LoginPage.test.tsx 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834
  1. /**
  2. * Tests for the LoginPage component.
  3. */
  4. import { describe, it, expect, beforeEach, afterEach, vi } from 'vitest';
  5. import { fireEvent, screen, waitFor } from '@testing-library/react';
  6. import userEvent from '@testing-library/user-event';
  7. import { render } from '../utils';
  8. import { LoginPage } from '../../pages/LoginPage';
  9. import { http, HttpResponse } from 'msw';
  10. import { server } from '../mocks/server';
  11. describe('LoginPage', () => {
  12. beforeEach(() => {
  13. server.use(
  14. http.get('/api/v1/auth/status', () => {
  15. return HttpResponse.json({ auth_enabled: true, requires_setup: false });
  16. })
  17. );
  18. });
  19. describe('rendering', () => {
  20. it('renders the login form', async () => {
  21. render(<LoginPage />);
  22. await waitFor(() => {
  23. expect(screen.getByRole('heading', { name: /Bambuddy Login/i })).toBeInTheDocument();
  24. });
  25. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  26. expect(screen.getByLabelText(/Password/i)).toBeInTheDocument();
  27. expect(screen.getByRole('button', { name: /Sign in/i })).toBeInTheDocument();
  28. });
  29. it('renders the sign in description', async () => {
  30. render(<LoginPage />);
  31. await waitFor(() => {
  32. expect(screen.getByText(/Sign in to your account/i)).toBeInTheDocument();
  33. });
  34. });
  35. });
  36. describe('form validation', () => {
  37. it('shows error when submitting empty form', async () => {
  38. const user = userEvent.setup();
  39. render(<LoginPage />);
  40. await waitFor(() => {
  41. expect(screen.getByRole('button', { name: /Sign in/i })).toBeInTheDocument();
  42. });
  43. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  44. // The form has required fields, so HTML5 validation should prevent submission
  45. // or the component shows a toast
  46. });
  47. it('allows entering username and password', async () => {
  48. const user = userEvent.setup();
  49. render(<LoginPage />);
  50. await waitFor(() => {
  51. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  52. });
  53. await user.type(screen.getByLabelText(/Username/i), 'testuser');
  54. await user.type(screen.getByLabelText(/Password/i), 'testpassword');
  55. expect(screen.getByLabelText(/Username/i)).toHaveValue('testuser');
  56. expect(screen.getByLabelText(/Password/i)).toHaveValue('testpassword');
  57. });
  58. });
  59. describe('login flow', () => {
  60. it('submits login request with credentials', async () => {
  61. const user = userEvent.setup();
  62. let loginCalled = false;
  63. server.use(
  64. http.post('/api/v1/auth/login', async ({ request }) => {
  65. loginCalled = true;
  66. const body = await request.json() as { username: string; password: string };
  67. if (body.username === 'validuser' && body.password === 'validpass') {
  68. return HttpResponse.json({
  69. access_token: 'test-token',
  70. token_type: 'bearer',
  71. user: {
  72. id: 1,
  73. username: 'validuser',
  74. role: 'admin',
  75. is_active: true,
  76. created_at: new Date().toISOString(),
  77. },
  78. });
  79. }
  80. return HttpResponse.json(
  81. { detail: 'Incorrect username or password' },
  82. { status: 401 }
  83. );
  84. })
  85. );
  86. render(<LoginPage />);
  87. await waitFor(() => {
  88. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  89. });
  90. await user.type(screen.getByLabelText(/Username/i), 'validuser');
  91. await user.type(screen.getByLabelText(/Password/i), 'validpass');
  92. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  93. // Verify the login endpoint was called
  94. await waitFor(() => {
  95. expect(loginCalled).toBe(true);
  96. });
  97. });
  98. it('shows loading state during login', async () => {
  99. const user = userEvent.setup();
  100. let resolveLogin: () => void;
  101. const loginPromise = new Promise<void>(resolve => { resolveLogin = resolve; });
  102. // Slow login endpoint that we control
  103. server.use(
  104. http.post('/api/v1/auth/login', async () => {
  105. await loginPromise;
  106. return HttpResponse.json({
  107. access_token: 'test-token',
  108. token_type: 'bearer',
  109. user: {
  110. id: 1,
  111. username: 'testuser',
  112. role: 'admin',
  113. is_active: true,
  114. created_at: new Date().toISOString(),
  115. },
  116. });
  117. })
  118. );
  119. render(<LoginPage />);
  120. await waitFor(() => {
  121. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  122. });
  123. await user.type(screen.getByLabelText(/Username/i), 'testuser');
  124. await user.type(screen.getByLabelText(/Password/i), 'testpass');
  125. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  126. // Check for loading state - button text should change to "Logging in..."
