Fix tests for earlier changes.
This commit is contained in:
@@ -642,7 +642,10 @@ def update_oid_client(
|
|||||||
changes["redirect_uris"] = redirect_uris
|
changes["redirect_uris"] = redirect_uris
|
||||||
if secret_hash is not None and secret_hash != client.client_secret_hash:
|
if secret_hash is not None and secret_hash != client.client_secret_hash:
|
||||||
changes["client_secret_hash"] = secret_hash
|
changes["client_secret_hash"] = secret_hash
|
||||||
if backchannel_logout_uri is not _UNSET and backchannel_logout_uri != client.backchannel_logout_uri:
|
if (
|
||||||
|
backchannel_logout_uri is not _UNSET
|
||||||
|
and backchannel_logout_uri != client.backchannel_logout_uri
|
||||||
|
):
|
||||||
changes["backchannel_logout_uri"] = backchannel_logout_uri
|
changes["backchannel_logout_uri"] = backchannel_logout_uri
|
||||||
|
|
||||||
if not changes:
|
if not changes:
|
||||||
|
|||||||
@@ -1090,7 +1090,11 @@ async def admin_update_oidc_client(
|
|||||||
if not isinstance(uri, str) or not uri.startswith("http"):
|
if not isinstance(uri, str) or not uri.startswith("http"):
|
||||||
raise ValueError(f"Invalid redirect URI: {uri}")
|
raise ValueError(f"Invalid redirect URI: {uri}")
|
||||||
|
|
||||||
if backchannel_logout_uri is not _UNSET and backchannel_logout_uri and not backchannel_logout_uri.startswith("http"):
|
if (
|
||||||
|
backchannel_logout_uri is not _UNSET
|
||||||
|
and backchannel_logout_uri
|
||||||
|
and not backchannel_logout_uri.startswith("http")
|
||||||
|
):
|
||||||
raise ValueError("backchannel_logout_uri must be an HTTP(S) URL")
|
raise ValueError("backchannel_logout_uri must be an HTTP(S) URL")
|
||||||
|
|
||||||
secret_hash = None
|
secret_hash = None
|
||||||
|
|||||||
@@ -231,7 +231,9 @@ def create_logout_token(
|
|||||||
"iat": int(now.timestamp()),
|
"iat": int(now.timestamp()),
|
||||||
"exp": int((now + timedelta(seconds=120)).timestamp()),
|
"exp": int((now + timedelta(seconds=120)).timestamp()),
|
||||||
"events": {"http://schemas.openid.net/event/backchannel-logout": {}},
|
"events": {"http://schemas.openid.net/event/backchannel-logout": {}},
|
||||||
"jti": hashlib.sha256(f"{now.timestamp()}{audience}{sid}{sub}".encode()).hexdigest()[:16],
|
"jti": hashlib.sha256(
|
||||||
|
f"{now.timestamp()}{audience}{sid}{sub}".encode()
|
||||||
|
).hexdigest()[:16],
|
||||||
}
|
}
|
||||||
if sid:
|
if sid:
|
||||||
payload["sid"] = sid
|
payload["sid"] = sid
|
||||||
|
|||||||
+14
-6
@@ -11,7 +11,7 @@ These tests cover:
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
import secrets
|
import secrets
|
||||||
from datetime import timedelta
|
from datetime import UTC, datetime, timedelta
|
||||||
|
|
||||||
import httpx
|
import httpx
|
||||||
import pytest
|
import pytest
|
||||||
@@ -299,22 +299,30 @@ class TestSetSessionEndpoint:
|
|||||||
"""Tests for POST /auth/api/set-session"""
|
"""Tests for POST /auth/api/set-session"""
|
||||||
|
|
||||||
@pytest.mark.asyncio
|
@pytest.mark.asyncio
|
||||||
async def test_set_session_without_bearer_returns_401(
|
async def test_set_session_without_bearer_returns_400(
|
||||||
self, client: httpx.AsyncClient
|
self, client: httpx.AsyncClient
|
||||||
):
|
):
|
||||||
"""Set session without bearer token should return 401."""
|
"""Set session without bearer token should return 400."""
|
||||||
response = await client.post("/auth/api/set-session")
|
response = await client.post("/auth/api/set-session")
|
||||||
assert response.status_code == 401
|
assert response.status_code == 400
|
||||||
|
|
||||||
@pytest.mark.asyncio
|
@pytest.mark.asyncio
|
||||||
async def test_set_session_with_valid_bearer_token(
|
async def test_set_session_with_valid_bearer_token(
|
||||||
self, client: httpx.AsyncClient, session_token: str
|
self, client: httpx.AsyncClient, session_token: str
|
||||||
):
|
):
|
||||||
"""Set session with valid bearer token should set cookie."""
|
"""Set session with valid auth code as bearer should set cookie."""
|
||||||
|
from paskia import authcode
|
||||||
|
|
||||||
|
code = authcode.store_cookie(
|
||||||
|
authcode.CookieCode(
|
||||||
|
session_key=session_token,
|
||||||
|
created=datetime.now(UTC),
|
||||||
|
)
|
||||||
|
)
|
||||||
response = await client.post(
|
response = await client.post(
|
||||||
"/auth/api/set-session",
|
"/auth/api/set-session",
|
||||||
headers={
|
headers={
|
||||||
"Authorization": f"Bearer {session_token}",
|
"Authorization": f"Bearer {code}",
|
||||||
"Host": "localhost:4401",
|
"Host": "localhost:4401",
|
||||||
},
|
},
|
||||||
)
|
)
|
||||||
|
|||||||
Reference in New Issue
Block a user