|
17 | 17 | package smoketest.oauth2.server;
|
18 | 18 |
|
19 | 19 | import java.net.URI;
|
| 20 | +import java.util.List; |
20 | 21 | import java.util.Map;
|
21 | 22 | import java.util.Objects;
|
22 | 23 |
|
|
31 | 32 | import org.springframework.http.HttpHeaders;
|
32 | 33 | import org.springframework.http.HttpMethod;
|
33 | 34 | import org.springframework.http.HttpStatus;
|
| 35 | +import org.springframework.http.MediaType; |
34 | 36 | import org.springframework.http.ResponseEntity;
|
35 | 37 | import org.springframework.security.oauth2.core.AuthorizationGrantType;
|
36 | 38 | import org.springframework.security.oauth2.core.OAuth2AccessToken;
|
@@ -118,4 +120,49 @@ void validTokenRequestShouldReturnTokenResponse() {
|
118 | 120 | .isEqualTo(OAuth2AccessToken.TokenType.BEARER.getValue());
|
119 | 121 | }
|
120 | 122 |
|
| 123 | + @Test |
| 124 | + void anonymousTokenRequestShouldReturnUnauthorized() { |
| 125 | + HttpHeaders headers = new HttpHeaders(); |
| 126 | + HttpEntity<Object> request = new HttpEntity<>(headers); |
| 127 | + String requestUri = UriComponentsBuilder.fromUriString("/token") |
| 128 | + .queryParam(OAuth2ParameterNames.CLIENT_ID, "messaging-client") |
| 129 | + .queryParam(OAuth2ParameterNames.GRANT_TYPE, AuthorizationGrantType.CLIENT_CREDENTIALS.getValue()) |
| 130 | + .queryParam(OAuth2ParameterNames.SCOPE, "message.read+message.write") |
| 131 | + .toUriString(); |
| 132 | + ResponseEntity<Map<String, Object>> entity = this.restTemplate.exchange(requestUri, HttpMethod.POST, request, |
| 133 | + MAP_TYPE_REFERENCE); |
| 134 | + assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.UNAUTHORIZED); |
| 135 | + } |
| 136 | + |
| 137 | + @Test |
| 138 | + void anonymousTokenRequestWithAcceptHeaderAllShouldReturnUnauthorized() { |
| 139 | + HttpHeaders headers = new HttpHeaders(); |
| 140 | + headers.setAccept(List.of(MediaType.ALL)); |
| 141 | + HttpEntity<Object> request = new HttpEntity<>(headers); |
| 142 | + String requestUri = UriComponentsBuilder.fromUriString("/token") |
| 143 | + .queryParam(OAuth2ParameterNames.CLIENT_ID, "messaging-client") |
| 144 | + .queryParam(OAuth2ParameterNames.GRANT_TYPE, AuthorizationGrantType.CLIENT_CREDENTIALS.getValue()) |
| 145 | + .queryParam(OAuth2ParameterNames.SCOPE, "message.read+message.write") |
| 146 | + .toUriString(); |
| 147 | + ResponseEntity<Map<String, Object>> entity = this.restTemplate.exchange(requestUri, HttpMethod.POST, request, |
| 148 | + MAP_TYPE_REFERENCE); |
| 149 | + assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.UNAUTHORIZED); |
| 150 | + } |
| 151 | + |
| 152 | + @Test |
| 153 | + void anonymousTokenRequestWithAcceptHeaderTextHtmlShouldRedirectToLogin() { |
| 154 | + HttpHeaders headers = new HttpHeaders(); |
| 155 | + headers.setAccept(List.of(MediaType.TEXT_HTML)); |
| 156 | + HttpEntity<Object> request = new HttpEntity<>(headers); |
| 157 | + String requestUri = UriComponentsBuilder.fromUriString("/token") |
| 158 | + .queryParam(OAuth2ParameterNames.CLIENT_ID, "messaging-client") |
| 159 | + .queryParam(OAuth2ParameterNames.GRANT_TYPE, AuthorizationGrantType.CLIENT_CREDENTIALS.getValue()) |
| 160 | + .queryParam(OAuth2ParameterNames.SCOPE, "message.read+message.write") |
| 161 | + .toUriString(); |
| 162 | + ResponseEntity<Map<String, Object>> entity = this.restTemplate.exchange(requestUri, HttpMethod.POST, request, |
| 163 | + MAP_TYPE_REFERENCE); |
| 164 | + assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.FOUND); |
| 165 | + assertThat(entity.getHeaders().getLocation()).isEqualTo(URI.create("http://localhost:" + this.port + "/login")); |
| 166 | + } |
| 167 | + |
121 | 168 | }
|
0 commit comments