  127. await waitFor(() => {
  128. expect(screen.getByRole('button', { name: /Logging in/i })).toBeInTheDocument();
  129. });
  130. // Release the login request
  131. resolveLogin!();
  132. });
  133. });
  134. describe('2FA flow', () => {
  135. // Helper: login as a 2FA user and get to the 2FA step
  136. async function loginWith2FA(twoFAMethods = ['totp', 'backup']) {
  137. const user = userEvent.setup();
  138. server.use(
  139. http.post('/api/v1/auth/login', () =>
  140. HttpResponse.json({
  141. requires_2fa: true,
  142. pre_auth_token: 'test-pre-auth-token',
  143. two_fa_methods: twoFAMethods,
  144. })
  145. )
  146. );
  147. render(<LoginPage />);
  148. await waitFor(() => {
  149. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  150. });
  151. await user.type(screen.getByLabelText(/Username/i), 'mfa-user');
  152. await user.type(screen.getByLabelText(/Password/i), 'mfa-password');
  153. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  154. return user;
  155. }
  156. it('shows 2FA step when login returns requires_2fa', async () => {
  157. await loginWith2FA();
  158. await waitFor(() => {
  159. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  160. });
  161. });
  162. it('shows code input on the 2FA step', async () => {
  163. await loginWith2FA();
  164. await waitFor(() => {
  165. // The code input field is rendered
  166. expect(screen.getByRole('textbox', { name: /Verification Code/i })).toBeInTheDocument();
  167. });
  168. });
  169. it('submits 2FA verify request with code and pre_auth_token', async () => {
  170. let verifyCalled = false;
  171. let verifyBody: unknown;
  172. server.use(
  173. http.post('/api/v1/auth/2fa/verify', async ({ request }) => {
  174. verifyCalled = true;
  175. verifyBody = await request.json();
  176. return HttpResponse.json({
  177. access_token: 'final-jwt',
  178. token_type: 'bearer',
  179. user: {
  180. id: 1,
  181. username: 'mfa-user',
  182. role: 'admin',
  183. is_active: true,
  184. created_at: new Date().toISOString(),
  185. },
  186. });
  187. })
  188. );
  189. const user = await loginWith2FA();
  190. await waitFor(() => {
  191. expect(screen.getByRole('textbox', { name: /Verification Code/i })).toBeInTheDocument();
  192. });
  193. await user.type(screen.getByRole('textbox', { name: /Verification Code/i }), '123456');
  194. await user.click(screen.getByRole('button', { name: /Verify/i }));
  195. await waitFor(() => {
  196. expect(verifyCalled).toBe(true);
  197. });
  198. expect(verifyBody).toMatchObject({
  199. pre_auth_token: 'test-pre-auth-token',
  200. code: '123456',
  201. method: 'totp',
  202. });
  203. });
  204. it('returns to credentials step when back button is clicked', async () => {
  205. await loginWith2FA();
  206. await waitFor(() => {
  207. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  208. });
  209. const user = userEvent.setup();
  210. const backButton = screen.getByRole('button', { name: /Back to login/i });
  211. await user.click(backButton);
  212. await waitFor(() => {
  213. expect(screen.getByRole('heading', { name: /Bambuddy Login/i })).toBeInTheDocument();
  214. });
  215. });
  216. it('shows method selector when multiple 2FA methods are available', async () => {
  217. await loginWith2FA(['totp', 'email', 'backup']);
  218. await waitFor(() => {
  219. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  220. });
  221. // Multiple method buttons should be visible
  222. expect(screen.getByRole('button', { name: /Authenticator/i })).toBeInTheDocument();
  223. expect(screen.getByRole('button', { name: /Email/i })).toBeInTheDocument();
  224. expect(screen.getByRole('button', { name: /Backup/i })).toBeInTheDocument();
  225. });
