|
| 1 | +from datetime import timedelta |
| 2 | + |
1 | 3 | from django.contrib.auth import get_user_model |
2 | | -from django.test import TestCase |
| 4 | +from django.test import TransactionTestCase |
| 5 | +from django.utils import timezone |
3 | 6 |
|
4 | 7 | import mock |
5 | 8 | from oauthlib.common import Request |
6 | 9 |
|
| 10 | +from ..exceptions import FatalClientError |
7 | 11 | from ..oauth2_validators import OAuth2Validator |
8 | | -from ..models import get_application_model |
| 12 | +from ..models import get_application_model, AccessToken, RefreshToken |
9 | 13 |
|
10 | 14 | UserModel = get_user_model() |
11 | 15 | AppModel = get_application_model() |
12 | 16 |
|
13 | 17 |
|
14 | | -class TestOAuth2Validator(TestCase): |
| 18 | +class TestOAuth2Validator(TransactionTestCase): |
15 | 19 | def setUp(self): |
16 | 20 | self.user = UserModel.objects.create_user("user", "test@user.com", "123456") |
17 | 21 | self.request = mock.MagicMock(wraps=Request) |
18 | | - self.request.client = None |
| 22 | + self.request.user = self.user |
| 23 | + self.request.grant_type = "not client" |
19 | 24 | self.validator = OAuth2Validator() |
20 | 25 | self.application = AppModel.objects.create( |
21 | 26 | client_id='client_id', client_secret='client_secret', user=self.user, |
22 | 27 | client_type=AppModel.CLIENT_PUBLIC, authorization_grant_type=AppModel.GRANT_PASSWORD) |
| 28 | + self.request.client = self.application |
23 | 29 |
|
24 | 30 | def tearDown(self): |
25 | 31 | self.application.delete() |
@@ -108,3 +114,129 @@ def test_client_authentication_required(self): |
108 | 114 |
|
109 | 115 | def test_load_application_fails_when_request_has_no_client(self): |
110 | 116 | self.assertRaises(AssertionError, self.validator.authenticate_client_id, 'client_id', {}) |
| 117 | + |
| 118 | + def test_rotate_refresh_token__is_true(self): |
| 119 | + self.assertTrue(self.validator.rotate_refresh_token(mock.MagicMock())) |
| 120 | + |
| 121 | + def test_save_bearer_token__without_user__raises_fatal_client(self): |
| 122 | + token = {} |
| 123 | + |
| 124 | + with self.assertRaises(FatalClientError): |
| 125 | + self.validator.save_bearer_token(token, mock.MagicMock()) |
| 126 | + |
| 127 | + def test_save_bearer_token__with_existing_tokens__does_not_create_new_tokens(self): |
| 128 | + |
| 129 | + rotate_token_function = mock.MagicMock() |
| 130 | + rotate_token_function.return_value = False |
| 131 | + self.validator.rotate_refresh_token = rotate_token_function |
| 132 | + |
| 133 | + access_token = AccessToken.objects.create( |
| 134 | + token="123", |
| 135 | + user=self.user, |
| 136 | + expires=timezone.now() + timedelta(seconds=60), |
| 137 | + application=self.application |
| 138 | + ) |
| 139 | + refresh_token = RefreshToken.objects.create( |
| 140 | + access_token=access_token, |
| 141 | + token="abc", |
| 142 | + user=self.user, |
| 143 | + application=self.application |
| 144 | + ) |
| 145 | + self.request.refresh_token_instance = refresh_token |
| 146 | + token = { |
| 147 | + "scope": "foo bar", |
| 148 | + "refresh_token": "abc", |
| 149 | + "access_token": "123", |
| 150 | + } |
| 151 | + |
| 152 | + self.assertEqual(1, RefreshToken.objects.count()) |
| 153 | + self.assertEqual(1, AccessToken.objects.count()) |
| 154 | + |
| 155 | + self.validator.save_bearer_token(token, self.request) |
