Software /
code /
prosody
File
spec/util_jwt_spec.lua @ 11853:ae5ac9830add
mod_http_file_share: return 401 instead of 403 if authentication failed
This is as per the HTTP standards [1]. Thankfully, the REQUIRED
www-authenticate header is already generated by the code.
[1]: https://datatracker.ietf.org/doc/html/rfc7235#section-3.1
author | Jonas Schäfer <jonas@wielicki.name> |
---|---|
date | Tue, 19 Oct 2021 16:37:32 +0200 |
parent | 10661:4eee1aaa9405 |
child | 12696:27a72982e331 |
line wrap: on
line source
local jwt = require "util.jwt"; describe("util.jwt", function () it("validates", function () local key = "secret"; local token = jwt.sign(key, { payload = "this" }); assert.string(token); local ok, parsed = jwt.verify(key, token); assert.truthy(ok) assert.same({ payload = "this" }, parsed); end); it("rejects invalid", function () local key = "secret"; local token = jwt.sign("wrong", { payload = "this" }); assert.string(token); local ok = jwt.verify(key, token); assert.falsy(ok) end); end);