  226. it('does not show method selector with only one 2FA method', async () => {
  227. await loginWith2FA(['totp']);
  228. await waitFor(() => {
  229. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  230. });
  231. // Single-method: no method selector buttons
  232. expect(screen.queryByRole('button', { name: /Authenticator/i })).not.toBeInTheDocument();
  233. });
  234. it('shows send code button when email method is selected', async () => {
  235. const _user = await loginWith2FA(['email']);
  236. await waitFor(() => {
  237. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  238. });
  239. // For email method the "Send code" button should be shown
  240. await waitFor(() => {
  241. expect(screen.getByRole('button', { name: /Send Code/i })).toBeInTheDocument();
  242. });
  243. });
  244. });
  245. describe('Remember Me', () => {
  246. const mockUser = {
  247. id: 1,
  248. username: 'testuser',
  249. role: 'admin' as const,
  250. is_active: true,
  251. created_at: new Date().toISOString(),
  252. };
  253. beforeEach(() => {
  254. vi.mocked(localStorage.setItem).mockClear();
  255. sessionStorage.clear();
  256. server.use(
  257. http.post('/api/v1/auth/login', () =>
  258. HttpResponse.json({
  259. access_token: 'test-token',
  260. token_type: 'bearer',
  261. user: mockUser,
  262. })
  263. ),
  264. // Prevent checkAuthStatus from clearing the token when getCurrentUser is called
  265. http.get('/api/v1/auth/me', () => HttpResponse.json(mockUser))
  266. );
  267. });
  268. it('renders Remember Me checkbox on credentials step', async () => {
  269. render(<LoginPage />);
  270. await waitFor(() => {
  271. expect(screen.getByLabelText(/Remember Me/i)).toBeInTheDocument();
  272. });
  273. expect(screen.getByRole('checkbox', { name: /Remember Me/i })).not.toBeChecked();
  274. });
  275. it('does not persist token to localStorage when unchecked (default)', async () => {
  276. const user = userEvent.setup();
  277. render(<LoginPage />);
  278. await waitFor(() => {
  279. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  280. });
  281. await user.type(screen.getByLabelText(/Username/i), 'testuser');
  282. await user.type(screen.getByLabelText(/Password/i), 'testpassword');
  283. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  284. // Token must be in sessionStorage (tab-only) but not in localStorage
  285. await waitFor(() => {
  286. expect(vi.mocked(localStorage.setItem)).not.toHaveBeenCalledWith('auth_token', expect.any(String));
  287. expect(sessionStorage.getItem('auth_token')).toBe('test-token');
  288. });
  289. });
  290. it('persists token to localStorage when Remember Me is checked', async () => {
  291. const user = userEvent.setup();
  292. render(<LoginPage />);
  293. await waitFor(() => {
  294. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  295. });
  296. await user.click(screen.getByRole('checkbox', { name: /Remember Me/i }));
  297. await user.type(screen.getByLabelText(/Username/i), 'testuser');
  298. await user.type(screen.getByLabelText(/Password/i), 'testpassword');
  299. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  300. await waitFor(() => {
  301. expect(vi.mocked(localStorage.setItem)).toHaveBeenCalledWith('auth_token', 'test-token');
  302. });
  303. });
  304. it('carries Remember Me through 2FA verification', async () => {
  305. server.use(
  306. http.post('/api/v1/auth/login', () =>
  307. HttpResponse.json({
  308. requires_2fa: true,
  309. pre_auth_token: 'pre-token',
  310. two_fa_methods: ['totp'],
  311. })
  312. ),
  313. http.post('/api/v1/auth/2fa/verify', () =>
  314. HttpResponse.json({
  315. access_token: 'final-token',
  316. token_type: 'bearer',
  317. user: mockUser,
  318. })
  319. )
  320. );
