Skip to content

test(auth): add regression coverage proving access/refresh token expiry is config-driven - #170

Merged
datvt243 merged 2 commits into
stagingfrom
155-token-exp-in
Sep 27, 2026
Merged

datvt243 merged 2 commits into
stagingfrom
155-token-exp-in

Conversation

@datvt243

Copy link
Copy Markdown
Owner

Summary

Closes #155. The production fix was already live on staging since commit f355e2f (2026-08-21) — both jwtSign() call sites (login, refresh) already pass TOKEN_EXP_IN/TOKEN_REFRESH_EXP_IN — but no test ever decoded a real issued JWT to prove exp/iat actually reflects the configured duration, and the diagram node was never backfilled.

  • src/__tests__/auth/tokenExpiry.test.ts — uses the real jwtSign/jwtVerify (unmocked) and real config, decodes issued tokens, and proves access vs refresh tokens get 2 distinct, config-driven lifetimes (not a shared hardcoded default), plus regression checks for both fallback defaults (1h access, 7d refresh).
  • agent-hub/: backfilled evidence (implementer + verifier) and sealed node fix-refresh-token-expiry-unused.

Commits

  • 6cfba0a test(auth): add regression coverage proving access/refresh token expiry is config-driven

Test plan

  • npm test — 143 passed, 143 total (independently re-run by the verifier subagent)
  • npm run build — clean

🤖 Generated with Claude Code

datvt243 and others added 2 commits September 28, 2026 01:26
…ry is config-driven

Closes #155. The production fix was already live on staging since
commit f355e2f (2026-08-21) — both jwtSign() call sites (login,
refresh) already pass TOKEN_EXP_IN/TOKEN_REFRESH_EXP_IN — but no test
ever decoded a real issued JWT to prove exp/iat actually reflects the
configured duration, and the diagram node was never backfilled.

- src/__tests__/auth/tokenExpiry.test.ts: uses the real jwtSign/
  jwtVerify (unmocked) and real config, decodes issued tokens, and
  proves access vs refresh tokens get 2 distinct, config-driven
  lifetimes (not a shared hardcoded default), plus regression checks
  for both fallback defaults ('1h' access, '7d' refresh).
- agent-hub: backfill evidence (implementer + verifier) and seal node
  fix-refresh-token-expiry-unused.

npm test: 143 passed, 143 total (independently re-run by the verifier
subagent). npm run build: clean.

Node: fix-refresh-token-expiry-unused (SEALED)
Evidence: agent-hub/evidence/implementer/2026-09-28/fix-refresh-token-expiry-unused-plan.md,
agent-hub/evidence/verifier/2026-09-28/fix-refresh-token-expiry-unused-seal.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@datvt243
datvt243 merged commit 6faec85 into staging Sep 27, 2026
3 checks passed
@datvt243
datvt243 deleted the 155-token-exp-in branch September 27, 2026 18:32
@datvt243 datvt243 mentioned this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant