diff --git a/apps/mcp/src/server/auth/index.test.ts b/apps/mcp/src/server/auth/index.test.ts index ee85bc64..d551a7e2 100644 --- a/apps/mcp/src/server/auth/index.test.ts +++ b/apps/mcp/src/server/auth/index.test.ts @@ -83,19 +83,16 @@ describe("MCP authentication", () => { }) it("rejects a token issued for a different audience", async () => { - const errorSpy = vi.spyOn(console, "error").mockImplementation(() => {}) - vi.spyOn(console, "debug").mockImplementation(() => {}) + vi.spyOn(console, "error").mockImplementation(() => {}) const token = await signToken({ audience: "https://api.example.com" }) await expect( validateOAuthToken(token, API_URL, MCP_RESOURCE, keySet), ).resolves.toBeNull() - expect(errorSpy).not.toHaveBeenCalled() }) it("rejects expired tokens and tokens without a subject", async () => { - const errorSpy = vi.spyOn(console, "error").mockImplementation(() => {}) - vi.spyOn(console, "debug").mockImplementation(() => {}) + vi.spyOn(console, "error").mockImplementation(() => {}) const expired = await signToken({ expiresIn: "-1s" }) const noSubject = await signToken({ subject: "" }) @@ -105,11 +102,10 @@ describe("MCP authentication", () => { await expect( validateOAuthToken(noSubject, API_URL, MCP_RESOURCE, keySet), ).resolves.toBeNull() - expect(errorSpy).not.toHaveBeenCalled() }) it("rejects opaque API keys without an API request", async () => { - vi.spyOn(console, "debug").mockImplementation(() => {}) + vi.spyOn(console, "error").mockImplementation(() => {}) const fetchSpy = vi.fn() vi.stubGlobal("fetch", fetchSpy) @@ -170,8 +166,7 @@ describe("MCP authentication", () => { }) it("rejects an API key the session endpoint refuses", async () => { - const errorSpy = vi.spyOn(console, "error").mockImplementation(() => {}) - vi.spyOn(console, "debug").mockImplementation(() => {}) + vi.spyOn(console, "error").mockImplementation(() => {}) vi.stubGlobal( "fetch", vi.fn().mockResolvedValue(new Response(null, { status: 401 })), @@ -180,7 +175,6 @@ describe("MCP authentication", () => { await expect( validateApiKey("sm_revoked_key_0123456789abcdef", API_URL), ).resolves.toBeNull() - expect(errorSpy).not.toHaveBeenCalled() }) it("rejects malformed API keys without an API request", async () => { @@ -193,7 +187,7 @@ describe("MCP authentication", () => { }) it("surfaces a 500 from the session endpoint as TransientAuthError, not invalid token", async () => { - const errorSpy = vi.spyOn(console, "error").mockImplementation(() => {}) + vi.spyOn(console, "error").mockImplementation(() => {}) vi.stubGlobal( "fetch", vi.fn().mockResolvedValue(new Response(null, { status: 500 })), @@ -202,14 +196,10 @@ describe("MCP authentication", () => { await expect( validateApiKey("sm_outage_key_0123456789abcdef", API_URL), ).rejects.toThrow(TransientAuthError) - expect(errorSpy).toHaveBeenCalledWith( - "Auth backend transient failure:", - expect.anything(), - ) }) it("surfaces a session-endpoint timeout as TransientAuthError", async () => { - const errorSpy = vi.spyOn(console, "error").mockImplementation(() => {}) + vi.spyOn(console, "error").mockImplementation(() => {}) vi.stubGlobal( "fetch", vi.fn().mockRejectedValue( @@ -222,9 +212,5 @@ describe("MCP authentication", () => { await expect( validateApiKey("sm_timeout_key_0123456789abcd", API_URL), ).rejects.toThrow(TransientAuthError) - expect(errorSpy).toHaveBeenCalledWith( - "Auth backend transient failure:", - expect.anything(), - ) }) })