  321. const user = userEvent.setup();
  322. render(<LoginPage />);
  323. await waitFor(() => {
  324. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  325. });
  326. // Check Remember Me before submitting credentials
  327. await user.click(screen.getByRole('checkbox', { name: /Remember Me/i }));
  328. await user.type(screen.getByLabelText(/Username/i), 'testuser');
  329. await user.type(screen.getByLabelText(/Password/i), 'testpassword');
  330. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  331. // Now on 2FA step — enter code and verify
  332. await waitFor(() => {
  333. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  334. });
  335. await user.type(screen.getByRole('textbox', { name: /Verification Code/i }), '123456');
  336. await user.click(screen.getByRole('button', { name: /Verify/i }));
  337. // Token must be persisted to localStorage because Remember Me was checked
  338. await waitFor(() => {
  339. expect(vi.mocked(localStorage.setItem)).toHaveBeenCalledWith('auth_token', 'final-token');
  340. });
  341. });
  342. it('checkbox is not shown on 2FA step', async () => {
  343. server.use(
  344. http.post('/api/v1/auth/login', () =>
  345. HttpResponse.json({
  346. requires_2fa: true,
  347. pre_auth_token: 'pre-token',
  348. two_fa_methods: ['totp'],
  349. })
  350. )
  351. );
  352. const user = userEvent.setup();
  353. render(<LoginPage />);
  354. await waitFor(() => {
  355. expect(screen.getByLabelText(/Username/i)).toBeInTheDocument();
  356. });
  357. await user.type(screen.getByLabelText(/Username/i), 'testuser');
  358. await user.type(screen.getByLabelText(/Password/i), 'testpassword');
  359. await user.click(screen.getByRole('button', { name: /Sign in/i }));
  360. await waitFor(() => {
  361. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  362. });
  363. expect(screen.queryByLabelText(/Remember Me/i)).not.toBeInTheDocument();
  364. });
  365. });
  366. describe('OIDC with Remember Me', () => {
  367. const mockUser = {
  368. id: 1,
  369. username: 'oidcuser',
  370. role: 'admin' as const,
  371. is_active: true,
  372. created_at: new Date().toISOString(),
  373. };
  374. beforeEach(() => {
  375. vi.mocked(localStorage.setItem).mockClear();
  376. sessionStorage.clear();
  377. });
  378. afterEach(() => {
  379. window.location.hash = '';
  380. window.history.pushState({}, '', '/login');
  381. sessionStorage.clear();
  382. });
  383. it('persists token to localStorage after OIDC redirect when Remember Me was set', async () => {
  384. sessionStorage.setItem('auth_remember_me', '1');
  385. server.use(
  386. http.post('/api/v1/auth/oidc/exchange', () =>
  387. HttpResponse.json({
  388. access_token: 'oidc-token',
  389. token_type: 'bearer',
  390. user: mockUser,
  391. })
  392. )
  393. );
  394. window.location.hash = '#oidc_token=test-exchange-token';
  395. render(<LoginPage />);
  396. await waitFor(() => {
  397. expect(vi.mocked(localStorage.setItem)).toHaveBeenCalledWith('auth_token', 'oidc-token');
  398. });
  399. expect(sessionStorage.getItem('auth_remember_me')).toBeNull();
  400. });
  401. it('carries Remember Me through OIDC + 2FA flow', async () => {
  402. sessionStorage.setItem('auth_remember_me', '1');
  403. server.use(
  404. http.post('/api/v1/auth/oidc/exchange', () =>
  405. HttpResponse.json({
  406. requires_2fa: true,
  407. pre_auth_token: 'oidc-pre-token',
  408. two_fa_methods: ['totp'],
  409. })
  410. ),
  411. http.post('/api/v1/auth/2fa/verify', () =>
  412. HttpResponse.json({
  413. access_token: 'oidc-2fa-token',
  414. token_type: 'bearer',
  415. user: mockUser,
  416. })
  417. )
  418. );
  419. window.location.hash = '#oidc_token=test-exchange-token';
  420. const user = userEvent.setup();
