Build a valid current TOTP code for a base32 secret using the same construction the service uses, so the service must accept it.
(secret_base32: &str)
| 1370 | updated_at: Set(now), |
| 1371 | } |
| 1372 | .insert(&db) |
| 1373 | .await |
| 1374 | .unwrap(); |
| 1375 | |
| 1376 | // Token whose 8-char prefix matches the row's `token_prefix`. |
| 1377 | let result = AuthService::validate_agent_token(&db, "testtest-not-a-real-token") |
| 1378 | .await |
| 1379 | .unwrap(); |
| 1380 | assert!( |
| 1381 | result.is_none(), |
| 1382 | "row with non-NULL prefix but NULL token_hash must not validate" |
| 1383 | ); |
| 1384 | } |
| 1385 | |
| 1386 | #[tokio::test] |
| 1387 | async fn test_init_admin_noop_when_users_exist() { |
| 1388 | let (db, _tmp) = setup_test_db().await; |
| 1389 | AuthService::create_user(&db, "someone", "pass1234", "admin") |
| 1390 | .await |
| 1391 | .expect("seed a user"); |
no outgoing calls