using backend.Devices; using FluentAssertions; using Xunit; namespace backend.tests; public class DeviceTokenServiceTests { private readonly DeviceTokenService _svc = new(); [Fact] public void Generate_returns_url_safe_token_of_expected_length() { var (plaintext, hash) = _svc.Generate(); plaintext.Should().MatchRegex("^[A-Za-z0-9_-]+$"); plaintext.Length.Should().BeGreaterThanOrEqualTo(40); hash.Should().NotBeNullOrEmpty(); hash.Should().NotBe(plaintext); } [Fact] public void Hash_is_deterministic_for_same_input() { var (plaintext, hash) = _svc.Generate(); _svc.Hash(plaintext).Should().Be(hash); } [Fact] public void Verify_accepts_matching_plaintext_and_rejects_others() { var (plaintext, hash) = _svc.Generate(); _svc.Verify(plaintext, hash).Should().BeTrue(); _svc.Verify(plaintext + "x", hash).Should().BeFalse(); _svc.Verify("totally-different", hash).Should().BeFalse(); } }