| 156 | + |
| 157 | + self.assertEqual(1, RefreshToken.objects.count()) |
| 158 | + self.assertEqual(1, AccessToken.objects.count()) |
| 159 | + |
| 160 | + def test_save_bearer_token__checks_to_rotate_tokens(self): |
| 161 | + |
| 162 | + rotate_token_function = mock.MagicMock() |
| 163 | + rotate_token_function.return_value = False |
| 164 | + self.validator.rotate_refresh_token = rotate_token_function |
| 165 | + |
| 166 | + access_token = AccessToken.objects.create( |
| 167 | + token="123", |
| 168 | + user=self.user, |
| 169 | + expires=timezone.now() + timedelta(seconds=60), |
| 170 | + application=self.application |
| 171 | + ) |
| 172 | + refresh_token = RefreshToken.objects.create( |
| 173 | + access_token=access_token, |
| 174 | + token="abc", |
| 175 | + user=self.user, |
| 176 | + application=self.application |
| 177 | + ) |
| 178 | + self.request.refresh_token_instance = refresh_token |
| 179 | + token = { |
| 180 | + "scope": "foo bar", |
| 181 | + "refresh_token": "abc", |
| 182 | + "access_token": "123", |
| 183 | + } |
| 184 | + |
| 185 | + self.validator.save_bearer_token(token, self.request) |
| 186 | + rotate_token_function.assert_called_once_with(self.request) |
| 187 | + |
| 188 | + def test_save_bearer_token__with_new_token__creates_new_tokens(self): |
| 189 | + token = { |
| 190 | + "scope": "foo bar", |
| 191 | + "refresh_token": "abc", |
| 192 | + "access_token": "123", |
| 193 | + } |
| 194 | + |
| 195 | + self.assertEqual(0, RefreshToken.objects.count()) |
| 196 | + self.assertEqual(0, AccessToken.objects.count()) |
| 197 | + |
| 198 | + self.validator.save_bearer_token(token, self.request) |
| 199 | + |
| 200 | + self.assertEqual(1, RefreshToken.objects.count()) |
| 201 | + self.assertEqual(1, AccessToken.objects.count()) |
| 202 | + |
| 203 | + def test_save_bearer_token__with_new_token_equal_to_existing_token__revokes_old_tokens(self): |
| 204 | + access_token = AccessToken.objects.create( |
| 205 | + token="123", |
| 206 | + user=self.user, |
| 207 | + expires=timezone.now() + timedelta(seconds=60), |
| 208 | + application=self.application |
| 209 | + ) |
| 210 | + refresh_token = RefreshToken.objects.create( |
| 211 | + access_token=access_token, |
| 212 | + token="abc", |
| 213 | + user=self.user, |
| 214 | + application=self.application |
| 215 | + ) |
| 216 | + |
| 217 | + self.request.refresh_token_instance = refresh_token |
| 218 | + |
| 219 | + token = { |
| 220 | + "scope": "foo bar", |
| 221 | + "refresh_token": "abc", |
| 222 | + "access_token": "123", |
| 223 | + } |
| 224 | + |
| 225 | + self.assertEqual(1, RefreshToken.objects.count()) |
| 226 | + self.assertEqual(1, AccessToken.objects.count()) |
| 227 | + |
| 228 | + self.validator.save_bearer_token(token, self.request) |
| 229 | + |
| 230 | + self.assertEqual(1, RefreshToken.objects.count()) |
| 231 | + self.assertEqual(1, AccessToken.objects.count()) |
| 232 | + |
| 233 | + def test_save_bearer_token__with_no_refresh_token__creates_new_access_token_only(self): |
| 234 | + token = { |
| 235 | + "scope": "foo bar", |
| 236 | + "access_token": "123", |
| 237 | + } |
| 238 | + |
| 239 | + self.validator.save_bearer_token(token, self.request) |
| 240 | + |
| 241 | + self.assertEqual(0, RefreshToken.objects.count()) |
| 242 | + self.assertEqual(1, AccessToken.objects.count()) |
0 commit comments