You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Quarkus接口添加认证后测试不通过,如何处理授权部分?

接口加认证后测试用例的修复方案

给你几个可行的修复方向,结合你的测试代码逐一说明:

1. Mock认证组件,跳过真实认证逻辑

如果你的认证是通过自定义服务或者Spring Security核心组件实现的,直接在测试里Mock这些组件,让认证逻辑直接返回“通过”状态,不用走真实校验流程。

修改后的测试代码示例:

// 假设用的是Spring Security,Mock AuthenticationManager或自定义AuthService
@MockBean
private AuthenticationManager authenticationManager;

@Test
public void testInvalidLimitExceptionMapping() {
    String errorMessage = "Invalid offset or limit values.";
    String json = mapErrorToJson(errorMessage);

    // Mock认证通过逻辑
    Mockito.when(authenticationManager.authenticate(any(Authentication.class)))
            .thenReturn(new UsernamePasswordAuthenticationToken("testUser", null, Collections.emptyList()));

    Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString()))
            .thenThrow(new InvalidParameterException(errorMessage));

    given()
            .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03")
            .then()
            .statusCode(400)
            .body(is(json));
}

2. 在请求中携带合法的测试用认证凭证

如果不想Mock组件,直接给请求加符合要求的认证头,比如JWT Token或Basic Auth信息:

情况1:JWT认证

@Test
public void testInvalidLimitExceptionMapping() {
    String errorMessage = "Invalid offset or limit values.";
    String json = mapErrorToJson(errorMessage);

    Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString()))
            .thenThrow(new InvalidParameterException(errorMessage));

    // 使用预先生成的测试用合法JWT Token
    String testToken = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...";

    given()
            .header("Authorization", "Bearer " + testToken) // 添加认证头
            .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03")
            .then()
            .statusCode(400)
            .body(is(json));
}

情况2:Basic认证

@Test
public void testInvalidLimitExceptionMapping() {
    String errorMessage = "Invalid offset or limit values.";
    String json = mapErrorToJson(errorMessage);

    Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString()))
            .thenThrow(new InvalidParameterException(errorMessage));

    given()
            .auth().preemptive().basic("testUsername", "testPassword") // 添加Basic认证
            .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03")
            .then()
            .statusCode(400)
            .body(is(json));
}

3. 测试环境临时绕过该接口的认证

如果是Spring项目,可以用测试注解或临时配置,让测试时的这个接口不需要认证:

方法A:用@WithMockUser注解

// 在测试方法或类上添加注解,模拟已登录用户
@WithMockUser(username = "testUser", roles = {"USER"})
@Test
public void testInvalidLimitExceptionMapping() {
    String errorMessage = "Invalid offset or limit values.";
    String json = mapErrorToJson(errorMessage);

    Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString()))
            .thenThrow(new InvalidParameterException(errorMessage));

    given()
            .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03")
            .then()
            .statusCode(400)
            .body(is(json));
}

方法B:临时修改Security配置

在测试类里添加测试专用的SecurityFilterChain,让/v1/orders接口跳过认证:

@Configuration
public class TestSecurityConfig {
    @Bean
    public SecurityFilterChain testSecurityFilterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers("/v1/orders").permitAll() // 允许该接口无需认证
                .anyRequest().authenticated()
        );
        return http.build();
    }
}

然后在测试类上引入这个配置:

@Import(TestSecurityConfig.class)
public class OrderControllerTest {
    // 你的测试代码...
}

内容的提问来源于stack exchange,提问作者grigor martirosyan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 05:55:07