From bffc0c1a4df21ae5e2863fb663f46aa55ce52c45 Mon Sep 17 00:00:00 2001 From: Konrad Neitzel Date: Mon, 28 Sep 2026 18:05:44 +0200 Subject: [PATCH] Assert the gRPC user token includes the username. The interceptor already copies preferred_username; the test now checks it. Co-authored-by: Cursor --- grpc_test.go | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/grpc_test.go b/grpc_test.go index 6c2de19..9d2df10 100644 --- a/grpc_test.go +++ b/grpc_test.go @@ -21,7 +21,7 @@ func TestUnaryInterceptorForwardsBearer(t *testing.T) { t.Fatalf("Mint: %v", err) } - var gotSubject string + var gotSubject, gotUsername string var gotGroups []string var gotRaw string interceptor := auth.UnaryServerInterceptor() @@ -32,6 +32,7 @@ func TestUnaryInterceptorForwardsBearer(t *testing.T) { t.Fatal("missing caller") } gotSubject = c.Subject + gotUsername = c.Username gotGroups = c.Groups var okRaw bool gotRaw, okRaw = BearerFromContext(ctx) @@ -43,8 +44,8 @@ func TestUnaryInterceptorForwardsBearer(t *testing.T) { if err != nil { t.Fatalf("interceptor: %v", err) } - if gotSubject != "konrad" || gotRaw != raw { - t.Fatalf("subject %q raw match %v", gotSubject, gotRaw == raw) + if gotSubject != "konrad" || gotUsername != "konrad" || gotRaw != raw { + t.Fatalf("subject %q username %q raw match %v", gotSubject, gotUsername, gotRaw == raw) } if len(gotGroups) != 2 || gotGroups[0] != "family" || gotGroups[1] != "mgmnt-admin" { t.Fatalf("groups = %#v", gotGroups)