Documentation
¶
Overview ¶
Package authtest mints a credential a test can present.
Identity here is a VERIFIED token and nothing else. GetSessionClaims parses and validates; there is no field to write a principal into and no store to seed. That is the property worth keeping — it is what stopped this service minting its own admins out of an MD5 and a memory map — so a test that needs an authenticated caller has to present a real credential rather than fabricate the answer.
So this signs one. It installs a certificate the verifier will trust and signs against the matching key, and the code under test then authenticates exactly the way it does in production: the same parse, the same signature check, the same issuer policy. Nothing is bypassed and no seam is added to reach around.
A test that fabricates an identity is not testing authorisation — it is testing an entry point of its own. This is the entry point everyone else uses.
The key is generated once per process and never leaves it, so a token minted here is worth nothing anywhere else. It lives under internal/ and only tests import it.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Signing ¶
func Signing(t testing.TB) *rsa.PrivateKey
Signing is the key the verifier trusts, for a test that has to mint a credential this package's own happy path cannot: another brand's issuer, a window that has already closed, an algorithm nobody agreed to. Those claim sets are each a different attack and belong at the test that names them — what must not be duplicated is the INSTALL, because two installers race over one global and the loser signs against a certificate that is no longer there.
Types ¶
This section is empty.