oauth2-server/tests/Middleware/AuthorizationServerMiddlewareTest.php

125 lines
4.8 KiB
PHP
Raw Normal View History

2016-03-10 17:22:48 +00:00
<?php
namespace LeagueTests\Middleware;
use DateInterval;
2016-04-17 08:06:17 -04:00
use League\OAuth2\Server\AuthorizationServer;
2016-04-10 15:58:01 +01:00
use League\OAuth2\Server\Exception\OAuthServerException;
2016-03-10 17:22:48 +00:00
use League\OAuth2\Server\Grant\ClientCredentialsGrant;
2016-04-17 12:54:25 +01:00
use League\OAuth2\Server\Middleware\AuthorizationServerMiddleware;
2016-03-10 17:22:48 +00:00
use League\OAuth2\Server\Repositories\AccessTokenRepositoryInterface;
use League\OAuth2\Server\Repositories\ClientRepositoryInterface;
use League\OAuth2\Server\Repositories\ScopeRepositoryInterface;
2016-04-09 10:46:40 -04:00
use LeagueTests\Stubs\AccessTokenEntity;
2016-03-15 01:10:47 +01:00
use LeagueTests\Stubs\ClientEntity;
use LeagueTests\Stubs\ScopeEntity;
2016-03-10 17:22:48 +00:00
use LeagueTests\Stubs\StubResponseType;
use PHPUnit\Framework\TestCase;
2016-03-10 17:22:48 +00:00
use Zend\Diactoros\Response;
use Zend\Diactoros\ServerRequestFactory;
class AuthorizationServerMiddlewareTest extends TestCase
2016-03-10 17:22:48 +00:00
{
const DEFAULT_SCOPE = 'basic';
2016-03-10 17:22:48 +00:00
public function testValidResponse()
{
$client = new ClientEntity();
$client->setConfidential();
2016-07-08 15:29:21 +02:00
$clientRepository = $this->getMockBuilder(ClientRepositoryInterface::class)->getMock();
$clientRepository->method('getClientEntity')->willReturn($client);
2016-03-10 17:22:48 +00:00
$scopeEntity = new ScopeEntity;
2016-03-23 18:50:14 +00:00
$scopeRepositoryMock = $this->getMockBuilder(ScopeRepositoryInterface::class)->getMock();
$scopeRepositoryMock->method('getScopeEntityByIdentifier')->willReturn($scopeEntity);
2016-03-23 18:50:14 +00:00
$scopeRepositoryMock->method('finalizeScopes')->willReturnArgument(0);
2016-07-08 15:29:21 +02:00
$accessRepositoryMock = $this->getMockBuilder(AccessTokenRepositoryInterface::class)->getMock();
$accessRepositoryMock->method('getNewToken')->willReturn(new AccessTokenEntity());
2016-04-17 12:54:25 +01:00
$server = new AuthorizationServer(
2016-03-10 17:22:48 +00:00
$clientRepository,
$accessRepositoryMock,
2016-03-23 18:50:14 +00:00
$scopeRepositoryMock,
2016-03-28 17:10:41 +02:00
'file://' . __DIR__ . '/../Stubs/private.key',
2017-07-01 18:11:19 +01:00
base64_encode(random_bytes(36)),
2016-03-10 17:22:48 +00:00
new StubResponseType()
);
$server->setDefaultScope(self::DEFAULT_SCOPE);
2016-04-10 15:58:01 +01:00
$server->enableGrantType(new ClientCredentialsGrant());
2016-03-10 17:22:48 +00:00
$_POST['grant_type'] = 'client_credentials';
$_POST['client_id'] = 'foo';
$_POST['client_secret'] = 'bar';
$request = ServerRequestFactory::fromGlobals();
2016-04-17 12:54:25 +01:00
$middleware = new AuthorizationServerMiddleware($server);
2016-03-10 17:22:48 +00:00
$response = $middleware->__invoke(
$request,
new Response(),
function () {
return func_get_args()[1];
}
);
$this->assertEquals(200, $response->getStatusCode());
}
public function testOAuthErrorResponse()
{
2016-07-08 15:29:21 +02:00
$clientRepository = $this->getMockBuilder(ClientRepositoryInterface::class)->getMock();
$clientRepository->method('validateClient')->willReturn(false);
2016-03-10 17:22:48 +00:00
2016-04-17 12:54:25 +01:00
$server = new AuthorizationServer(
2016-03-10 17:22:48 +00:00
$clientRepository,
2016-07-08 15:29:21 +02:00
$this->getMockBuilder(AccessTokenRepositoryInterface::class)->getMock(),
$this->getMockBuilder(ScopeRepositoryInterface::class)->getMock(),
2016-03-28 17:10:41 +02:00
'file://' . __DIR__ . '/../Stubs/private.key',
2017-07-01 18:11:19 +01:00
base64_encode(random_bytes(36)),
2016-03-10 17:22:48 +00:00
new StubResponseType()
);
$server->enableGrantType(new ClientCredentialsGrant(), new DateInterval('PT1M'));
2016-03-10 17:22:48 +00:00
$_POST['grant_type'] = 'client_credentials';
$_POST['client_id'] = 'foo';
$_POST['client_secret'] = 'bar';
$request = ServerRequestFactory::fromGlobals();
2016-04-17 12:54:25 +01:00
$middleware = new AuthorizationServerMiddleware($server);
2016-03-10 17:22:48 +00:00
$response = $middleware->__invoke(
$request,
new Response(),
function () {
return func_get_args()[1];
}
);
$this->assertEquals(401, $response->getStatusCode());
}
2016-04-10 15:58:01 +01:00
public function testOAuthErrorResponseRedirectUri()
{
$exception = OAuthServerException::invalidScope('test', 'http://foo/bar');
$response = $exception->generateHttpResponse(new Response());
$this->assertEquals(302, $response->getStatusCode());
$this->assertEquals('http://foo/bar?error=invalid_scope&error_description=The+requested+scope+is+invalid%2C+unknown%2C+or+malformed&hint=Check+the+%60test%60+scope&message=The+requested+scope+is+invalid%2C+unknown%2C+or+malformed',
2017-07-01 18:11:19 +01:00
$response->getHeader('location')[0]);
2016-04-10 15:58:01 +01:00
}
public function testOAuthErrorResponseRedirectUriFragment()
{
$exception = OAuthServerException::invalidScope('test', 'http://foo/bar');
$response = $exception->generateHttpResponse(new Response(), true);
$this->assertEquals(302, $response->getStatusCode());
$this->assertEquals('http://foo/bar#error=invalid_scope&error_description=The+requested+scope+is+invalid%2C+unknown%2C+or+malformed&hint=Check+the+%60test%60+scope&message=The+requested+scope+is+invalid%2C+unknown%2C+or+malformed',
2017-07-01 18:11:19 +01:00
$response->getHeader('location')[0]);
2016-04-10 15:58:01 +01:00
}
2016-03-10 17:22:48 +00:00
}