Initial commit

This commit is contained in:
2026-05-18 13:17:28 -04:00
committed by GitHub
commit 16fadfd529
91 changed files with 3321 additions and 0 deletions
+55
View File
@@ -0,0 +1,55 @@
require "rails_helper"
RSpec.describe BlacklistedToken, type: :model do
let(:user) { User.create!(email: "test@example.com", password: "123456", password_confirmation: "123456") }
describe "validations" do
it "requires jti" do
token = BlacklistedToken.new(user: user, exp: 1.hour.from_now)
expect(token.valid?).to be false
expect(token.errors[:jti]).to include("can't be blank")
end
it "requires exp" do
token = BlacklistedToken.new(user: user, jti: SecureRandom.uuid)
expect(token.valid?).to be false
expect(token.errors[:exp]).to include("can't be blank")
end
it "requires unique jti" do
jti = SecureRandom.uuid
BlacklistedToken.create!(user: user, jti: jti, exp: 1.hour.from_now)
duplicate = BlacklistedToken.new(user: user, jti: jti, exp: 1.hour.from_now)
expect(duplicate.valid?).to be false
expect(duplicate.errors[:jti]).to include("has already been taken")
end
end
describe ".blacklisted?" do
it "returns true for blacklisted tokens" do
jti = SecureRandom.uuid
BlacklistedToken.create!(user: user, jti: jti, exp: 1.hour.from_now)
expect(BlacklistedToken.blacklisted?(jti)).to be true
end
it "returns false for non-blacklisted tokens" do
expect(BlacklistedToken.blacklisted?("non-existent-jti")).to be false
end
end
describe ".cleanup_expired" do
it "removes expired tokens" do
expired_token = BlacklistedToken.create!(user: user, jti: SecureRandom.uuid, exp: 1.day.ago)
valid_token = BlacklistedToken.create!(user: user, jti: SecureRandom.uuid, exp: 1.hour.from_now)
expect {
BlacklistedToken.cleanup_expired
}.to change { BlacklistedToken.count }.by(-1)
expect(BlacklistedToken.exists?(expired_token.id)).to be false
expect(BlacklistedToken.exists?(valid_token.id)).to be true
end
end
end
+71
View File
@@ -0,0 +1,71 @@
require "rails_helper"
RSpec.describe RefreshToken, type: :model do
let(:user) { User.create!(email: "test@example.com", password: "123456", password_confirmation: "123456") }
describe "validations" do
it "generates token automatically" do
token = RefreshToken.create!(user: user)
expect(token.token).to be_present
end
it "sets expiration automatically" do
token = RefreshToken.create!(user: user)
expect(token.expires_at).to be_present
expect(token.expires_at).to be > Time.current
end
it "requires unique token" do
token1 = RefreshToken.create!(user: user)
token2 = RefreshToken.new(user: user, token: token1.token, expires_at: 7.days.from_now)
expect(token2.valid?).to be false
expect(token2.errors[:token]).to include("has already been taken")
end
end
describe "#active?" do
it "returns true for non-revoked, non-expired tokens" do
token = RefreshToken.create!(user: user)
expect(token.active?).to be true
end
it "returns false for revoked tokens" do
token = RefreshToken.create!(user: user, revoked: true)
expect(token.active?).to be false
end
it "returns false for expired tokens" do
token = RefreshToken.create!(user: user, expires_at: 1.day.ago)
expect(token.active?).to be false
end
end
describe "#revoke!" do
it "marks token as revoked" do
token = RefreshToken.create!(user: user)
expect(token.revoked).to be false
token.revoke!
