oauth2-server/tests/resource/ResourceServerTest.php

285 lines
8.9 KiB
PHP
Raw Normal View History

2013-02-05 16:20:56 +00:00
<?php
use \Mockery as m;
class Resource_Server_test extends PHPUnit_Framework_TestCase
{
private $session;
2013-02-05 16:20:56 +00:00
public function setUp()
{
$this->session = M::mock('League\OAuth2\Server\Storage\SessionInterface');
}
2013-02-05 16:20:56 +00:00
private function returnDefault()
{
return new League\OAuth2\Server\Resource($this->session);
}
2013-02-05 16:20:56 +00:00
public function test_getExceptionMessage()
{
$m = League\OAuth2\Server\Resource::getExceptionMessage('invalid_request');
$reflector = new ReflectionClass($this->returnDefault());
$exceptionMessages = $reflector->getProperty('exceptionMessages');
$exceptionMessages->setAccessible(true);
$v = $exceptionMessages->getValue();
$this->assertEquals($v['invalid_request'], $m);
}
public function test_getExceptionCode()
{
$this->assertEquals('invalid_request', League\OAuth2\Server\Resource::getExceptionType(0));
$this->assertEquals('invalid_token', League\OAuth2\Server\Resource::getExceptionType(1));
$this->assertEquals('insufficient_scope', League\OAuth2\Server\Resource::getExceptionType(2));
}
public function test_getExceptionHttpHeaders()
{
$this->assertEquals(array('HTTP/1.1 400 Bad Request'), League\OAuth2\Server\Resource::getExceptionHttpHeaders('invalid_request'));
$this->assertContains('HTTP/1.1 401 Unauthorized', League\OAuth2\Server\Resource::getExceptionHttpHeaders('invalid_token'));
$this->assertEquals(array('HTTP/1.1 403 Forbidden'), League\OAuth2\Server\Resource::getExceptionHttpHeaders('insufficient_scope'));
}
public function test_setRequest()
2013-02-05 16:20:56 +00:00
{
$s = $this->returnDefault();
$request = new League\OAuth2\Server\Util\Request();
2013-02-05 16:20:56 +00:00
$s->setRequest($request);
$reflector = new ReflectionClass($s);
$requestProperty = $reflector->getProperty('request');
$requestProperty->setAccessible(true);
$v = $requestProperty->getValue($s);
$this->assertTrue($v instanceof League\OAuth2\Server\Util\RequestInterface);
2013-02-05 16:20:56 +00:00
}
public function test_getRequest()
{
$s = $this->returnDefault();
$request = new League\OAuth2\Server\Util\Request();
2013-02-05 16:20:56 +00:00
$s->setRequest($request);
$v = $s->getRequest();
$this->assertTrue($v instanceof League\OAuth2\Server\Util\RequestInterface);
2013-02-05 16:20:56 +00:00
}
public function test_getTokenKey()
{
$s = $this->returnDefault();
$this->assertEquals('access_token', $s->getTokenKey());
2013-02-05 16:20:56 +00:00
}
public function test_setTokenKey()
{
$s = $this->returnDefault();
$s->setTokenKey('oauth_token');
2013-02-05 16:20:56 +00:00
$reflector = new ReflectionClass($s);
$requestProperty = $reflector->getProperty('tokenKey');
$requestProperty->setAccessible(true);
$v = $requestProperty->getValue($s);
$this->assertEquals('oauth_token', $v);
2013-02-05 16:20:56 +00:00
}
2013-05-06 11:09:36 -07:00
public function test_getScopes()
{
$s = $this->returnDefault();
$this->assertEquals(array(), $s->getScopes());
}
2013-02-05 16:20:56 +00:00
/**
* @expectedException League\OAuth2\Server\Exception\MissingAccessTokenException
2013-02-05 16:20:56 +00:00
*/
public function test_determineAccessToken_missingToken()
{
$_SERVER['HTTP_AUTHORIZATION'] = 'Bearer';
$request = new League\OAuth2\Server\Util\Request(array(), array(), array(), array(), $_SERVER);
2013-02-05 16:20:56 +00:00
$s = $this->returnDefault();
$s->setRequest($request);
2013-02-05 16:20:56 +00:00
$reflector = new ReflectionClass($s);
$method = $reflector->getMethod('determineAccessToken');
$method->setAccessible(true);
2013-02-05 16:20:56 +00:00
$method->invoke($s);
2013-02-05 16:20:56 +00:00
}
/**
* @expectedException League\OAuth2\Server\Exception\MissingAccessTokenException
*/
public function test_determineAccessToken_brokenCurlRequest()
{
$_SERVER['HTTP_AUTHORIZATION'] = 'Bearer, Bearer abcdef';
$request = new League\OAuth2\Server\Util\Request(array(), array(), array(), array(), $_SERVER);
$s = $this->returnDefault();
$s->setRequest($request);
$reflector = new ReflectionClass($s);
$method = $reflector->getMethod('determineAccessToken');
$method->setAccessible(true);
$method->invoke($s);
}
2013-02-05 16:20:56 +00:00
public function test_determineAccessToken_fromHeader()
{
$request = new League\OAuth2\Server\Util\Request();
2013-02-05 16:20:56 +00:00
2013-02-08 11:40:33 +00:00
$requestReflector = new ReflectionClass($request);
$param = $requestReflector->getProperty('headers');
$param->setAccessible(true);
$param->setValue($request, array(
