import { createTestingPinia } from '@pinia/testing' import { setActivePinia } from 'pinia' import { useOAuthStore } from 'src/stores/oauth.js' import { MASTODON_APP_URL, MASTODON_APP_VERIFY_URL, OAUTH_TOKEN_URL, } from 'src/api/oauth.js' const response = (data, extra = {}) => new Response(JSON.stringify(data), { headers: { 'Content-Type': 'application/json' }, ...extra, }) const defaultMockAppURL = () => { return response({ client_id: 'test-id', client_secret: 'test-secret', }) } const defaultMockAppVerifyURL = (headers) => { const authHeader = headers.Authorization if ( authHeader === 'Bearer test-app-token' || authHeader === 'Bearer also-good-app-token' ) { return response({}) } else { return response( { error: { detail: 'Internal server error' } }, { status: 400 }, ) } } const defaultMockOAuthTokenURL = (params) => { const data = params.body if ( data.get('client_id') === 'test-id' && data.get('client_secret') === 'test-secret' && data.get('grant_type') === 'client_credentials' && data.has('redirect_uri') ) { return response({ access_token: 'test-app-token' }) } else { // Pleroma 2.9.0 gives the following respoonse upon error return response({ error: 'Invalid credentials' }, { status: 400 }) } } const authApis = ({ mockAppURL, mockAppVerifyURL, mockOAuthTokenURL } = {}) => { const mockFetch = vi.fn().mockImplementation((url, params) => { const { method = 'GET', headers } = params if (url === MASTODON_APP_URL && method === 'POST') { return (mockAppURL ?? defaultMockAppURL)() } else if (url === MASTODON_APP_VERIFY_URL && method === 'GET') { return (mockAppVerifyURL ?? defaultMockAppVerifyURL)(headers) } else if (url === OAUTH_TOKEN_URL && method === 'POST') { return (mockOAuthTokenURL ?? defaultMockOAuthTokenURL)(params) } else { return response({ error: 'Invalid request for test' }, { status: 401 }) } }) vi.stubGlobal('fetch', mockFetch) return mockFetch } describe('oauth store', () => { beforeEach(() => { setActivePinia(createTestingPinia({ stubActions: false })) }) describe('createApp', () => { it('should use create an app and record client id and secret', async () => { authApis() const store = useOAuthStore() const app = await store.createApp() expect(store.clientId).to.eql('test-id') expect(store.clientSecret).to.eql('test-secret') expect(app.clientId).to.eql('test-id') expect(app.clientSecret).to.eql('test-secret') }) it('should throw and not update if failed', async () => { const mockFetch = authApis() mockFetch.mockResolvedValueOnce( new Response('Throttled', { status: 429, statusText: 'Throttled', headers: { 'Content-Type': 'text/plain' }, }), ) const store = useOAuthStore() const res = store.createApp() await expect(res).rejects.toThrowError('Throttled') expect(store.clientId).to.eql(false) expect(store.clientSecret).to.eql(false) }) }) describe('ensureApp', () => { it('should create an app if it does not exist', async () => { authApis() const store = useOAuthStore() const app = await store.ensureApp() expect(store.clientId).to.eql('test-id') expect(store.clientSecret).to.eql('test-secret') expect(app.clientId).to.eql('test-id') expect(app.clientSecret).to.eql('test-secret') }) it('should not create an app if it exists', async () => { authApis({ mockAppURL: () => new Response('Throttled', { status: 429, statusText: 'Throttled', headers: { 'Content-Type': 'text/plain' }, }), }) const store = useOAuthStore() store.clientId = 'another-id' store.clientSecret = 'another-secret' const app = await store.ensureApp() expect(store.clientId).to.eql('another-id') expect(store.clientSecret).to.eql('another-secret') expect(app.clientId).to.eql('another-id') expect(app.clientSecret).to.eql('another-secret') }) }) describe('getAppToken', () => { it('should get app token and set it in state', async () => { authApis() const store = useOAuthStore() store.clientId = 'test-id' store.clientSecret = 'test-secret' const token = await store.getAppToken() expect(token).to.eql('test-app-token') expect(store.appToken).to.eql('test-app-token') }) it('should throw and not set state if it cannot get app token', async () => { authApis() const store = useOAuthStore() store.clientId = 'bad-id' store.clientSecret = 'bad-secret' await expect(store.getAppToken()).rejects.toThrowError('400') expect(store.appToken).to.eql(false) }) }) describe('ensureAppToken', () => { it('should work if the state is empty', async () => { authApis() const store = useOAuthStore() const token = await store.ensureAppToken() expect(token).to.eql('test-app-token') expect(store.appToken).to.eql('test-app-token') }) it('should work if we already have a working token', async () => { authApis() const store = useOAuthStore() store.appToken = 'also-good-app-token' const token = await store.ensureAppToken() expect(token).to.eql('also-good-app-token') expect(store.appToken).to.eql('also-good-app-token') }) it('should work if we have a bad token but good app credentials', async () => { authApis({ mockAppURL: () => new Response('Should not call this API', { status: 400, statusText: 'Should not call this API', headers: { 'Content-Type': 'text/plain' }, }), }) const store = useOAuthStore() store.appToken = 'bad-app-token' store.clientId = 'test-id' store.clientSecret = 'test-secret' const token = await store.ensureAppToken() expect(token).to.eql('test-app-token') expect(store.appToken).to.eql('test-app-token') }) it('should work if we have no token but good app credentials', async () => { authApis({ mockAppURL: () => new Response('Should not call this API', { status: 400, statusText: 'Should not call this API', headers: { 'Content-Type': 'text/plain' }, }), }) const store = useOAuthStore() store.clientId = 'test-id' store.clientSecret = 'test-secret' const token = await store.ensureAppToken() expect(token).to.eql('test-app-token') expect(store.appToken).to.eql('test-app-token') }) it('should work if we have no token and bad app credentials', async () => { authApis() const store = useOAuthStore() store.clientId = 'bad-id' store.clientSecret = 'bad-secret' const token = await store.ensureAppToken() expect(token).to.eql('test-app-token') expect(store.appToken).to.eql('test-app-token') expect(store.clientId).to.eql('test-id') expect(store.clientSecret).to.eql('test-secret') }) it('should work if we have bad token and bad app credentials', async () => { authApis() const store = useOAuthStore() store.appToken = 'bad-app-token' store.clientId = 'bad-id' store.clientSecret = 'bad-secret' const token = await store.ensureAppToken() expect(token).to.eql('test-app-token') expect(store.appToken).to.eql('test-app-token') expect(store.clientId).to.eql('test-id') expect(store.clientSecret).to.eql('test-secret') }) it('should throw if we cannot create an app', async () => { authApis({ mockAppURL: () => new Response('Throttled', { status: 429, statusText: 'Throttled', headers: { 'Content-Type': 'text/plain' }, }), }) const store = useOAuthStore() await expect(store.ensureAppToken()).rejects.toThrowError('Throttled') }) it('should throw if we cannot obtain app token', async () => { authApis({ mockOAuthTokenURL: () => new Response('Throttled', { status: 429, statusText: 'Throttled', headers: { 'Content-Type': 'text/plain' }, }), }) const store = useOAuthStore() await expect(store.getAppToken()).rejects.toThrowError('Throttled') }) }) })