expect(token.revoked).to be true
end
end
describe ".cleanup_old_tokens" do
it "removes expired and revoked tokens" do
old_expired = RefreshToken.create!(user: user, expires_at: 31.days.ago)
old_revoked = RefreshToken.create!(user: user, revoked: true, created_at: 31.days.ago, expires_at: 1.day.from_now)
recent_revoked = RefreshToken.create!(user: user, revoked: true, expires_at: 1.day.from_now)
valid_token = RefreshToken.create!(user: user)
expect {
RefreshToken.cleanup_old_tokens
}.to change { RefreshToken.count }.by(-2)
expect(RefreshToken.exists?(old_expired.id)).to be false
expect(RefreshToken.exists?(old_revoked.id)).to be false
expect(RefreshToken.exists?(recent_revoked.id)).to be true
expect(RefreshToken.exists?(valid_token.id)).to be true
end
end
end
+72
View File
@@ -0,0 +1,72 @@
# This file is copied to spec/ when you run 'rails generate rspec:install'
require 'spec_helper'
ENV['RAILS_ENV'] ||= 'test'
require_relative '../config/environment'
# Prevent database truncation if the environment is production
abort("The Rails environment is running in production mode!") if Rails.env.production?
# Uncomment the line below in case you have `--require rails_helper` in the `.rspec` file
# that will avoid rails generators crashing because migrations haven't been run yet
# return unless Rails.env.test?
require 'rspec/rails'
# Add additional requires below this line. Rails is not loaded until this point!
# Requires supporting ruby files with custom matchers and macros, etc, in
# spec/support/ and its subdirectories. Files matching `spec/**/*_spec.rb` are
# run as spec files by default. This means that files in spec/support that end
# in _spec.rb will both be required and run as specs, causing the specs to be
# run twice. It is recommended that you do not name files matching this glob to
# end with _spec.rb. You can configure this pattern with the --pattern
# option on the command line or in ~/.rspec, .rspec or `.rspec-local`.
#
# The following line is provided for convenience purposes. It has the downside
# of increasing the boot-up time by auto-requiring all files in the support
# directory. Alternatively, in the individual `*_spec.rb` files, manually
# require only the support files necessary.
#
# Rails.root.glob('spec/support/**/*.rb').sort_by(&:to_s).each { |f| require f }
# Ensures that the test database schema matches the current schema file.
# If there are pending migrations it will invoke `db:test:prepare` to
# recreate the test database by loading the schema.
# If you are not using ActiveRecord, you can remove these lines.
begin
ActiveRecord::Migration.maintain_test_schema!
rescue ActiveRecord::PendingMigrationError => e
abort e.to_s.strip
end
RSpec.configure do |config|
# Remove this line if you're not using ActiveRecord or ActiveRecord fixtures
config.fixture_paths = [
Rails.root.join('spec/fixtures')
]
# If you're not using ActiveRecord, or you'd prefer not to run each of your
# examples within a transaction, remove the following line or assign false
# instead of true.
config.use_transactional_fixtures = true
# You can uncomment this line to turn off ActiveRecord support entirely.
# config.use_active_record = false
# RSpec Rails uses metadata to mix in different behaviours to your tests,
# for example enabling you to call `get` and `post` in request specs. e.g.:
#
# RSpec.describe UsersController, type: :request do
# # ...
# end
#
# The different available types are documented in the features, such as in
# https://rspec.info/features/8-0/rspec-rails
#
# You can also this infer these behaviours automatically by location, e.g.
# /spec/models would pull in the same behaviour as `type: :model` but this
# behaviour is considered legacy and will be removed in a future version.
#
# To enable this behaviour uncomment the line below.
# config.infer_spec_type_from_file_location!
# Filter lines from Rails gems in backtraces.
config.filter_rails_from_backtrace!
