import { describe, expect, it } from 'vitest'; import { JwtStrategy } from './jwt.strategy'; /** * JwtStrategy.validate — pinnt die Durchreichung von mustChangePassword * (260921-fi3, Aufgabe 1, Befund 1/D-01). Direkte Konstruktion ohne * Nest-Testmodul, Muster aus `../../tenant/tenant.guard.spec.ts`. */ function makeConfigService() { return { get: () => 'test-secret' } as any; } describe('JwtStrategy.validate', () => { it('Anspruch mustChangePassword=true im Token: liefert request.user.mustChangePassword === true', async () => { const strategy = new JwtStrategy(makeConfigService()); const result = await strategy.validate({ sub: 'u1', username: 'admin', role: 'ADMIN', tenantId: 't1', mustChangePassword: true, }); expect(result.mustChangePassword).toBe(true); }); it('Anspruch fehlt im Token (Alt-Sitzung, vor dieser Aenderung ausgestellt): liefert false statt undefined', async () => { const strategy = new JwtStrategy(makeConfigService()); const result = await strategy.validate({ sub: 'u1', username: 'admin', role: 'ADMIN', tenantId: 't1', }); expect(result.mustChangePassword).toBe(false); }); it('id, username, role und tenantId werden unveraendert wie bisher durchgereicht', async () => { const strategy = new JwtStrategy(makeConfigService()); const result = await strategy.validate({ sub: 'u1', username: 'nutzer1', role: 'USER', tenantId: 't2', mustChangePassword: false, }); expect(result).toEqual({ id: 'u1', username: 'nutzer1', role: 'USER', tenantId: 't2', mustChangePassword: false, }); }); });