  421. render(<LoginPage />);
  422. await waitFor(() => {
  423. expect(screen.getByRole('heading', { name: /Two-Factor Authentication/i })).toBeInTheDocument();
  424. });
  425. // Flag consumed on mount — no stale value for future flows
  426. expect(sessionStorage.getItem('auth_remember_me')).toBeNull();
  427. await user.type(screen.getByRole('textbox', { name: /Verification Code/i }), '123456');
  428. await user.click(screen.getByRole('button', { name: /Verify/i }));
  429. await waitFor(() => {
  430. expect(vi.mocked(localStorage.setItem)).toHaveBeenCalledWith('auth_token', 'oidc-2fa-token');
  431. });
  432. });
  433. it('cleans up auth_remember_me flag when OIDC returns an error', async () => {
  434. sessionStorage.setItem('auth_remember_me', '1');
  435. window.history.pushState({}, '', '/login?oidc_error=invalid_state');
  436. render(<LoginPage />);
  437. await waitFor(() => {
  438. expect(sessionStorage.getItem('auth_remember_me')).toBeNull();
  439. });
  440. });
  441. it('does not persist token to localStorage after OIDC redirect when Remember Me was not set', async () => {
  442. // No auth_remember_me flag set — token must stay session-only
  443. server.use(
  444. http.post('/api/v1/auth/oidc/exchange', () =>
  445. HttpResponse.json({
  446. access_token: 'oidc-session-token',
  447. token_type: 'bearer',
  448. user: mockUser,
  449. })
  450. )
  451. );
  452. window.location.hash = '#oidc_token=test-exchange-token';
  453. render(<LoginPage />);
  454. await waitFor(() => {
  455. expect(sessionStorage.getItem('auth_token')).toBe('oidc-session-token');
  456. });
  457. expect(vi.mocked(localStorage.setItem)).not.toHaveBeenCalledWith('auth_token', expect.any(String));
  458. });
  459. it('shows error toast when OIDC exchange returns unexpected response shape', async () => {
  460. sessionStorage.setItem('auth_remember_me', '1');
  461. server.use(
  462. // Response is missing both access_token and requires_2fa — hits the else branch
  463. http.post('/api/v1/auth/oidc/exchange', () =>
  464. HttpResponse.json({ token_type: 'bearer' })
  465. )
  466. );
  467. window.location.hash = '#oidc_token=test-exchange-token';
  468. render(<LoginPage />);
  469. await waitFor(() => {
  470. expect(screen.getByText(/Login.*failed|failed.*login/i)).toBeInTheDocument();
  471. });
  472. // Flag must still be cleaned up even on malformed response
  473. expect(sessionStorage.getItem('auth_remember_me')).toBeNull();
  474. });
  475. it('writes auth_remember_me flag to sessionStorage before OIDC provider redirect', async () => {
  476. server.use(
  477. http.get('/api/v1/auth/oidc/providers', () =>
  478. HttpResponse.json([
  479. {
  480. id: 42,
  481. name: 'FlagIdP',
  482. issuer_url: 'https://flag.test',
  483. client_id: 'c',
  484. is_enabled: true,
  485. icon_url: null,
  486. has_icon: false,
  487. email_claim: 'email',
  488. require_email_verified: true,
  489. auto_create_users: false,
  490. auto_link_existing_accounts: false,
  491. },
  492. ])
  493. ),
  494. http.get('/api/v1/auth/oidc/authorize/42', () =>
  495. HttpResponse.json({ auth_url: 'https://flag.test/authorize?state=abc' })
  496. )
  497. );
  498. const user = userEvent.setup();
  499. render(<LoginPage />);
  500. // Tick "Remember Me"
  501. await waitFor(() => {
  502. expect(screen.getByRole('checkbox', { name: /Remember Me/i })).toBeInTheDocument();
  503. });
  504. await user.click(screen.getByRole('checkbox', { name: /Remember Me/i }));
  505. // Wait for OIDC provider button to appear
  506. await waitFor(() => {
  507. expect(screen.getByRole('button', { name: /FlagIdP/i })).toBeInTheDocument();
  508. });
  509. // Stub window.location so the OIDC redirect doesn't actually navigate.
