-- right_aud_array: verify pg_knoe_auth accepts a token with aud as a JSON array -- containing the expected audience value. -- -- This is the positive counterpart to wrong_aud_array.sql. -- The token is issued by mock_jwks.py /token/right_aud_array with -- "aud": ["pg.0.knoe.dev"] — the array form of the correct audience. -- -- This test catches the §2.2.4-FIX bug: before the fix, json_get_string -- returned NULL for array-form aud, causing valid tokens to be rejected. -- -- Full end-to-end test requires the test harness to attempt a connection -- with the token from mock_jwks.py /token/right_aud_array and verify -- the connection is accepted. -- This SQL file validates the server-side GUC state is correct. SELECT 'right_aud_array' AS test_case, 'requires_harness_connection_test' AS note;