|
| 1 | +from flask import url_for |
| 2 | +import critiquebrainz.db.oauth_client as db_oauth_client |
| 3 | +import critiquebrainz.db.oauth_grant as db_oauth_grant |
| 4 | +import critiquebrainz.db.users as db_users |
| 5 | +from critiquebrainz.frontend.testing import FrontendTestCase |
| 6 | + |
| 7 | +from urllib.parse import urlparse, parse_qs |
| 8 | + |
| 9 | + |
| 10 | +class OauthTestCase(FrontendTestCase): |
| 11 | + def setUp(self): |
| 12 | + from critiquebrainz.db.user import User |
| 13 | + self.user = User(db_users.get_or_create(2, "9371e5c7-5995-4471-a5a9-33481f897f9c", new_user_data={ |
| 14 | + "display_name": u"User", |
| 15 | + })) |
| 16 | + self.oauthclient = db_oauth_client.create( |
| 17 | + user_id=self.user.id, |
| 18 | + name='An oauth app', |
| 19 | + desc='This is a great client', |
| 20 | + website='https://example.com', |
| 21 | + redirect_uri='https://example.com/redirect' |
| 22 | + ) |
| 23 | + |
| 24 | + |
| 25 | + def test_invalid_clientid(self): |
| 26 | + self.temporary_login(self.user) |
| 27 | + response = self.client.get(url_for('oauth.authorize_prompt', response_type='code', client_id='not-an-id', redirect_uri='x', scope='x', state='x')) |
| 28 | + assert response.status_code == 400 |
| 29 | + assert "400 Bad Request: Client authentication failed." in response.text |
| 30 | + |
| 31 | + def test_invalid_redirect_uri(self): |
| 32 | + self.temporary_login(self.user) |
| 33 | + client_id = self.oauthclient["client_id"] |
| 34 | + response = self.client.get(url_for('oauth.authorize_prompt', response_type='code', client_id=client_id, redirect_uri='x', scope='x', state='x')) |
| 35 | + assert response.status_code == 400 |
| 36 | + assert "400 Bad Request: Invalid redirect uri." in response.text |
| 37 | + |
| 38 | + def test_invalid_scope(self): |
| 39 | + self.temporary_login(self.user) |
| 40 | + client_id = self.oauthclient["client_id"] |
| 41 | + redirect_uri = self.oauthclient["redirect_uri"] |
| 42 | + response = self.client.get(url_for('oauth.authorize_prompt', response_type='code', client_id=client_id, redirect_uri=redirect_uri, scope='x', state='x')) |
| 43 | + assert response.status_code == 400 |
| 44 | + assert "400 Bad Request: The requested scope is invalid, unknown, or malformed." in response.text |
| 45 | + |
| 46 | + def test_valid_oauth_request(self): |
| 47 | + self.temporary_login(self.user) |
| 48 | + client_id = self.oauthclient["client_id"] |
| 49 | + redirect_uri = self.oauthclient["redirect_uri"] |
| 50 | + response = self.client.get(url_for('oauth.authorize_prompt', response_type='code', client_id=client_id, redirect_uri=redirect_uri, scope='review', state='x')) |
| 51 | + assert response.status_code == 200 |
| 52 | + assert "Do you want to give access to your account to An oauth app?" in response.text |
| 53 | + |
| 54 | + def test_approve_invalid_parameter(self): |
| 55 | + """Same endpoint, but a POST with an invalid client id""" |
| 56 | + self.temporary_login(self.user) |
| 57 | + response = self.client.post(url_for('oauth.authorize_prompt', response_type='code', client_id='x', redirect_uri='y', scope='review', state='x')) |
| 58 | + assert response.status_code == 400 |
| 59 | + assert "400 Bad Request: Client authentication failed." in response.text |
| 60 | + |
| 61 | + def test_approve_application(self): |
| 62 | + """A POST to approve an oauth authorization""" |
| 63 | + self.temporary_login(self.user) |
| 64 | + client_id = self.oauthclient["client_id"] |
| 65 | + redirect_uri = self.oauthclient["redirect_uri"] |
| 66 | + response = self.client.post(url_for('oauth.authorize_prompt', response_type='code', client_id=client_id, redirect_uri=redirect_uri, scope='review', state='x')) |
| 67 | + assert response.status_code == 302 |
| 68 | + # This is the redirect URL that we set in the oauth client |
| 69 | + assert response.location.startswith('https://example.com/redirect?code=') |
| 70 | + |
| 71 | + redirect_location = urlparse(response.location) |
| 72 | + query = parse_qs(redirect_location.query) |
| 73 | + assert query['state'] == ['x'] |
| 74 | + code = query['code'][0] |
| 75 | + |
| 76 | + grants = db_oauth_grant.list_grants(client_id=client_id, code=code) |
| 77 | + assert len(grants) == 1 |
0 commit comments