// DS1 follow-up — currentAccessToken reads the REAL Supabase session, so // email/password users' authenticated fetches carry a token (the OAuth-only // 'sb-token' key left them silently unauthenticated everywhere). const { currentAccessToken } = require('../../web/src/lib/authToken'); function fakeWindow(store) { const keys = Object.keys(store); global.window = { localStorage: { length: keys.length, key: (i) => keys[i] ?? null, getItem: (k) => (k in store ? store[k] : null), }, }; } afterEach(() => { delete global.window; }); describe('currentAccessToken', () => { test('reads the v2 supabase session (access_token at top level)', () => { fakeWindow({ 'sb-zmdnczhtdxcddsxzttub-auth-token': JSON.stringify({ access_token: 'TOKEN_V2', refresh_token: 'r' }) }); expect(currentAccessToken()).toBe('TOKEN_V2'); }); test('reads the v1 shape (currentSession.access_token)', () => { fakeWindow({ 'sb-abc-auth-token': JSON.stringify({ currentSession: { access_token: 'TOKEN_V1' } }) }); expect(currentAccessToken()).toBe('TOKEN_V1'); }); test('falls back to the legacy sb-token key', () => { fakeWindow({ 'sb-token': 'LEGACY' }); expect(currentAccessToken()).toBe('LEGACY'); }); test('no session → null (never throws on malformed JSON)', () => { fakeWindow({ 'sb-x-auth-token': 'not json{' }); expect(currentAccessToken()).toBeNull(); }); test('SSR (no window) → null', () => { expect(currentAccessToken()).toBeNull(); }); });