# arbitrary gems may also be filtered via:
# config.filter_gems_from_backtrace("gem name")
end
+42
View File
@@ -0,0 +1,42 @@
require "swagger_helper"
RSpec.describe "api/v1/admin", type: :request do
path "/api/v1/admin/dashboard" do
get "admin dashboard (admin only)" do
tags "Admin"
produces "application/json"
security [ bearer_auth: [] ]
response "200", "admin dashboard accessed" do
let!(:admin_user) { User.create!(email: "admin@example.com", password: "123456", password_confirmation: "123456", role: :admin) }
let(:Authorization) { "Bearer #{JsonWebToken.encode(user_id: admin_user.id)}" }
run_test! do |response|
data = JSON.parse(response.body)
expect(data["message"]).to include("Welcome to admin dashboard")
expect(data["stats"]).to be_present
expect(data["stats"]["total_users"]).to be_a(Integer)
end
end
response "403", "forbidden for non-admin users" do
let!(:regular_user) { User.create!(email: "user@example.com", password: "123456", password_confirmation: "123456", role: :user) }
let(:Authorization) { "Bearer #{JsonWebToken.encode(user_id: regular_user.id)}" }
run_test! do |response|
data = JSON.parse(response.body)
expect(data["error"]).to include("Forbidden")
end
end
response "401", "unauthorized without token" do
let(:Authorization) { "" }
run_test! do |response|
data = JSON.parse(response.body)
expect(data["error"]).to include("unauthorized")
end
end
end
end
end
+37
View File
@@ -0,0 +1,37 @@
require "swagger_helper"
RSpec.describe "api/v1/auth", type: :request do
path "/api/v1/login" do
post "logs in a user" do
tags "Auth"
consumes "application/json"
produces "application/json"
security []
parameter name: :credentials, in: :body, schema: {
type: :object,
required: %w[email password],
properties: {
email: {
type: :string,
example: "bob@random.com"
},
password: {
type: :string,
example: "123456"
}
}
}
response "200", "logged in" do
let!(:user) { User.create(email: "bob@random.com", password: "123456", password_confirmation: "123456") }
let(:credentials) { { email: "bob@random.com", password: "123456" } }
run_test!
end
response "401", "invalid credentials" do
let(:credentials) { { email: "notbob@example.com", password: "wrong" } }
run_test!
end
end
end
end
+55
View File
@@ -0,0 +1,55 @@
require "swagger_helper"
RSpec.describe "api/v1/logout", type: :request do
path "/api/v1/logout" do
post "logs out user and blacklists token" do
tags "Auth"
consumes "application/json"
produces "application/json"
security [ bearer_auth: [] ]
let!(:user) { User.create!(email: "test@example.com", password: "123456", password_confirmation: "123456") }
response "200", "successfully logged out" do
let(:Authorization) do
token = JsonWebToken.encode(user_id: user.id)
"Bearer #{token}"
end
run_test! do |response|
data = JSON.parse(response.body)
expect(data["message"]).to include("Successfully logged out")
# verify token was blacklisted by checking the response
# (we can't decode the token variable here as it's scoped to the let block)
end
end
response "401", "unauthorized without token" do
let(:Authorization) { "" }
run_test! do |response|
data = JSON.parse(response.body)
expect(data["error"]).to include("unauthorized")
end
end
end
end
describe "blacklisted token rejection" do
it "rejects requests with blacklisted tokens" do
user = User.create!(email: "test@example.com", password: "123456", password_confirmation: "123456")
token = JsonWebToken.encode(user_id: user.id)
# first logout to blacklist the token
post "/api/v1/logout", headers: { "Authorization" => "Bearer #{token}" }
expect(response).to have_http_status(:ok)
# try to access protected endpoint with blacklisted token
get "/api/v1/profile", headers: { "Authorization" => "Bearer #{token}" }
expect(response).to have_http_status(:unauthorized)
data = JSON.parse(response.body)
expect(data["error"]).to include("Token has been revoked")
end
end
end
+23
View File
@@ -0,0 +1,23 @@
require "swagger_helper"
RSpec.describe "api/v1/profile", type: :request do
path "/api/v1/profile" do
get "get current user info using jwt token" do
tags "Profile"
security [ bearer_auth: [] ]
produces "application/json"
response "200", "profile fetched" do
let!(:user) { User.create(email: "bob@random.com", password: "123456", password_confirmation: "123456") }
let(:Authorization) { "Bearer #{JsonWebToken.encode(user_id: user.id)}" }
run_test!
end
response "401", "unauthorized access" do
let(:Authorization) { "" }
run_test!
