forked from alterminal/alterminal
fixup
This commit is contained in:
@@ -420,3 +420,62 @@ func TestApplicationPersistence(t *testing.T) {
|
||||
t.Errorf("查無 client_id 應回 gorm.ErrRecordNotFound,得到 %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPostLogoutRedirectURIs(t *testing.T) {
|
||||
t.Run("註冊並精確比對", func(t *testing.T) {
|
||||
a, _, err := NewApplication("示範應用", ClientConfidential,
|
||||
[]string{"https://app.example.com/cb"}, nil, "",
|
||||
"https://app.example.com/logged-out")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !a.PostLogoutRedirectURIs.Contains("https://app.example.com/logged-out") {
|
||||
t.Error("註冊的登出後返回 URI 應精確比對成功")
|
||||
}
|
||||
// 與 redirect URI 不互通(RP-Initiated Logout 1.0 §3:僅比對
|
||||
// post_logout_redirect_uris 註冊值)。
|
||||
if a.PostLogoutRedirectURIs.Contains("https://app.example.com/cb") {
|
||||
t.Error("redirect URI 不應混入登出後返回 URI 的比對")
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("未註冊時為非 nil 空清單", func(t *testing.T) {
|
||||
a, _, err := NewApplication("無返回", ClientConfidential,
|
||||
[]string{"https://app.example.com/cb"}, nil, "")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if a.PostLogoutRedirectURIs == nil || len(a.PostLogoutRedirectURIs) != 0 {
|
||||
t.Errorf("未指定應為非 nil 空清單(序列化為 []),得到 %v", a.PostLogoutRedirectURIs)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("格式驗證與 redirect URI 同規則", func(t *testing.T) {
|
||||
if _, _, err := NewApplication("示範應用", ClientConfidential,
|
||||
[]string{"https://app.example.com/cb"}, nil, "",
|
||||
"http://app.example.com/logged-out"); err == nil {
|
||||
t.Error("非 loopback 的 http 登出後返回 URI 應被拒")
|
||||
}
|
||||
if _, _, err := NewApplication("示範應用", ClientConfidential,
|
||||
[]string{"https://app.example.com/cb"}, nil, "",
|
||||
"https://app.example.com/logged-out#frag"); err == nil {
|
||||
t.Error("含 fragment 的登出後返回 URI 應被拒")
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("Update 可清空", func(t *testing.T) {
|
||||
a, _, err := NewApplication("示範應用", ClientConfidential,
|
||||
[]string{"https://app.example.com/cb"}, nil, "",
|
||||
"https://app.example.com/logged-out")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := a.Update("示範應用", ClientConfidential,
|
||||
[]string{"https://app.example.com/cb"}, nil, ""); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(a.PostLogoutRedirectURIs) != 0 {
|
||||
t.Errorf("Update 未指定時應清空,得到 %v", a.PostLogoutRedirectURIs)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user