Skip to content

test: cover null claim names, zero leeway and null audience in JWTVerifier - #814

Open
renanmpimentel wants to merge 1 commit into
auth0:masterfrom
renanmpimentel:test/verifier-argument-and-null-audience-checks
Open

renanmpimentel wants to merge 1 commit into
auth0:masterfrom
renanmpimentel:test/verifier-argument-and-null-audience-checks

Conversation

@renanmpimentel

@renanmpimentel renanmpimentel commented Oct 6, 2026 •

Copy link
Copy Markdown

Changes

Test-only change in JWTVerifierTest. No production code, public API or behaviour is changed. It adds three tests for documented Verification contracts that the current suite doesn't check:

  1. shouldThrowOnNullCustomClaimNameForEveryValueType: withClaim/withArrayClaim are documented to throw IllegalArgumentException when the claim name is null. Only the withClaim(String, String) overload (and withClaimPresence) is tested today. This test covers the Boolean, Integer, Long, Double, Instant and BiPredicate overloads of withClaim, and the String..., Integer... and Long... overloads of withArrayClaim.
  2. shouldAcceptZeroLeeway: acceptLeeway, acceptExpiresAt, acceptNotBefore and acceptIssuedAt are documented to throw only when the leeway is negative. Negative values are tested, but 0 never is.
  3. shouldThrowWhenExpectedNullAudienceButTokenHasAudience: mirrors the existing withAnyOfAudience case (shouldThrowWhenExpectedEmptyList) for withAudience((String[]) null). A token that has an aud claim must be rejected with IncorrectClaimException.

Each of these regressions currently leaves the whole suite green:

Regression in JWTVerifier Before (703 tests) After (706 tests)
drop assertNonNull(name) from withClaim(String, Boolean) passes 1 failure
... same for Integer, Long, Double, Instant, BiPredicate passes 1 failure each
... same for withArrayClaim(String...), (Integer...), (Long...) passes 1 failure each
assertPositive: leeway < 0 → leeway <= 0 (rejects 0) passes 1 failure
withAudience: verifyNull(claim, value) → value == null (accepts any aud when null is expected) passes 1 failure

Each regression was applied on its own against the unmodified suite, then against the new one.

References

No issue. I found these while experimenting with Supertest, a tool for evaluating test effectiveness using mutation testing and test-harness mutilation. With PIT 1.15.8 on JWTVerifier*, killed mutants go from 155 to 165 of 171. The remaining 6 are equivalent, e.g. addMandatoryClaimChecks lambdas whose callee only returns true or throws.

Testing

  • ./gradlew assemble apiDiff check jacocoTestReport --continue (same as CI): BUILD SUCCESSFUL. Tests ran on Java 8, 11, 17 and 21 with 0 failures, and checkstyle and apiDiff pass.

  • The before/after table above was produced by applying each regression in isolation and running ./gradlew :java-jwt:test.

  • This change adds test coverage

  • This change has been tested on the latest version of Java or why not

Checklist

@renanmpimentel
renanmpimentel requested a review from a team as a code owner October 6, 2026 00:18

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant