OAuth2ResourceServerApplicationITests.java 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124
  1. /*
  2. * Copyright 2002-2019 the original author or authors.
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * https://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. package sample;
  17. import org.junit.Test;
  18. import org.junit.runner.RunWith;
  19. import org.springframework.beans.factory.annotation.Autowired;
  20. import org.springframework.boot.test.autoconfigure.web.servlet.AutoConfigureMockMvc;
  21. import org.springframework.boot.test.context.SpringBootTest;
  22. import org.springframework.http.HttpHeaders;
  23. import org.springframework.mock.web.MockHttpServletRequest;
  24. import org.springframework.test.context.ActiveProfiles;
  25. import org.springframework.test.context.junit4.SpringRunner;
  26. import org.springframework.test.web.servlet.MockMvc;
  27. import org.springframework.test.web.servlet.request.RequestPostProcessor;
  28. import static org.hamcrest.Matchers.containsString;
  29. import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.get;
  30. import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.post;
  31. import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.content;
  32. import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.header;
  33. import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.status;
  34. /**
  35. * Integration tests for {@link OAuth2ResourceServerApplication}
  36. *
  37. * @author Josh Cummings
  38. */
  39. @RunWith(SpringRunner.class)
  40. @SpringBootTest
  41. @AutoConfigureMockMvc
  42. @ActiveProfiles("test")
  43. public class OAuth2ResourceServerApplicationITests {
  44. String noScopesToken = "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJzdWJqZWN0IiwiZXhwIjoyMTY0MjQ1ODgwLCJhdXRob3JpdGllcyI6WyJST0xFX1VTRVIiXSwianRpIjoiMDFkOThlZWEtNjc0MC00OGRlLTk4ODAtYzM5ZjgyMGZiNzVlIiwiY2xpZW50X2lkIjoibm9zY29wZXMiLCJzY29wZSI6WyJub25lIl19.VOzgGLOUuQ_R2Ur1Ke41VaobddhKgUZgto7Y3AGxst7SuxLQ4LgWwdSSDRx-jRvypjsCgYPbjAYLhn9nCbfwtCitkymUKUNKdebvVAI0y8YvliWTL5S-GiJD9dN8SSsXUla9A4xB_9Mt5JAlRpQotQSCLojVSKQmjhMpQWmYAlKVjnlImoRwQFPI4w3Ijn4G4EMTKWUYRfrD0-WNT9ZYWBeza6QgV6sraP7ToRB3eQLy2p04cU40X-RHLeYCsMBfxsMMh89CJff-9tn7VDKi1hAGc_Lp9yS9ZaItJuFJTjf8S_vsjVB1nBhvdS_6IED_m_fOU52KiGSO2qL6shxHvg";
  45. String messageReadToken = "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJzdWJqZWN0IiwiZXhwIjoyMTY0MjQ1NjQ4LCJhdXRob3JpdGllcyI6WyJST0xFX1VTRVIiXSwianRpIjoiY2I1ZGMwNDYtMDkyMi00ZGJmLWE5MzAtOGI2M2FhZTYzZjk2IiwiY2xpZW50X2lkIjoicmVhZGVyIiwic2NvcGUiOlsibWVzc2FnZTpyZWFkIl19.Pre2ksnMiOGYWQtuIgHB0i3uTnNzD0SMFM34iyQJHK5RLlSjge08s9qHdx6uv5cZ4gZm_cB1D6f4-fLx76bCblK6mVcabbR74w_eCdSBXNXuqG-HNrOYYmmx5iJtdwx5fXPmF8TyVzsq_LvRm_LN4lWNYquT4y36Tox6ZD3feYxXvHQ3XyZn9mVKnlzv-GCwkBohCR3yPow5uVmr04qh_al52VIwKMrvJBr44igr4fTZmzwRAZmQw5rZeyep0b4nsCjadNcndHtMtYKNVuG5zbDLsB7GGvilcI9TDDnUXtwthB_3iq32DAd9x8wJmJ5K8gmX6GjZFtYzKk_zEboXoQ";
