feat: add admin-controlled authentication debug mode
This commit is contained in:
@@ -246,8 +246,36 @@ function test_invalid_authentication(): void
|
||||
!header_contains($response['headers'], 'Set-Cookie: wordpress_logged_in_'),
|
||||
'Invalid authentication request issued a logged-in cookie.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], 'JWT signature is invalid.') === false,
|
||||
'Debug details were exposed while debug mode was disabled.'
|
||||
);
|
||||
|
||||
pass('Invalid JWT is rejected without login cookies');
|
||||
pass('Invalid JWT is rejected without login cookies or debug details');
|
||||
}
|
||||
|
||||
function test_debug_error_details(): void
|
||||
{
|
||||
update_option('mahak_debug_mode', 1);
|
||||
|
||||
$response = http_request(TEST_SITE_URL.'/mahak/login/?token=not-a-jwt');
|
||||
|
||||
assert_true($response['status'] === 500, 'Debug error response should return HTTP 500.');
|
||||
assert_true(
|
||||
strpos($response['body'], 'JWT must contain header, payload, and signature.') !== false,
|
||||
'Debug response did not contain the underlying exception message.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], 'UnexpectedValueException') !== false,
|
||||
'Debug response did not contain the exception class.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], 'Stack trace') !== false,
|
||||
'Debug response did not contain a stack trace.'
|
||||
);
|
||||
|
||||
update_option('mahak_debug_mode', 0);
|
||||
pass('Debug mode displays full exception details and stack trace');
|
||||
}
|
||||
|
||||
boot_wordpress();
|
||||
@@ -256,5 +284,6 @@ activate_and_configure_plugin();
|
||||
wait_for_http();
|
||||
test_valid_authentication();
|
||||
test_invalid_authentication();
|
||||
test_debug_error_details();
|
||||
|
||||
echo "[OK] Authentication integration test passed\n";
|
||||
|
||||
Reference in New Issue
Block a user