Supertest · JWT Authentication และ Request State
Bearer Token Request
ส่ง JWT ด้วย `.auth()` หรือ Authorization header
ส่ง JWT เป็น Bearer token
Protected route ต้องได้รับ credential ใน `Authorization` header รูปแบบมาตรฐานคือ `Bearer <token>` Supertest มี `.auth(token, { type: 'bearer' })` เป็น shorthand หรือจะตั้ง header เองเพื่อให้เห็น wire format ก็ได้
ใช้ .auth() แบบ bearerTS
เขียน Authorization header ตรง ๆTS
ใช้รูปแบบนี้เมื่อต้องการสอนหรือ debug header ที่ส่งจริง
assert identity ผ่าน behavior
อย่าหยุดที่ status 200 ถ้า protected endpoint ควรคืนเฉพาะ Todo ของ user ที่ login ให้ตรวจ owner หรือรายการที่สร้างจาก fixture เพื่อพิสูจน์ว่า token ถูกนำไปใช้จริง
i
token ถูกต้องแต่ resource อาจไม่ถูกต้อง
authentication บอกว่า request เป็นใคร ส่วน authorization และ ownership บอกว่าทำอะไรได้บ้าง ต้องมี test แยกคำถามเหล่านี้