[PR #22268] test: add comprehensive unit tests for PassportService with exception handling optimization #29882

Closed
opened 2026-02-21 20:46:25 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/22268

State: closed
Merged: Yes


Description:

Add comprehensive unit tests for libs.passport module with exception handling improvements discovered during testing.

Core Functionality Tests

  • JWT token issuance and verification lifecycle
  • Support for various payload types (strings, numbers, nested objects, Unicode)
  • Token integrity validation and tampering detection
  • Secret key isolation between service instances

Security Tests

  • Token signature validation with different secret keys
  • Algorithm mismatch detection (HS256 enforcement)
  • Expired token handling
  • Invalid token format rejection

Exception Handling Optimization

  • Reordered exception catching to handle ExpiredSignatureError first
  • Added PyJWTError as catch-all for unhandled JWT exceptions
  • Updated tests to reflect new exception handling behavior
  • Ensures all JWT-related errors are properly converted to Unauthorized

Edge Cases

  • Empty and None secret key handling
  • Large payload support
  • Special characters in payload
  • Malformed token formats

This PR closes the discussion in issue #22264 regarding exception handling order optimization in PassportService.

The extensive test coverage is intentional due to the security-sensitive nature of this module.

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/22268 **State:** closed **Merged:** Yes --- ## Description: ### Add comprehensive unit tests for libs.passport module with exception handling improvements discovered during testing. ### Core Functionality Tests - JWT token issuance and verification lifecycle - Support for various payload types (strings, numbers, nested objects, Unicode) - Token integrity validation and tampering detection - Secret key isolation between service instances ### Security Tests - Token signature validation with different secret keys - Algorithm mismatch detection (HS256 enforcement) - Expired token handling - Invalid token format rejection ### Exception Handling Optimization - Reordered exception catching to handle ExpiredSignatureError first - Added PyJWTError as catch-all for unhandled JWT exceptions - Updated tests to reflect new exception handling behavior - Ensures all JWT-related errors are properly converted to Unauthorized ### Edge Cases - Empty and None secret key handling - Large payload support - Special characters in payload - Malformed token formats ### This PR closes the discussion in issue #22264 regarding exception handling order optimization in PassportService. ### The extensive test coverage is intentional due to the security-sensitive nature of this module. ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:46:25 -05:00
yindo closed this issue 2026-02-21 20:46:26 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#29882