test(api): add 401-retry fail-closed regression
Oracle round-5 PASS verdict was non-blocking on this. Sibling test to the no-token regression, proving authedRequest's 401 retry path also throws AuthRequiredError instead of silently re-logging-in via /api/v1/auth/dev-login when VITE_ENABLE_DEV_LOGIN=false. 31/31 unit tests green.
This commit is contained in:
@@ -123,3 +123,18 @@ describe("authedRequest fail-closed when dev-login disabled", () => {
|
||||
delete (import.meta.env as any).VITE_ENABLE_DEV_LOGIN;
|
||||
});
|
||||
});
|
||||
|
||||
describe("authedRequest 401 retry fail-closed when dev-login disabled", () => {
|
||||
beforeEach(() => {
|
||||
import.meta.env.VITE_ENABLE_DEV_LOGIN = "false";
|
||||
});
|
||||
it("throws AuthRequiredError on 401 instead of silently re-logging in", async () => {
|
||||
const calls = mockFetch([
|
||||
(url) => url.endsWith("/api/v1/auth/me") ? new Response("expired", { status: 401 }) : undefined,
|
||||
]);
|
||||
sessionStorage.setItem("fm.mc.token.v1", "stale-token");
|
||||
await expect(api.me()).rejects.toThrow(/Sign in required/);
|
||||
expect(calls.filter((c) => c.url.endsWith("/dev-login")).length).toBe(0);
|
||||
delete (import.meta.env as any).VITE_ENABLE_DEV_LOGIN;
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user