使用 Mocha 和 Chai 测试 JWT 身份验证

Cli*_*Dev 4 mocha.js node.js express jwt chai

我一直在为我的get端点编写一个测试,它需要 的​​令牌admin来返回用户列表。

这是我的用户端点:

   app.get("/users", (req,res) => {
      const payload = req.payload

      if (payload && payload.user === "admin") {
         User.find({}, (err, users) => {
            if(!err) {
               res.status(200).send(users)
            } else { res.status(500).send(err) }
         })
      } else { res.status(500).send("Authentication Error!)}
   }
Run Code Online (Sandbox Code Playgroud)

这是我的 jwt 中间件:

   module.exports = {
  validateToken: (req, res, next) => {
    const authorizationHeader = req.headers.authorization;
    let result;
    if (authorizationHeader) {
      const token = req.headers.authorization.split(" ")[1]; // Bearer <token>
      const options = {
        expiresIn: "2d",
        issuer: "clint maruti"
      };
      try {
        // verify makes sure that the token hasn't expired and has been issued by us
        result = jwt.verify(token, process.env.JWT_SECRET, options);
        // Let's pass back the decoded token to the request object
        req.decoded = result;
        // We call next to pass execution to the subsequent middleware
        next();
      } catch (err) {
          // Throw an error just in case anything goes wrong with verification
          throw new Error(err)
      }
    } else {
        result = {
            error: 'Authentication error. Token required.',
            status: 401
        }
        res.status(401).send(result)
    }
  }
};
Run Code Online (Sandbox Code Playgroud)

这是我的示例测试:

let User = require("../models/users");

// Require dev dependencies
let chai = require("chai");
let chaiHttp = require("chai-http");
let app = require("../app");
let should = chai.should();

chai.use(chaiHttp);

let defaultUser = {
  name: "admin",
  password: "admin@123"
};

let token;

// parent block
describe("User", () => {
  beforeEach(done => {
    chai
      .request(app)
      .post("/users")
      .send(defaultUser)
      .end((err, res) => {
        res.should.have.status(200);
        done();
      });
  });
  beforeEach(done => {
    chai
      .request(app)
      .post("/login")
      .send(defaultUser)
      .end((err, res) => {
        token = res.body.token;
        res.should.have.status(200);
        done();
      });
  });
  afterEach(done => {
    // After each test we truncate the database
    User.remove({}, err => {
      done();
    });
  });

  describe("/get users", () => {
    it("should fetch all users successfully", done => {
      chai
        .request(app)
        .set("Authentication", token)
        .get("/users")
        .end((err, res) => {
          res.should.have.status(200);
          res.body.should.be.a("object");
          res.body.should.have.property("users");
          done();
        });
    });
  });
});

Run Code Online (Sandbox Code Playgroud)

问题:我的测试给出了断言错误 500,而不是状态代码 200,我编写了 2 个beforeEach函数。一是注册管理员,二是登录管理员并获取令牌。我想知道这是否是导致错误的原因?请帮忙

小智 12

我在这里找到了答案:

如何在 Mocha 测试用例中发送标头(“授权”、“承载令牌”)

您必须设置 { Authorization: "Bearer" + token }而不是"Authentication", token

你必须在.get之后调用.set

 describe("/get users", () => {
    it("should fetch all users successfully", (done) => {
      chai
        .request(app)
        .get("/users")
        .set({ Authorization: `Bearer ${token}` })
        .end((err, res) => {
          res.should.have.status(200);
          res.body.should.be.a("object");
          res.body.should.have.property("users");
          done();
        });
    });
  });
Run Code Online (Sandbox Code Playgroud)