  510. // Keep href valid so relative fetch URLs resolve correctly.
  511. Object.defineProperty(window, 'location', {
  512. writable: true,
  513. value: { ...window.location, href: 'http://localhost:3000/' },
  514. });
  515. await user.click(screen.getByRole('button', { name: /FlagIdP/i }));
  516. await waitFor(() => {
  517. expect(sessionStorage.getItem('auth_remember_me')).toBe('1');
  518. });
  519. });
  520. });
  521. // #1333: icon proxy — login page renders <img src> from /icon endpoint
  522. // rather than the upstream icon_url, so the strict img-src CSP holds.
  523. describe('OIDC icon proxy (#1333)', () => {
  524. beforeEach(() => {
  525. server.use(
  526. http.get('/api/v1/auth/status', () =>
  527. HttpResponse.json({ auth_enabled: true, setup_required: false })
  528. ),
  529. );
  530. });
  531. it('renders provider icon via the proxy URL when has_icon is true', async () => {
  532. server.use(
  533. http.get('/api/v1/auth/oidc/providers', () =>
  534. HttpResponse.json([
  535. {
  536. id: 7,
  537. name: 'IconProv',
  538. issuer_url: 'https://idp.test',
  539. client_id: 'c',
  540. is_enabled: true,
  541. icon_url: 'https://idp.test/icon.png',
  542. email_claim: 'email',
  543. require_email_verified: true,
  544. auto_create_users: false,
  545. auto_link_existing_accounts: false,
  546. has_icon: true,
  547. },
  548. ])
  549. ),
  550. );
  551. render(<LoginPage />);
  552. const button = await screen.findByRole('button', { name: /IconProv/i });
  553. const img = button.querySelector('img');
  554. expect(img).not.toBeNull();
  555. // Same-origin path — never the upstream icon_url. This is the entire
  556. // point of the proxy: keep img-src strictly 'self' data: blob:.
  557. expect(img!.getAttribute('src')).toBe('/api/v1/auth/oidc/providers/7/icon');
  558. });
  559. it('renders shield fallback when has_icon is false', async () => {
  560. server.use(
  561. http.get('/api/v1/auth/oidc/providers', () =>
  562. HttpResponse.json([
  563. {
  564. id: 8,
  565. name: 'NoIconProv',
  566. issuer_url: 'https://idp.test',
  567. client_id: 'c',
  568. is_enabled: true,
  569. icon_url: null,
  570. email_claim: 'email',
  571. require_email_verified: true,
  572. auto_create_users: false,
  573. auto_link_existing_accounts: false,
  574. has_icon: false,
  575. },
  576. ])
  577. ),
  578. );
  579. render(<LoginPage />);
  580. const button = await screen.findByRole('button', { name: /NoIconProv/i });
  581. expect(button.querySelector('img')).toBeNull();
  582. });
  583. it('renders mixed has_icon providers without crash', async () => {
  584. // N12 — multiple providers on the login page with a mix of
  585. // has_icon=true / false. No React-keys-collision warning, both
  586. // branches render correctly side by side.
  587. server.use(
  588. http.get('/api/v1/auth/oidc/providers', () =>
  589. HttpResponse.json([
  590. {
  591. id: 10,
  592. name: 'WithIcon',
  593. issuer_url: 'https://idp.test',
  594. client_id: 'c1',
  595. is_enabled: true,
  596. icon_url: 'https://idp.test/icon.png',
  597. has_icon: true,
  598. email_claim: 'email',
  599. require_email_verified: true,
  600. auto_create_users: false,
  601. auto_link_existing_accounts: false,
  602. },
  603. {
  604. id: 11,
  605. name: 'NoIcon',
  606. issuer_url: 'https://idp.test',
  607. client_id: 'c2',
  608. is_enabled: true,
  609. icon_url: null,
  610. has_icon: false,
  611. email_claim: 'email',
  612. require_email_verified: true,
  613. auto_create_users: false,
  614. auto_link_existing_accounts: false,
  615. },
  616. ])
  617. ),
  618. );
  619. render(<LoginPage />);
  620. const withIconBtn = await screen.findByRole('button', { name: /WithIcon/i });
  621. const noIconBtn = await screen.findByRole('button', { name: /NoIcon/i });
  622. expect(withIconBtn.querySelector('img')).not.toBeNull();
  623. expect(noIconBtn.querySelector('img')).toBeNull();
  624. });
  625. it('swaps in shield fallback when the icon fails to load', async () => {
  626. // I3 (#1333 review): the LoginPage must not show the browser
  627. // broken-image glyph to anonymous users. onError must fall back to
  628. // the Shield icon.