  46. String messageWriteToken = "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJzdWJqZWN0IiwiZXhwIjoyMTY0MjQzOTA0LCJhdXRob3JpdGllcyI6WyJST0xFX1VTRVIiXSwianRpIjoiZGI4ZjgwMzQtM2VlNy00NjBjLTk3NTEtMDJiMDA1OWI5NzA4IiwiY2xpZW50X2lkIjoid3JpdGVyIiwic2NvcGUiOlsibWVzc2FnZTp3cml0ZSJdfQ.USvpx_ntKXtchLmc93auJq0qSav6vLm4B7ItPzhrDH2xmogBP35eKeklwXK5GCb7ck1aKJV5SpguBlTCz0bZC1zAWKB6gyFIqedALPAran5QR-8WpGfl0wFqds7d8Jw3xmpUUBduRLab9hkeAhgoVgxevc8d6ITM7kRnHo5wT3VzvBU8DquedVXm5fbBnRPgG4_jOWJKbqYpqaR2z2TnZRWh3CqL82Orh1Ww1dJYF_fae1dTVV4tvN5iSndYcGxMoBaiw3kRRi6EyNxnXnt1pFtZqc1f6D9x4AHiri8_vpBp2vwG5OfQD5-rrleP_XlIB3rNQT7tu3fiqu4vUzQaEg";
  47. @Autowired
  48. MockMvc mvc;
  49. @Test
  50. public void performWhenValidBearerTokenThenAllows()
  51. throws Exception {
  52. this.mvc.perform(get("/").with(bearerToken(this.noScopesToken)))
  53. .andExpect(status().isOk())
  54. .andExpect(content().string(containsString("Hello, subject!")));
  55. }
  56. // -- tests with scopes
  57. @Test
  58. public void performWhenValidBearerTokenThenScopedRequestsAlsoWork()
  59. throws Exception {
  60. this.mvc.perform(get("/message").with(bearerToken(this.messageReadToken)))
  61. .andExpect(status().isOk())
  62. .andExpect(content().string(containsString("secret message")));
  63. }
  64. @Test
  65. public void performWhenInsufficientlyScopedBearerTokenThenDeniesScopedMethodAccess()
  66. throws Exception {
  67. this.mvc.perform(get("/message").with(bearerToken(this.noScopesToken)))
  68. .andExpect(status().isForbidden())
  69. .andExpect(header().string(HttpHeaders.WWW_AUTHENTICATE,
  70. containsString("Bearer error=\"insufficient_scope\"")));
  71. }
  72. @Test
  73. public void performPostWhenValidBearerTokenThenScopedRequestsAlsoWork()
  74. throws Exception {
  75. this.mvc.perform(post("/message").content("example message")
  76. .with(bearerToken(this.messageWriteToken)))
  77. .andExpect(status().isOk())
  78. .andExpect(content().string(containsString("Message was created")));
  79. }
  80. @Test
  81. public void performPostWhenInsufficientlyScopedBearerTokenThenDeniesScopedMethodAccess()
  82. throws Exception {
  83. this.mvc.perform(post("/message").content("Example message")
  84. .with(bearerToken(this.messageReadToken)))
  85. .andExpect(status().isForbidden())
  86. .andExpect(header().string(HttpHeaders.WWW_AUTHENTICATE,
  87. containsString("Bearer error=\"insufficient_scope\"")));
  88. }
  89. private static class BearerTokenRequestPostProcessor implements RequestPostProcessor {
  90. private String token;
  91. BearerTokenRequestPostProcessor(String token) {
  92. this.token = token;
  93. }
  94. @Override
  95. public MockHttpServletRequest postProcessRequest(MockHttpServletRequest request) {
  96. request.addHeader("Authorization", "Bearer " + this.token);
  97. return request;
  98. }
  99. }
  100. private static BearerTokenRequestPostProcessor bearerToken(String token) {
  101. return new BearerTokenRequestPostProcessor(token);
  102. }
  103. }