import { describe, it, expect } from 'vitest'; import { hashPassword, verifyPassword, generateSessionToken, hashSessionToken } from '$lib/server/auth-utils'; describe('auth-utils', () => { it('hashes and verifies a password', async () => { const hash = await hashPassword('testpassword'); expect(hash).not.toBe('testpassword'); expect(await verifyPassword(hash, 'testpassword')).toBe(true); expect(await verifyPassword(hash, 'wrongpassword')).toBe(false); }); it('generates unique session tokens', () => { const token1 = generateSessionToken(); const token2 = generateSessionToken(); expect(token1).toHaveLength(64); expect(token2).toHaveLength(64); expect(token1).not.toBe(token2); }); it('hashes session tokens deterministically', () => { const token = generateSessionToken(); const hash1 = hashSessionToken(token); const hash2 = hashSessionToken(token); expect(hash1).toBe(hash2); expect(hash1).not.toBe(token); }); });