end
end
end
end
+29
View File
@@ -0,0 +1,29 @@
require "rails_helper"
RSpec.describe "Rack::Attack throttling", type: :request do
describe "POST /api/v1/login" do
let!(:user) do
User.create(email: "bob@random.com", password: "123456", password_confirmation: "123456")
end
it "throttles after 3 login attempts" do
3.times do
post "/api/v1/login", params: {
email: "bob@random.com",
password: "wrongpassword"
}.to_json, headers: { "CONTENT_TYPE" => "application/json" }
expect(response.status).to_not eq(429)
end
# this one is going to be blocked. too much attempt
post "/api/v1/login", params: {
email: "bob@random.com",
password: "wrongpassword"
}.to_json, headers: { "CONTENT_TYPE" => "application/json" }
expect(response.status).to eq(429)
expect(response.body).to include("chill out")
end
end
end
+55
View File
@@ -0,0 +1,55 @@
require "swagger_helper"
RSpec.describe "api/v1/refresh", type: :request do
path "/api/v1/refresh" do
post "refreshes access token using refresh token" do
tags "Auth"
consumes "application/json"
produces "application/json"
security []
parameter name: :refresh_request, in: :body, schema: {
type: :object,
required: %w[refresh_token],
properties: {
refresh_token: { type: :string, example: "your_refresh_token_here" }
}
}
let(:user) { User.create!(email: "test@example.com", password: "123456", password_confirmation: "123456") }
let(:refresh_token_record) { user.refresh_tokens.create! }
response "200", "new access token issued" do
let(:refresh_request) { { refresh_token: refresh_token_record.token } }
run_test! do |response|
data = JSON.parse(response.body)
expect(data["access_token"]).to be_present
expect(data["user"]["email"]).to eq("test@example.com")
end
end
response "401", "invalid or expired refresh token" do
let(:refresh_request) { { refresh_token: "invalid_token" } }
run_test! do |response|
data = JSON.parse(response.body)
expect(data["error"]).to include("Invalid or expired refresh token")
end
end
response "401", "revoked refresh token" do
before do
refresh_token_record.revoke!
end
let(:refresh_request) { { refresh_token: refresh_token_record.token } }
run_test! do |response|
data = JSON.parse(response.body)
expect(data["error"]).to include("Invalid or expired refresh token")
end
end
end
end
end
+51
View File
@@ -0,0 +1,51 @@
require "swagger_helper"
RSpec.describe "api/v1/signup", type: :request do
path "/api/v1/signup" do
post "registers a new user and returns a jwt" do
tags "Auth"
consumes "application/json"
produces "application/json"
security []
parameter name: :user, in: :body, schema: {
type: :object,
required: %w[email password password_confirmation],
properties: {
email: { type: :string, example: "newbob@example.com" },
password: { type: :string, example: "123456" },
password_confirmation: { type: :string, example: "123456" }
}
}
response "201", "user created and token returned" do
let(:user) do
{
email: "newbob@example.com",
password: "123456",
password_confirmation: "123456"
}
end
run_test!
end
response "422", "validation failed invalid email + password" do
let(:user) do
{
email: "",
password: "123456",
password_confirmation: "000000"
}
end
run_test! do |response|
data = JSON.parse(response.body)
expect(data["errors"]).to include(
"Email can't be blank",
"Password confirmation doesn't match Password"
)
