", ""); err == nil { t.Fatal("expected error for empty profile") } } func writeTestJSON(w http.ResponseWriter, v any) { w.Header().Set("Content-Type", "application/json") _ = json.NewEncoder(w).Encode(v) }