-
Notifications
You must be signed in to change notification settings - Fork 149
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Persist Authorizations by Person #83
- Loading branch information
Showing
11 changed files
with
446 additions
and
21 deletions.
There are no files selected for viewing
181 changes: 181 additions & 0 deletions
181
Client/src/test/java/org/xdi/oxauth/ws/rs/PersistClientAuthorizationsHttpTest.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,181 @@ | ||
package org.xdi.oxauth.ws.rs; | ||
|
||
import org.testng.annotations.Parameters; | ||
import org.testng.annotations.Test; | ||
import org.xdi.oxauth.BaseTest; | ||
import org.xdi.oxauth.client.*; | ||
import org.xdi.oxauth.model.common.AuthenticationMethod; | ||
import org.xdi.oxauth.model.common.GrantType; | ||
import org.xdi.oxauth.model.common.Prompt; | ||
import org.xdi.oxauth.model.common.ResponseType; | ||
import org.xdi.oxauth.model.register.ApplicationType; | ||
import org.xdi.oxauth.model.util.StringUtils; | ||
|
||
import java.util.Arrays; | ||
import java.util.List; | ||
import java.util.UUID; | ||
|
||
import static org.testng.Assert.assertEquals; | ||
import static org.testng.Assert.assertNotNull; | ||
|
||
/** | ||
* @author Javier Rojas Blum | ||
* @version October 16, 2015 | ||
*/ | ||
public class PersistClientAuthorizationsHttpTest extends BaseTest { | ||
|
||
@Parameters({"userId", "userSecret", "redirectUris", "redirectUri"}) | ||
@Test | ||
public void persistentClientAuthorizations(final String userId, final String userSecret, | ||
final String redirectUris, final String redirectUri) throws Exception { | ||
showTitle("persistentClientAuthorizations"); | ||
|
||
List<ResponseType> responseTypes = Arrays.asList(ResponseType.CODE, ResponseType.ID_TOKEN); | ||
|
||
// 1. Register client | ||
RegisterRequest registerRequest = new RegisterRequest(ApplicationType.WEB, "oxAuth test app", | ||
StringUtils.spaceSeparatedToList(redirectUris)); | ||
registerRequest.setResponseTypes(responseTypes); | ||
|
||
RegisterClient registerClient = new RegisterClient(registrationEndpoint); | ||
registerClient.setRequest(registerRequest); | ||
RegisterResponse registerResponse = registerClient.exec(); | ||
|
||
showClient(registerClient); | ||
assertEquals(registerResponse.getStatus(), 200, "Unexpected response code: " + registerResponse.getEntity()); | ||
assertNotNull(registerResponse.getClientId()); | ||
assertNotNull(registerResponse.getClientSecret()); | ||
assertNotNull(registerResponse.getRegistrationAccessToken()); | ||
assertNotNull(registerResponse.getClientIdIssuedAt()); | ||
assertNotNull(registerResponse.getClientSecretExpiresAt()); | ||
|
||
String clientId = registerResponse.getClientId(); | ||
String clientSecret = registerResponse.getClientSecret(); | ||
|
||
String sessionId = null; | ||
{ | ||
// 2. Request authorization | ||
List<String> scopes = Arrays.asList("openid", "profile"); | ||
String nonce = UUID.randomUUID().toString(); | ||
String state = UUID.randomUUID().toString(); | ||
|
||
AuthorizationRequest authorizationRequest = new AuthorizationRequest(responseTypes, clientId, scopes, redirectUri, nonce); | ||
authorizationRequest.setState(state); | ||
|
||
AuthorizationResponse authorizationResponse = authenticateResourceOwnerAndGrantAccess( | ||
authorizationEndpoint, authorizationRequest, userId, userSecret); | ||
|
||
assertNotNull(authorizationResponse.getLocation()); | ||
assertNotNull(authorizationResponse.getCode()); | ||
assertNotNull(authorizationResponse.getIdToken()); | ||
assertNotNull(authorizationResponse.getState()); | ||
|
||
String authorizationCode = authorizationResponse.getCode(); | ||
sessionId = authorizationResponse.getSessionId(); | ||
|
||
// 3. Request access token using the authorization code. | ||
TokenRequest tokenRequest = new TokenRequest(GrantType.AUTHORIZATION_CODE); | ||
tokenRequest.setCode(authorizationCode); | ||
tokenRequest.setRedirectUri(redirectUri); | ||
tokenRequest.setAuthUsername(clientId); | ||
tokenRequest.setAuthPassword(clientSecret); | ||
tokenRequest.setAuthenticationMethod(AuthenticationMethod.CLIENT_SECRET_BASIC); | ||
|
||
TokenClient tokenClient = new TokenClient(tokenEndpoint); | ||
tokenClient.setRequest(tokenRequest); | ||
TokenResponse tokenResponse = tokenClient.exec(); | ||
|
||
showClient(tokenClient); | ||
