diff --git a/frontend/src/runtime/secureSessionStorage.test.ts b/frontend/src/runtime/secureSessionStorage.test.ts index f4fb83e4..2521a3a8 100644 --- a/frontend/src/runtime/secureSessionStorage.test.ts +++ b/frontend/src/runtime/secureSessionStorage.test.ts @@ -41,6 +41,7 @@ const createStorage = (): Storage => { describe("secure session storage", () => { beforeEach(() => { + vi.stubEnv("VITE_DESKTOP_SERVER_URL", ""); vi.useFakeTimers(); vi.setSystemTime(new Date("2026-07-02T00:00:00.000Z")); resetSecureSessionStorageForTests(); @@ -53,6 +54,7 @@ describe("secure session storage", () => { }); afterEach(() => { + vi.unstubAllEnvs(); vi.useRealTimers(); resetSecureSessionStorageForTests(); localStorage.clear(); @@ -158,6 +160,25 @@ describe("secure session storage", () => { expect(invokeMock).not.toHaveBeenCalled(); }); + it("restores credentials for the build default when no desktop server override is stored", async () => { + vi.stubEnv("VITE_DESKTOP_SERVER_URL", "https://default.ctms.example.com"); + localStorage.removeItem(DESKTOP_SERVER_URL_KEY); + const token = createJwt(Date.now() + DESKTOP_SESSION_MAX_AGE_MS); + invokeMock.mockResolvedValue(JSON.stringify({ + version: 1, + token, + storedAt: Date.now(), + expiresAt: Date.now() + DESKTOP_SESSION_MAX_AGE_MS, + })); + + await initializeSecureSessionStorage(); + + expect(getSessionToken()).toBe(token); + expect(invokeMock).toHaveBeenCalledExactlyOnceWith("credential_get", { + serverOrigin: "https://default.ctms.example.com/", + }); + }); + it("clears the previous server credential after a desktop server switch", async () => { const previousServerOrigin = "https://old.ctms.example.com/"; const nextServerOrigin = "https://new.ctms.example.com/";