end
end
end
end
end
+94
View File
@@ -0,0 +1,94 @@
# This file was generated by the `rails generate rspec:install` command. Conventionally, all
# specs live under a `spec` directory, which RSpec adds to the `$LOAD_PATH`.
# The generated `.rspec` file contains `--require spec_helper` which will cause
# this file to always be loaded, without a need to explicitly require it in any
# files.
#
# Given that it is always loaded, you are encouraged to keep this file as
# light-weight as possible. Requiring heavyweight dependencies from this file
# will add to the boot time of your test suite on EVERY test run, even for an
# individual file that may not need all of that loaded. Instead, consider making
# a separate helper file that requires the additional dependencies and performs
# the additional setup, and require it from the spec files that actually need
# it.
#
# See https://rubydoc.info/gems/rspec-core/RSpec/Core/Configuration
RSpec.configure do |config|
# rspec-expectations config goes here. You can use an alternate
# assertion/expectation library such as wrong or the stdlib/minitest
# assertions if you prefer.
config.expect_with :rspec do |expectations|
# This option will default to `true` in RSpec 4. It makes the `description`
# and `failure_message` of custom matchers include text for helper methods
# defined using `chain`, e.g.:
# be_bigger_than(2).and_smaller_than(4).description
# # => "be bigger than 2 and smaller than 4"
# ...rather than:
# # => "be bigger than 2"
expectations.include_chain_clauses_in_custom_matcher_descriptions = true
end
# rspec-mocks config goes here. You can use an alternate test double
# library (such as bogus or mocha) by changing the `mock_with` option here.
config.mock_with :rspec do |mocks|
# Prevents you from mocking or stubbing a method that does not exist on
# a real object. This is generally recommended, and will default to
# `true` in RSpec 4.
mocks.verify_partial_doubles = true
end
# This option will default to `:apply_to_host_groups` in RSpec 4 (and will
# have no way to turn it off -- the option exists only for backwards
# compatibility in RSpec 3). It causes shared context metadata to be
# inherited by the metadata hash of host groups and examples, rather than
# triggering implicit auto-inclusion in groups with matching metadata.
config.shared_context_metadata_behavior = :apply_to_host_groups
# The settings below are suggested to provide a good initial experience
# with RSpec, but feel free to customize to your heart's content.
=begin
# This allows you to limit a spec run to individual examples or groups
# you care about by tagging them with `:focus` metadata. When nothing
# is tagged with `:focus`, all examples get run. RSpec also provides
# aliases for `it`, `describe`, and `context` that include `:focus`
# metadata: `fit`, `fdescribe` and `fcontext`, respectively.
config.filter_run_when_matching :focus
# Allows RSpec to persist some state between runs in order to support
# the `--only-failures` and `--next-failure` CLI options. We recommend
# you configure your source control system to ignore this file.
config.example_status_persistence_file_path = "spec/examples.txt"
# Limits the available syntax to the non-monkey patched syntax that is
# recommended. For more details, see:
# https://rspec.info/features/3-12/rspec-core/configuration/zero-monkey-patching-mode/
config.disable_monkey_patching!
# Many RSpec users commonly either run the entire suite or an individual
# file, and it's useful to allow more verbose output when running an
# individual spec file.
if config.files_to_run.one?
# Use the documentation formatter for detailed output,
# unless a formatter has already been configured
# (e.g. via a command-line flag).
config.default_formatter = "doc"
end
# Print the 10 slowest examples and example groups at the
# end of the spec run, to help surface which specs are running
# particularly slow.
config.profile_examples = 10
# Run specs in random order to surface order dependencies. If you find an
# order dependency and want to debug it, you can fix the order by providing
# the seed, which is printed after each run.
# --seed 1234
config.order = :random
# Seed global randomization in this process using the `--seed` CLI option.
# Setting this allows you to use `--seed` to deterministically reproduce
# test failures related to randomization by passing the same `--seed` value
# as the one that triggered the failure.
Kernel.srand config.seed
=end
end
+53
View File
@@ -0,0 +1,53 @@
# frozen_string_literal: true
require 'rails_helper'
RSpec.configure do |config|
# Specify a root folder where Swagger JSON files are generated
# NOTE: If you're using the rswag-api to serve API descriptions, you'll need
# to ensure that it's configured to serve Swagger from the same folder
config.openapi_root = Rails.root.join('swagger').to_s
# Define one or more Swagger documents and provide global metadata for each one
# When you run the 'rswag:specs:swaggerize' rake task, the complete Swagger will
# be generated at the provided relative path under openapi_root
# By default, the operations defined in spec files are added to the first
# document below. You can override this behavior by adding a openapi_spec tag to the
# the root example_group in your specs, e.g. describe '...', openapi_spec: 'v2/swagger.json'
config.openapi_specs = {
'v1/swagger.yaml' => {
openapi: '3.0.1',
info: {
title: 'API V1',
version: 'v1'
},
paths: {},
components: {
securitySchemes: {
bearer_auth: {
type: :http,
scheme: :bearer,
bearerFormat: :JWT
}
}
},
security: [ { bearer_auth: [] } ],
servers: [
{
url: '{defaultHost}',
variables: {
defaultHost: {
default: 'http://localhost:3000'
}
}
}
]
}
}
# Specify the format of the output Swagger file when running 'rswag:specs:swaggerize'.
# The openapi_specs configuration option has the filename including format in
# the key, this may want to be changed to avoid putting yaml in json files.
# Defaults to json. Accepts ':json' and ':yaml'.
config.openapi_format = :yaml
end