assertEquals(tokenResponse.getStatus(), 200, "Unexpected response code: " + tokenResponse.getStatus()); | ||
assertNotNull(tokenResponse.getEntity()); | ||
assertNotNull(tokenResponse.getAccessToken()); | ||
assertNotNull(tokenResponse.getExpiresIn()); | ||
assertNotNull(tokenResponse.getTokenType()); | ||
assertNotNull(tokenResponse.getRefreshToken()); | ||
} | ||
|
||
{ | ||
// 4. Request authorization | ||
List<String> scopes = Arrays.asList("openid", "address", "email"); | ||
String nonce = UUID.randomUUID().toString(); | ||
String state = UUID.randomUUID().toString(); | ||
|
||
AuthorizationRequest authorizationRequest = new AuthorizationRequest(responseTypes, clientId, scopes, redirectUri, nonce); | ||
authorizationRequest.setState(state); | ||
|
||
AuthorizationResponse authorizationResponse = authenticateResourceOwnerAndGrantAccess( | ||
authorizationEndpoint, authorizationRequest, userId, userSecret); | ||
|
||
assertNotNull(authorizationResponse.getLocation()); | ||
assertNotNull(authorizationResponse.getCode()); | ||
assertNotNull(authorizationResponse.getIdToken()); | ||
assertNotNull(authorizationResponse.getState()); | ||
|
||
String authorizationCode = authorizationResponse.getCode(); | ||
|
||
// 5. Request access token using the authorization code. | ||
TokenRequest tokenRequest = new TokenRequest(GrantType.AUTHORIZATION_CODE); | ||
tokenRequest.setCode(authorizationCode); | ||
tokenRequest.setRedirectUri(redirectUri); | ||
tokenRequest.setAuthUsername(clientId); | ||
tokenRequest.setAuthPassword(clientSecret); | ||
tokenRequest.setAuthenticationMethod(AuthenticationMethod.CLIENT_SECRET_BASIC); | ||
|
||
TokenClient tokenClient = new TokenClient(tokenEndpoint); | ||
tokenClient.setRequest(tokenRequest); | ||
TokenResponse tokenResponse = tokenClient.exec(); | ||
|
||
showClient(tokenClient); | ||
assertEquals(tokenResponse.getStatus(), 200, "Unexpected response code: " + tokenResponse.getStatus()); | ||
assertNotNull(tokenResponse.getEntity()); | ||
assertNotNull(tokenResponse.getAccessToken()); | ||
assertNotNull(tokenResponse.getExpiresIn()); | ||
assertNotNull(tokenResponse.getTokenType()); | ||
assertNotNull(tokenResponse.getRefreshToken()); | ||
} | ||
|
||
{ | ||
// 6. Request authorization | ||
List<String> scopes = Arrays.asList("openid", "profile", "address", "email"); | ||
String nonce = UUID.randomUUID().toString(); | ||
String state = UUID.randomUUID().toString(); | ||
|
||
AuthorizationRequest authorizationRequest = new AuthorizationRequest(responseTypes, clientId, scopes, redirectUri, nonce); | ||
authorizationRequest.setState(state); | ||
authorizationRequest.getPrompts().add(Prompt.NONE); | ||
authorizationRequest.setSessionId(sessionId); | ||
|
||
AuthorizeClient authorizeClient = new AuthorizeClient(authorizationEndpoint); | ||
authorizeClient.setRequest(authorizationRequest); | ||
|
||
AuthorizationResponse authorizationResponse = authorizeClient.exec(); | ||
|
||
assertNotNull(authorizationResponse.getLocation()); | ||
assertNotNull(authorizationResponse.getCode()); | ||
assertNotNull(authorizationResponse.getState()); | ||
assertNotNull(authorizationResponse.getScope()); | ||
|
||
String authorizationCode = authorizationResponse.getCode(); | ||
|
||
// 7. Get Access Token | ||
TokenRequest tokenRequest = new TokenRequest(GrantType.AUTHORIZATION_CODE); | ||
tokenRequest.setCode(authorizationCode); | ||
tokenRequest.setRedirectUri(redirectUri); | ||
tokenRequest.setAuthUsername(clientId); | ||
tokenRequest.setAuthPassword(clientSecret); | ||
tokenRequest.setAuthenticationMethod(AuthenticationMethod.CLIENT_SECRET_BASIC); | ||
|
||
TokenClient tokenClient = new TokenClient(tokenEndpoint); | ||
tokenClient.setRequest(tokenRequest); | ||
TokenResponse tokenResponse = tokenClient.exec(); | ||
|
||
showClient(tokenClient); | ||
assertEquals(tokenResponse.getStatus(), 200, "Unexpected response code: " + tokenResponse.getStatus()); | ||
assertNotNull(tokenResponse.getEntity(), "The entity is null"); | ||
assertNotNull(tokenResponse.getAccessToken(), "The access token is null"); | ||
assertNotNull(tokenResponse.getExpiresIn(), "The expires in value is null"); | ||
assertNotNull(tokenResponse.getTokenType(), "The token type is null"); | ||
assertNotNull(tokenResponse.getRefreshToken(), "The refresh token is null"); | ||
} | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.