package server import ( "bytes" "net/http" "net/http/httptest" "testing" "time" ) func TestLoginSuccess(t *testing.T) { s := &Server{ accessToken: "secret123", sessions: make(map[string]int64), loginAttempts: make(map[string]int), loginLockout: make(map[string]time.Time), } req := httptest.NewRequest("POST", "/api/login", bytes.NewBufferString(`{"token":"secret123"}`)) req.Header.Set("Content-Type", "application/json") w := httptest.NewRecorder() s.handleLogin(w, req) if w.Code != http.StatusOK { t.Errorf("Status = %d, want %d", w.Code, http.StatusOK) } if len(w.Header().Values("Set-Cookie")) == 0 { t.Error("Expected Set-Cookie header") } } func TestLoginFailure(t *testing.T) { s := &Server{ accessToken: "secret123", sessions: make(map[string]int64), loginAttempts: make(map[string]int), loginLockout: make(map[string]time.Time), } req := httptest.NewRequest("POST", "/api/login", bytes.NewBufferString(`{"token":"wrong"}`)) req.Header.Set("Content-Type", "application/json") w := httptest.NewRecorder() s.handleLogin(w, req) if w.Code != http.StatusUnauthorized { t.Errorf("Status = %d, want %d", w.Code, http.StatusUnauthorized) } }