2013-03-22 10:37:01 +00:00
'Authorization' => 'Bearer abcdef'
2013-02-08 11:40:33 +00:00
));
$s = $this->returnDefault();
$s->setRequest($request);
2013-02-05 16:20:56 +00:00
$reflector = new ReflectionClass($s);
2013-02-08 11:40:33 +00:00
$method = $reflector->getMethod('determineAccessToken');
$method->setAccessible(true);
2013-02-05 16:20:56 +00:00
$result = $method->invoke($s);
2013-02-05 16:20:56 +00:00
$this->assertEquals('abcdef', $result);
2013-02-05 16:20:56 +00:00
}
public function test_determineAccessToken_fromBrokenCurlHeader()
{
$request = new League\OAuth2\Server\Util\Request();
$requestReflector = new ReflectionClass($request);
$param = $requestReflector->getProperty('headers');
$param->setAccessible(true);
$param->setValue($request, array(
'Authorization' => 'Bearer abcdef, Bearer abcdef'
));
$s = $this->returnDefault();
$s->setRequest($request);
$reflector = new ReflectionClass($s);
$method = $reflector->getMethod('determineAccessToken');
$method->setAccessible(true);
$result = $method->invoke($s);
$this->assertEquals('abcdef', $result);
}
2013-02-05 16:20:56 +00:00
public function test_determineAccessToken_fromMethod()
{
$s = $this->returnDefault();
2013-02-05 16:20:56 +00:00
$_GET[$s->getTokenKey()] = 'abcdef';
$_SERVER['REQUEST_METHOD'] = 'get';
2013-02-05 16:20:56 +00:00
$request = new League\OAuth2\Server\Util\Request($_GET, array(), array(), array(), $_SERVER);
$s->setRequest($request);
2013-02-05 16:20:56 +00:00
$reflector = new ReflectionClass($s);
$method = $reflector->getMethod('determineAccessToken');
$method->setAccessible(true);
2013-02-05 16:20:56 +00:00
$result = $method->invoke($s);
2013-02-05 16:20:56 +00:00
$this->assertEquals('abcdef', $result);
2013-02-05 16:20:56 +00:00
}
public function test_hasScope_isRequired()
{
$s = $this->returnDefault();
$reflector = new ReflectionClass($s);
$param = $reflector->getProperty('sessionScopes');
$param->setAccessible(true);
$param->setValue($s, array(
'a', 'b', 'c'
));
$result = $s->hasScope(array('a', 'b'), true);
$this->assertEquals(true, $result);
}
/**
* @expectedException League\OAuth2\Server\Exception\InsufficientScopeException
*/
public function test_hasScope_isRequiredFailure()
{
$s = $this->returnDefault();
$reflector = new ReflectionClass($s);
$param = $reflector->getProperty('sessionScopes');
$param->setAccessible(true);
$param->setValue($s, array(
'a', 'b', 'c'
));
$s->hasScope('d', true);
}
/**
* @expectedException League\OAuth2\Server\Exception\InvalidAccessTokenException
*/
2013-02-05 16:20:56 +00:00
public function test_isValid_notValid()
{
$this->session->shouldReceive('validateAccessToken')->andReturn(false);
2013-02-05 16:20:56 +00:00
$request = new League\OAuth2\Server\Util\Request();
2013-02-08 11:40:33 +00:00
$requestReflector = new ReflectionClass($request);
$param = $requestReflector->getProperty('headers');
$param->setAccessible(true);
$param->setValue($request, array(
2013-03-22 10:37:01 +00:00
'Authorization' => 'Bearer abcdef'
2013-02-08 11:40:33 +00:00
));
$s = $this->returnDefault();
$s->setRequest($request);
2013-02-05 16:20:56 +00:00
$s->isValid();
2013-02-05 16:20:56 +00:00
}
public function test_isValid_valid()
{
$this->session->shouldReceive('validateAccessToken')->andReturn(array(
'session_id' => 1,
'owner_type' => 'user',
'owner_id' => 123,
2013-05-06 10:28:49 -07:00
'client_id' => 'testapp'
));
2013-05-06 10:28:49 -07:00
$this->session->shouldReceive('getScopes')->andReturn(array(
2013-05-27 19:38:07 +01:00
array('scope' => 'foo'),
array('scope' => 'bar')
2013-05-06 10:28:49 -07:00
));
2013-02-05 16:20:56 +00:00
$request = new League\OAuth2\Server\Util\Request();
2013-02-08 11:40:33 +00:00
$requestReflector = new ReflectionClass($request);
$param = $requestReflector->getProperty('headers');
$param->setAccessible(true);
$param->setValue($request, array(
2013-03-22 10:37:01 +00:00
'Authorization' => 'Bearer abcdef'
2013-02-08 11:40:33 +00:00
));
2013-05-06 10:28:49 -07:00
2013-02-08 11:40:33 +00:00
$s = $this->returnDefault();
$s->setRequest($request);
2013-02-05 16:20:56 +00:00
$this->assertTrue($s->isValid());
$this->assertEquals(123, $s->getOwnerId());
$this->assertEquals('user', $s->getOwnerType());
$this->assertEquals('abcdef', $s->getAccessToken());
2013-05-08 18:12:18 -07:00
$this->assertEquals('testapp', $s->getClientId());
$this->assertTrue($s->hasScope('foo'));
$this->assertTrue($s->hasScope('bar'));
$this->assertTrue($s->hasScope(array('foo', 'bar')));
$this->assertFalse($s->hasScope(array('foobar')));
$this->assertFalse($s->hasScope('foobar'));
2013-02-05 16:20:56 +00:00
}
}