Cover the OIDC loopback callback paths with real-socket tests #260
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/oidc-loopback-coverage"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
#258 made the loopback wait cancellable, but its one test never connects to the listener: it binds, cancels after 50ms and asserts on shutdown latency. The state comparison, the request-line bound and the accept loop were all unexercised, so a regression in any of them would have gone green.
What changed
statereturns the code, a mismatchedstateaborts as CSRF without echoing the code or the presented state, and a silent socket is dropped atREQUEST_LINE_TIMEOUTso the redirect queued behind it still lands.tokio::time::Instant, sincestd's ignores the virtual clock.REQUEST_LINE_TIMEOUTis untouched: lowering it to suit a test would weaken the thing under test.Testing
cargo test,cargo fmt --all -- --checkandcargo clippy --locked --all-targetsclean; each new test was also run against a mutant of the property it names (state comparison deleted, request-line bound removed) and only that test failed.Closes #259
Midwork-Id: lane=claude-8 repo=rasterstate/fj clone=fj-259 branch=fix/oidc-loopback-coverage head=6903f3b4bc253c9049651f9dec531d414a81c992 minted=2026-09-06T16:12:13Z