From 48c15ca30cae3e17c8290d4060dd7d52609bc4b1 Mon Sep 17 00:00:00 2001 From: jangrui Date: Thu, 14 May 2026 21:08:24 +0800 Subject: [PATCH] =?UTF-8?q?fix(tests):=20=E6=98=8E=E7=A1=AE=E9=85=8D?= =?UTF-8?q?=E7=BD=AE=20LDAP=20mock=20=E9=BB=98=E8=AE=A4=E8=A1=8C=E4=B8=BA?= =?UTF-8?q?=E5=B9=B6=E6=B7=BB=E5=8A=A0=20LDAP=20=E5=9B=9E=E9=80=80?= =?UTF-8?q?=E6=B5=8B=E8=AF=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 问题分析: - 原有测试未显式设置 ldapProperties.isEnabled() 的返回值 - 虽然 Mockito 默认返回 false,但为了测试稳定性应显式配置 - 缺少对 LDAP 回退功能的测试覆盖 修复内容: 1. 在 setUp() 中显式设置 ldapProperties.isEnabled() 返回 false - 确保所有原有测试不受 LDAP 功能影响 - 提高测试的可读性和维护性 2. 添加三个新的测试用例: - login_withUnknownUsername_fallsBackToLdap_whenEnabled 验证 LDAP 启用时,本地用户不存在会回退到 LDAP 认证 - login_withUnknownUsername_fails_whenLdapAuthenticationFails 验证 LDAP 认证失败时正确抛出异常 - login_withUnknownUsername_fails_whenLdapDisabled 验证 LDAP 禁用时不会调用 LDAP 服务 这些修改确保了: - 原有测试的稳定性和可预测性 - LDAP 回退功能的正确性 - 测试覆盖的完整性 Refs: https://github.com/iflytek/skillhub/pull/283 Signed-off-by: jangrui --- .../auth/local/LocalAuthServiceTest.java | 64 +++++++++++++++++++ 1 file changed, 64 insertions(+) diff --git a/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java b/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java index 444727f9..9c02485d 100644 --- a/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java +++ b/server/skillhub-auth/src/test/java/com/iflytek/skillhub/auth/local/LocalAuthServiceTest.java @@ -63,6 +63,9 @@ class LocalAuthServiceTest { @BeforeEach void setUp() { + // 默认禁用 LDAP,确保原有测试不受影响 + given(ldapProperties.isEnabled()).willReturn(false); + service = new LocalAuthService( credentialRepository, userAccountRepository, @@ -257,4 +260,65 @@ class LocalAuthServiceTest { .isInstanceOf(AuthFlowException.class) .hasMessageContaining("validation.auth.local.email.notBlank"); } + + @Test + void login_withUnknownUsername_fallsBackToLdap_whenEnabled() { + // Given + given(credentialRepository.findByUsernameIgnoreCase("ldapuser")).willReturn(Optional.empty()); + given(ldapProperties.isEnabled()).willReturn(true); + + UserAccount ldapUser = new UserAccount("usr_ldap", "ldapuser", "ldapuser@example.com", null); + ldapUser.setStatus(UserStatus.ACTIVE); + PlatformPrincipal ldapPrincipal = new PlatformPrincipal( + "usr_ldap", + "ldapuser", + "ldapuser@example.com", + null, + "ldap", + Set.of("USER") + ); + + given(ldapAuthService.login("ldapuser", "LdapPassword123!")).willReturn(ldapPrincipal); + + // When + var principal = service.login("ldapuser", "LdapPassword123!"); + + // Then + assertThat(principal.userId()).isEqualTo("usr_ldap"); + assertThat(principal.displayName()).isEqualTo("ldapuser"); + assertThat(principal.email()).isEqualTo("ldapuser@example.com"); + verify(ldapAuthService).login("ldapuser", "LdapPassword123!"); + } + + @Test + void login_withUnknownUsername_fails_whenLdapAuthenticationFails() { + // Given + given(credentialRepository.findByUsernameIgnoreCase("ldapuser")).willReturn(Optional.empty()); + given(ldapProperties.isEnabled()).willReturn(true); + + given(ldapAuthService.login("ldapuser", "WrongPassword")) + .willThrow(new AuthFlowException(HttpStatus.UNAUTHORIZED, "LDAP authentication failed")); + + // When & Then + assertThatThrownBy(() -> service.login("ldapuser", "WrongPassword")) + .isInstanceOf(AuthFlowException.class) + .extracting("status") + .isEqualTo(HttpStatus.UNAUTHORIZED); + + verify(ldapAuthService).login("ldapuser", "WrongPassword"); + } + + @Test + void login_withUnknownUsername_fails_whenLdapDisabled() { + // Given + given(credentialRepository.findByUsernameIgnoreCase("localuser")).willReturn(Optional.empty()); + given(ldapProperties.isEnabled()).willReturn(false); + + // When & Then + assertThatThrownBy(() -> service.login("localuser", "password")) + .isInstanceOf(AuthFlowException.class) + .extracting("status") + .isEqualTo(HttpStatus.UNAUTHORIZED); + + verify(ldapAuthService, never()).login(any(), any()); }