2023-04-14 19:25:56 +02:00
|
|
|
|
using Bit.Core.Auth.IdentityServer;
|
2021-01-06 19:49:28 +01:00
|
|
|
|
using Microsoft.AspNetCore.Http;
|
2020-12-28 19:49:18 +01:00
|
|
|
|
using Microsoft.Extensions.Primitives;
|
2021-01-06 19:49:28 +01:00
|
|
|
|
using NSubstitute;
|
|
|
|
|
using Xunit;
|
2020-12-28 19:49:18 +01:00
|
|
|
|
|
2023-04-14 19:25:56 +02:00
|
|
|
|
namespace Bit.Core.Test.Auth.IdentityServer;
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2020-12-28 19:49:18 +01:00
|
|
|
|
public class TokenRetrievalTests
|
|
|
|
|
{
|
|
|
|
|
private readonly Func<HttpRequest, string> _sut = TokenRetrieval.FromAuthorizationHeaderOrQueryString();
|
2022-08-29 21:53:48 +02:00
|
|
|
|
|
2020-12-28 19:49:18 +01:00
|
|
|
|
[Fact]
|
|
|
|
|
public void RetrieveToken_FromHeader_ReturnsToken()
|
2022-08-29 22:06:55 +02:00
|
|
|
|
{
|
2020-12-28 19:49:18 +01:00
|
|
|
|
// Arrange
|
|
|
|
|
var headers = new HeaderDictionary
|
|
|
|
|
{
|
|
|
|
|
{ "Authorization", "Bearer test_value" },
|
|
|
|
|
{ "X-Test-Header", "random_value" }
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
var request = Substitute.For<HttpRequest>();
|
|
|
|
|
|
|
|
|
|
request.Headers.Returns(headers);
|
|
|
|
|
|
|
|
|
|
// Act
|
2021-01-06 19:49:28 +01:00
|
|
|
|
var token = _sut(request);
|
2020-12-28 19:49:18 +01:00
|
|
|
|
|
|
|
|
|
// Assert
|
|
|
|
|
Assert.Equal("test_value", token);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
[Fact]
|
|
|
|
|
public void RetrieveToken_FromQueryString_ReturnsToken()
|
2022-08-29 22:06:55 +02:00
|
|
|
|
{
|
2020-12-28 19:49:18 +01:00
|
|
|
|
// Arrange
|
|
|
|
|
var queryString = new Dictionary<string, StringValues>
|
|
|
|
|
{
|
|
|
|
|
{ "access_token", "test_value" },
|
|
|
|
|
{ "test-query", "random_value" }
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
var request = Substitute.For<HttpRequest>();
|
|
|
|
|
request.Query.Returns(new QueryCollection(queryString));
|
|
|
|
|
|
|
|
|
|
// Act
|
2021-01-06 19:49:28 +01:00
|
|
|
|
var token = _sut(request);
|
2020-12-28 19:49:18 +01:00
|
|
|
|
|
|
|
|
|
// Assert
|
|
|
|
|
Assert.Equal("test_value", token);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
[Fact]
|
|
|
|
|
public void RetrieveToken_HasBoth_ReturnsHeaderToken()
|
2022-08-29 22:06:55 +02:00
|
|
|
|
{
|
2020-12-28 19:49:18 +01:00
|
|
|
|
// Arrange
|
|
|
|
|
var queryString = new Dictionary<string, StringValues>
|
|
|
|
|
{
|
|
|
|
|
{ "access_token", "query_string_token" },
|
|
|
|
|
{ "test-query", "random_value" }
|
2022-08-29 21:53:48 +02:00
|
|
|
|
};
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2020-12-28 19:49:18 +01:00
|
|
|
|
var headers = new HeaderDictionary
|
|
|
|
|
{
|
|
|
|
|
{ "Authorization", "Bearer header_token" },
|
|
|
|
|
{ "X-Test-Header", "random_value" }
|
2022-08-29 22:06:55 +02:00
|
|
|
|
};
|
|
|
|
|
|
2020-12-28 19:49:18 +01:00
|
|
|
|
var request = Substitute.For<HttpRequest>();
|
|
|
|
|
request.Headers.Returns(headers);
|
|
|
|
|
request.Query.Returns(new QueryCollection(queryString));
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
|
|
|
|
// Act
|
2021-01-06 19:49:28 +01:00
|
|
|
|
var token = _sut(request);
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2020-12-28 19:49:18 +01:00
|
|
|
|
// Assert
|
|
|
|
|
Assert.Equal("header_token", token);
|
2022-08-29 22:06:55 +02:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
[Fact]
|
2020-12-28 19:49:18 +01:00
|
|
|
|
public void RetrieveToken_NoToken_ReturnsNull()
|
2022-08-29 22:06:55 +02:00
|
|
|
|
{
|
2022-08-29 20:53:16 +02:00
|
|
|
|
// Arrange
|
2020-12-28 19:49:18 +01:00
|
|
|
|
var request = Substitute.For<HttpRequest>();
|
|
|
|
|
|
|
|
|
|
// Act
|
2021-01-06 19:49:28 +01:00
|
|
|
|
var token = _sut(request);
|
2020-12-28 19:49:18 +01:00
|
|
|
|
|
|
|
|
|
// Assert
|
|
|
|
|
Assert.Null(token);
|
|
|
|
|
}
|
|
|
|
|
}
|