The framework's own authorization mechanism, with the crypto left out.
Comparable across every framework. The token differs from the accepted one by its last character, so the denial arm walks the same string and measures the plumbing rather than a length check.
| test | heft | request | base | what differs from the base |
|---|---|---|---|---|
| authorized.allowed | 1 | GET /authorized/small | json.small | a bearer token the framework has to check |
| authorized.denied | 2 | GET /authorized/small | authorized.allowed | the request refused rather than served |
A bearer token the framework's own authorization mechanism has to check before the handler runs. Read against json.small, the difference is the check and the plumbing that carries it, not the crypto, which this family leaves out.
GET /authorized/small
No body.
HTTP 200
payload items.small
{"size":"small","count":1,"items":[{"id":1,"name":"slate-lamp-6647","category":"tools","priceCents":18928,"inStock":true}]}Compared as parsed JSON, so key order and how a number is written do not matter.
import { performanceTest } from "#kit";
import { TOKEN } from "#models/configuration";
import { items } from "#payloads";
const path = "/authorized/small";
export default performanceTest({
id: { family: "authorized", name: "allowed" },
path,
base: "json.small",
varies: "authorization",
heft: 1,
about:
"A bearer token the framework's own authorization mechanism has to check " +
"before the handler runs. Read against json.small, the difference is the " +
"check and the plumbing that carries it, not the crypto, which this " +
"family leaves out.",
request: (c) => c.get(path).header("authorization", `Bearer ${TOKEN}`).okWith(items.small),
});
The same endpoint refusing. The token differs from the accepted one by its last character, so the comparison walks the whole string and this row measures the refusal path rather than a length check.
GET /authorized/small
No body.
HTTP 403
The body is not checked.
import { performanceTest } from "#kit";
import { TOKEN } from "#models/configuration";
const path = "/authorized/small";
/** The token with its last character changed, so a refusal compares the whole string. */
const wrong = `${TOKEN.slice(0, -1)}0`;
export default performanceTest({
id: { family: "authorized", name: "denied" },
path,
base: "authorized.allowed",
varies: "outcome",
heft: 2,
about:
"The same endpoint refusing. The token differs from the accepted one by " +
"its last character, so the comparison walks the whole string and this " +
"row measures the refusal path rather than a length check.",
request: (c) => c.get(path).header("authorization", `Bearer ${wrong}`).status(403),
});