diff --git a/apps/emqx_authn/test/emqx_authn_jwt_SUITE.erl b/apps/emqx_authn/test/emqx_authn_jwt_SUITE.erl index f7534b880..bad6d5cc0 100644 --- a/apps/emqx_authn/test/emqx_authn_jwt_SUITE.erl +++ b/apps/emqx_authn/test/emqx_authn_jwt_SUITE.erl @@ -342,6 +342,40 @@ t_jwt_authenticator_verify_claims(_) -> }, ?assertMatch({ok, #{is_superuser := false}}, emqx_authn_jwt:authenticate(Credential3, State1)). +t_jwt_not_allow_empty_claim_name(_) -> + Request = #{ + <<"use_jwks">> => false, + <<"algorithm">> => <<"hmac-based">>, + <<"secret">> => <<"secret">>, + <<"mechanism">> => <<"jwt">> + }, + ?assertMatch( + {200, _}, + emqx_authn_api:authenticators( + post, #{body => Request} + ) + ), + + ?assertMatch( + {400, _}, + emqx_authn_api:authenticator( + put, #{ + bindings => #{id => <<"jwt">>}, + body => Request#{<<"verify_claims">> => #{<<>> => <<>>}} + } + ) + ), + + ?assertMatch( + {200, _}, + emqx_authn_api:authenticator( + put, #{ + bindings => #{id => <<"jwt">>}, + body => Request#{<<"verify_claims">> => #{<<"key">> => <<>>}} + } + ) + ). + %%------------------------------------------------------------------------------ %% Helpers %%------------------------------------------------------------------------------