← tests

authorized

The framework's own authorization mechanism, with the crypto left out.

Comparable across every framework. The token differs from the accepted one by its last character, so the denial arm walks the same string and measures the plumbing rather than a length check.

testheftrequestbasewhat differs from the base
authorized.allowed1GET /authorized/smalljson.smalla bearer token the framework has to check
authorized.denied2GET /authorized/smallauthorized.allowedthe request refused rather than served

authorized.allowed

heft 1

base json.smallbase of authorized.denied

A bearer token the framework's own authorization mechanism has to check before the handler runs. Read against json.small, the difference is the check and the plumbing that carries it, not the crypto, which this family leaves out.

Request

GET /authorized/small
authorizationBearer 5a7cc77ed0dcb825806b6f872026c317

No body.

Expected response

HTTP 200

payload items.small

{"size":"small","count":1,"items":[{"id":1,"name":"slate-lamp-6647","category":"tools","priceCents":18928,"inStock":true}]}

Compared as parsed JSON, so key order and how a number is written do not matter.

Test source, tests/authorized/allowed.ts
tests/authorized/allowed.tsopen on GitHub →
import { performanceTest } from "#kit";
import { TOKEN } from "#models/configuration";
import { items } from "#payloads";

const path = "/authorized/small";

export default performanceTest({
  id: { family: "authorized", name: "allowed" },
  path,
  base: "json.small",
  varies: "authorization",
  heft: 1,
  about:
    "A bearer token the framework's own authorization mechanism has to check " +
    "before the handler runs. Read against json.small, the difference is the " +
    "check and the plumbing that carries it, not the crypto, which this " +
    "family leaves out.",

  request: (c) => c.get(path).header("authorization", `Bearer ${TOKEN}`).okWith(items.small),
});

authorized.denied

heft 2

base authorized.allowed

The same endpoint refusing. The token differs from the accepted one by its last character, so the comparison walks the whole string and this row measures the refusal path rather than a length check.

Request

GET /authorized/small
authorizationBearer 5a7cc77ed0dcb825806b6f872026c310

No body.

Expected response

HTTP 403

The body is not checked.

Test source, tests/authorized/denied.ts
tests/authorized/denied.tsopen on GitHub →
import { performanceTest } from "#kit";
import { TOKEN } from "#models/configuration";

const path = "/authorized/small";

/** The token with its last character changed, so a refusal compares the whole string. */
const wrong = `${TOKEN.slice(0, -1)}0`;

export default performanceTest({
  id: { family: "authorized", name: "denied" },
  path,
  base: "authorized.allowed",
  varies: "outcome",
  heft: 2,
  about:
    "The same endpoint refusing. The token differs from the accepted one by " +
    "its last character, so the comparison walks the whole string and this " +
    "row measures the refusal path rather than a length check.",

  request: (c) => c.get(path).header("authorization", `Bearer ${wrong}`).status(403),
});