fix(tests): 明确配置 LDAP mock 默认行为并添加 LDAP 回退测试

问题分析:
- 原有测试未显式设置 ldapProperties.isEnabled() 的返回值
- 虽然 Mockito 默认返回 false,但为了测试稳定性应显式配置
- 缺少对 LDAP 回退功能的测试覆盖

修复内容:
1. 在 setUp() 中显式设置 ldapProperties.isEnabled() 返回 false
   - 确保所有原有测试不受 LDAP 功能影响
   - 提高测试的可读性和维护性

2. 添加三个新的测试用例:
   - login_withUnknownUsername_fallsBackToLdap_whenEnabled
     验证 LDAP 启用时,本地用户不存在会回退到 LDAP 认证
   - login_withUnknownUsername_fails_whenLdapAuthenticationFails
     验证 LDAP 认证失败时正确抛出异常
   - login_withUnknownUsername_fails_whenLdapDisabled
     验证 LDAP 禁用时不会调用 LDAP 服务

这些修改确保了:
- 原有测试的稳定性和可预测性
- LDAP 回退功能的正确性
- 测试覆盖的完整性

Refs: https://github.com/iflytek/skillhub/pull/283
Signed-off-by: jangrui <admin@jangrui.com>
This commit is contained in:
jangrui 2026-05-14 21:08:24 +08:00
parent 0b4714f735
commit 48c15ca30c

View file

@ -63,6 +63,9 @@ class LocalAuthServiceTest {
@BeforeEach
void setUp() {
// 默认禁用 LDAP,确保原有测试不受影响
given(ldapProperties.isEnabled()).willReturn(false);
service = new LocalAuthService(
credentialRepository,
userAccountRepository,
@ -257,4 +260,65 @@ class LocalAuthServiceTest {
.isInstanceOf(AuthFlowException.class)
.hasMessageContaining("validation.auth.local.email.notBlank");
}
@Test
void login_withUnknownUsername_fallsBackToLdap_whenEnabled() {
// Given
given(credentialRepository.findByUsernameIgnoreCase("ldapuser")).willReturn(Optional.empty());
given(ldapProperties.isEnabled()).willReturn(true);
UserAccount ldapUser = new UserAccount("usr_ldap", "ldapuser", "ldapuser@example.com", null);
ldapUser.setStatus(UserStatus.ACTIVE);
PlatformPrincipal ldapPrincipal = new PlatformPrincipal(
"usr_ldap",
"ldapuser",
"ldapuser@example.com",
null,
"ldap",
Set.of("USER")
);
given(ldapAuthService.login("ldapuser", "LdapPassword123!")).willReturn(ldapPrincipal);
// When
var principal = service.login("ldapuser", "LdapPassword123!");
// Then
assertThat(principal.userId()).isEqualTo("usr_ldap");
assertThat(principal.displayName()).isEqualTo("ldapuser");
assertThat(principal.email()).isEqualTo("ldapuser@example.com");
verify(ldapAuthService).login("ldapuser", "LdapPassword123!");
}
@Test
void login_withUnknownUsername_fails_whenLdapAuthenticationFails() {
// Given
given(credentialRepository.findByUsernameIgnoreCase("ldapuser")).willReturn(Optional.empty());
given(ldapProperties.isEnabled()).willReturn(true);
given(ldapAuthService.login("ldapuser", "WrongPassword"))
.willThrow(new AuthFlowException(HttpStatus.UNAUTHORIZED, "LDAP authentication failed"));
// When & Then
assertThatThrownBy(() -> service.login("ldapuser", "WrongPassword"))
.isInstanceOf(AuthFlowException.class)
.extracting("status")
.isEqualTo(HttpStatus.UNAUTHORIZED);
verify(ldapAuthService).login("ldapuser", "WrongPassword");
}
@Test
void login_withUnknownUsername_fails_whenLdapDisabled() {
// Given
given(credentialRepository.findByUsernameIgnoreCase("localuser")).willReturn(Optional.empty());
given(ldapProperties.isEnabled()).willReturn(false);
// When & Then
assertThatThrownBy(() -> service.login("localuser", "password"))
.isInstanceOf(AuthFlowException.class)
.extracting("status")
.isEqualTo(HttpStatus.UNAUTHORIZED);
verify(ldapAuthService, never()).login(any(), any());
}