unsignedTestJwt function
Crafts a JWT by base64url-encoding claims directly.
Unlike a JWT library, this gives exact control over every claim: no
auto-injected iat, no claim overrides. The signature is a stub, for
code paths that decode without verifying.
Implementation
@visibleForTesting
String unsignedTestJwt(Map<String, dynamic> claims) {
final header = base64Url.encode(
utf8.encode(jsonEncode({'alg': 'HS256', 'typ': 'JWT'})),
);
final body = base64Url.encode(utf8.encode(jsonEncode(claims)));
const signature = 'AAAA';
return '$header.$body.$signature';
}