deno.land / x / oauth4webapi@v1.2.2 / tap / callback.ts
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223import type QUnit from 'qunit'import * as lib from '../src/index.js'
const client = <lib.Client>{ client_id: 'urn:example:client_id',}const identifier = 'https://op.example.com'const issuer = <lib.AuthorizationServer>{ issuer: identifier,}
export default (QUnit: QUnit) => { const { module, test } = QUnit module('callback.ts') test('validateAuthResponse()', (t) => { lib.validateAuthResponse( issuer, client, new URL('https://rp.example.com/cb?code=foo'), lib.expectNoState, ) lib.validateAuthResponse(issuer, client, new URL('https://rp.example.com/cb?code=foo')) lib.validateAuthResponse( issuer, client, new URL('https://rp.example.com/cb?code=foo&state=foo'), 'foo', ) lib.validateAuthResponse(issuer, client, new URLSearchParams('code=foo'), lib.expectNoState) lib.validateAuthResponse(issuer, client, new URLSearchParams('code=foo&state=foo'), 'foo') lib.validateAuthResponse( issuer, client, new URLSearchParams('code=foo&state=foo'), lib.skipStateCheck, )
t.true( lib.isOAuth2Error( lib.validateAuthResponse( issuer, client, new URLSearchParams('error=access_denied'), lib.expectNoState, ), ), )
t.false( lib.isOAuth2Error( lib.validateAuthResponse( issuer, client, new URLSearchParams('code=foo'), lib.expectNoState, ), ), ) })
test('validateAuthResponse() error conditions', (t) => { t.throws( () => lib.validateAuthResponse(issuer, client, <any>null, lib.expectNoState), (err: Error) => { t.propContains(err, { message: '"parameters" must be an instance of URLSearchParams, or URL', }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URL('https://rp.example.com/cb?response=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: '"parameters" contains a JARM response, use validateJwtAuthResponse() instead of validateAuthResponse()', }) return true }, ) t.throws( () => lib.validateAuthResponse( { ...issuer, authorization_response_iss_parameter_supported: true }, client, new URL('https://rp.example.com/cb?code=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: 'response parameter "iss" (issuer) missing' }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URL('https://rp.example.com/cb?code=foo&iss=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: 'unexpected "iss" (issuer) response parameter value' }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URL('https://rp.example.com/cb?code=foo&state=bar'), 'foo', ), (err: Error) => { t.propContains(err, { message: 'unexpected "state" response parameter value' }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URLSearchParams('code=foo&state=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: 'unexpected "state" response parameter encountered' }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URLSearchParams('code=foo&state=foo'), <any>null, ), (err: Error) => { t.propContains(err, { message: '"expectedState" must be a non-empty string' }) return true }, ) t.throws( () => lib.validateAuthResponse(issuer, client, new URLSearchParams('code=foo'), 'foo'), (err: Error) => { t.propContains(err, { message: 'response parameter "state" missing', }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URLSearchParams('code=foo&id_token=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: 'implicit and hybrid flows are not supported' }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URLSearchParams('code=foo&token=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: 'implicit and hybrid flows are not supported' }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URLSearchParams('id_token=foo&token=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: 'implicit and hybrid flows are not supported' }) return true }, ) t.throws( () => lib.validateAuthResponse( issuer, client, new URLSearchParams('code=foo&id_token=foo&token=foo'), lib.expectNoState, ), (err: Error) => { t.propContains(err, { message: 'implicit and hybrid flows are not supported' }) return true }, ) t.throws( () => lib.validateAuthResponse(issuer, client, new URLSearchParams('state=foo&state=foo'), 'foo'), (err: Error) => { t.propContains(err, { message: '"state" parameter must be provided only once' }) return true }, ) })}
Version Info