-- valid_token: properly signed JWT authenticates to correct role -- Requires mock_jwks.py running and pg_knoe_auth loaded. -- The \getenv + \connect with token is handled by the test harness wrapper; -- here we verify the extension is loaded and the GUC is set. SHOW shared_preload_libraries; SELECT current_setting('pg_knoe_auth.role_claim'); SELECT current_setting('pg_knoe_auth.audience'); -- Verify the module is present in pg_preload_libraries SELECT count(*) > 0 AS pg_knoe_auth_loaded FROM pg_catalog.pg_file_settings WHERE name = 'shared_preload_libraries' AND setting LIKE '%pg_knoe_auth%';