  629. server.use(
  630. http.get('/api/v1/auth/oidc/providers', () =>
  631. HttpResponse.json([
  632. {
  633. id: 9,
  634. name: 'FlakyIcon',
  635. issuer_url: 'https://idp.test',
  636. client_id: 'c',
  637. is_enabled: true,
  638. icon_url: 'https://idp.test/icon.png',
  639. email_claim: 'email',
  640. require_email_verified: true,
  641. auto_create_users: false,
  642. auto_link_existing_accounts: false,
  643. has_icon: true,
  644. },
  645. ])
  646. ),
  647. );
  648. render(<LoginPage />);
  649. const img = (await screen.findByRole('button', { name: /FlakyIcon/i })).querySelector('img');
  650. expect(img).not.toBeNull();
  651. // Fire the image's onError — jsdom doesn't fetch network resources
  652. // so we simulate the failure directly.
  653. fireEvent.error(img!);
  654. // After error, no more <img> in the button; Shield fallback rendered.
  655. await waitFor(() => {
  656. const button = screen.getByRole('button', { name: /FlakyIcon/i });
  657. expect(button.querySelector('img')).toBeNull();
  658. });
  659. });
  660. it('keeps each provider button\'s iconFailed state independent', async () => {
  661. // The OIDCProviderButton sub-component exists specifically so each
  662. // provider owns its own iconFailed state. If a future refactor hoists
  663. // useState into the parent loop, an error on provider A would also
  664. // hide provider B's icon — exactly the regression this test catches.
  665. server.use(
  666. http.get('/api/v1/auth/oidc/providers', () =>
  667. HttpResponse.json([
  668. {
  669. id: 21,
  670. name: 'AlphaIdP',
  671. issuer_url: 'https://a.test',
  672. client_id: 'a',
  673. is_enabled: true,
  674. icon_url: 'https://a.test/icon.png',
  675. email_claim: 'email',
  676. require_email_verified: true,
  677. auto_create_users: false,
  678. auto_link_existing_accounts: false,
  679. has_icon: true,
  680. },
  681. {
  682. id: 22,
  683. name: 'BetaIdP',
  684. issuer_url: 'https://b.test',
  685. client_id: 'b',
  686. is_enabled: true,
  687. icon_url: 'https://b.test/icon.png',
  688. email_claim: 'email',
  689. require_email_verified: true,
  690. auto_create_users: false,
  691. auto_link_existing_accounts: false,
  692. has_icon: true,
  693. },
  694. ])
  695. ),
  696. );
  697. render(<LoginPage />);
  698. const alphaImg = (await screen.findByRole('button', { name: /AlphaIdP/i })).querySelector('img');
  699. const betaImg = (await screen.findByRole('button', { name: /BetaIdP/i })).querySelector('img');
  700. expect(alphaImg).not.toBeNull();
  701. expect(betaImg).not.toBeNull();
  702. fireEvent.error(alphaImg!);
  703. // Alpha's icon swaps to the Shield fallback…
  704. await waitFor(() => {
  705. expect(screen.getByRole('button', { name: /AlphaIdP/i }).querySelector('img')).toBeNull();
  706. });
  707. // …but Beta's icon stays put. If state leaks to the parent, this fails.
  708. expect(screen.getByRole('button', { name: /BetaIdP/i }).querySelector('img')).not.toBeNull();
  709. });
  710. });
  711. });