pleroma-fe/test/unit/specs/stores/oauth.spec.js
2026-09-04 16:08:47 +03:00

278 lines
8.4 KiB
JavaScript

import { createTestingPinia } from '@pinia/testing'
import { setActivePinia } from 'pinia'
import { useOAuthStore } from 'src/stores/oauth.js'
import {
MASTODON_APP_URL,
MASTODON_APP_VERIFY_URL,
OAUTH_TOKEN_URL,
} from 'src/api/oauth.js'
const response = (data, extra = {}) =>
new Response(JSON.stringify(data), {
headers: { 'Content-Type': 'application/json' },
...extra,
})
const defaultMockAppURL = () => {
return response({
client_id: 'test-id',
client_secret: 'test-secret',
})
}
const defaultMockAppVerifyURL = (headers) => {
const authHeader = headers.Authorization
if (
authHeader === 'Bearer test-app-token' ||
authHeader === 'Bearer also-good-app-token'
) {
return response({})
} else {
return response(
{ error: { detail: 'Internal server error' } },
{ status: 400 },
)
}
}
const defaultMockOAuthTokenURL = (params) => {
const data = params.body
if (
data.get('client_id') === 'test-id' &&
data.get('client_secret') === 'test-secret' &&
data.get('grant_type') === 'client_credentials' &&
data.has('redirect_uri')
) {
return response({ access_token: 'test-app-token' })
} else {
// Pleroma 2.9.0 gives the following respoonse upon error
return response({ error: 'Invalid credentials' }, { status: 400 })
}
}
const authApis = ({ mockAppURL, mockAppVerifyURL, mockOAuthTokenURL } = {}) => {
const mockFetch = vi.fn().mockImplementation((url, params) => {
const { method = 'GET', headers } = params
if (url === MASTODON_APP_URL && method === 'POST') {
return (mockAppURL ?? defaultMockAppURL)()
} else if (url === MASTODON_APP_VERIFY_URL && method === 'GET') {
return (mockAppVerifyURL ?? defaultMockAppVerifyURL)(headers)
} else if (url === OAUTH_TOKEN_URL && method === 'POST') {
return (mockOAuthTokenURL ?? defaultMockOAuthTokenURL)(params)
} else {
return response({ error: 'Invalid request for test' }, { status: 401 })
}
})
vi.stubGlobal('fetch', mockFetch)
return mockFetch
}
describe('oauth store', () => {
beforeEach(() => {
setActivePinia(createTestingPinia({ stubActions: false }))
})
describe('createApp', () => {
it('should use create an app and record client id and secret', async () => {
authApis()
const store = useOAuthStore()
const app = await store.createApp()
expect(store.clientId).to.eql('test-id')
expect(store.clientSecret).to.eql('test-secret')
expect(app.clientId).to.eql('test-id')
expect(app.clientSecret).to.eql('test-secret')
})
it('should throw and not update if failed', async () => {
const mockFetch = authApis()
mockFetch.mockResolvedValueOnce(
new Response('Throttled', {
status: 429,
statusText: 'Throttled',
headers: { 'Content-Type': 'text/plain' },
}),
)
const store = useOAuthStore()
const res = store.createApp()
await expect(res).rejects.toThrowError('Throttled')
expect(store.clientId).to.eql(false)
expect(store.clientSecret).to.eql(false)
})
})
describe('ensureApp', () => {
it('should create an app if it does not exist', async () => {
authApis()
const store = useOAuthStore()
const app = await store.ensureApp()
expect(store.clientId).to.eql('test-id')
expect(store.clientSecret).to.eql('test-secret')
expect(app.clientId).to.eql('test-id')
expect(app.clientSecret).to.eql('test-secret')
})
it('should not create an app if it exists', async () => {
authApis({
mockAppURL: () =>
new Response('Throttled', {
status: 429,
statusText: 'Throttled',
headers: { 'Content-Type': 'text/plain' },
}),
})
const store = useOAuthStore()
store.clientId = 'another-id'
store.clientSecret = 'another-secret'
const app = await store.ensureApp()
expect(store.clientId).to.eql('another-id')
expect(store.clientSecret).to.eql('another-secret')
expect(app.clientId).to.eql('another-id')
expect(app.clientSecret).to.eql('another-secret')
})
})
describe('getAppToken', () => {
it('should get app token and set it in state', async () => {
authApis()
const store = useOAuthStore()
store.clientId = 'test-id'
store.clientSecret = 'test-secret'
const token = await store.getAppToken()
expect(token).to.eql('test-app-token')
expect(store.appToken).to.eql('test-app-token')
})
it('should throw and not set state if it cannot get app token', async () => {
authApis()
const store = useOAuthStore()
store.clientId = 'bad-id'
store.clientSecret = 'bad-secret'
await expect(store.getAppToken()).rejects.toThrowError('400')
expect(store.appToken).to.eql(false)
})
})
describe('ensureAppToken', () => {
it('should work if the state is empty', async () => {
authApis()
const store = useOAuthStore()
const token = await store.ensureAppToken()
expect(token).to.eql('test-app-token')
expect(store.appToken).to.eql('test-app-token')
})
it('should work if we already have a working token', async () => {
authApis()
const store = useOAuthStore()
store.appToken = 'also-good-app-token'
const token = await store.ensureAppToken()
expect(token).to.eql('also-good-app-token')
expect(store.appToken).to.eql('also-good-app-token')
})
it('should work if we have a bad token but good app credentials', async () => {
authApis({
mockAppURL: () =>
new Response('Should not call this API', {
status: 400,
statusText: 'Should not call this API',
headers: { 'Content-Type': 'text/plain' },
}),
})
const store = useOAuthStore()
store.appToken = 'bad-app-token'
store.clientId = 'test-id'
store.clientSecret = 'test-secret'
const token = await store.ensureAppToken()
expect(token).to.eql('test-app-token')
expect(store.appToken).to.eql('test-app-token')
})
it('should work if we have no token but good app credentials', async () => {
authApis({
mockAppURL: () =>
new Response('Should not call this API', {
status: 400,
statusText: 'Should not call this API',
headers: { 'Content-Type': 'text/plain' },
}),
})
const store = useOAuthStore()
store.clientId = 'test-id'
store.clientSecret = 'test-secret'
const token = await store.ensureAppToken()
expect(token).to.eql('test-app-token')
expect(store.appToken).to.eql('test-app-token')
})
it('should work if we have no token and bad app credentials', async () => {
authApis()
const store = useOAuthStore()
store.clientId = 'bad-id'
store.clientSecret = 'bad-secret'
const token = await store.ensureAppToken()
expect(token).to.eql('test-app-token')
expect(store.appToken).to.eql('test-app-token')
expect(store.clientId).to.eql('test-id')
expect(store.clientSecret).to.eql('test-secret')
})
it('should work if we have bad token and bad app credentials', async () => {
authApis()
const store = useOAuthStore()
store.appToken = 'bad-app-token'
store.clientId = 'bad-id'
store.clientSecret = 'bad-secret'
const token = await store.ensureAppToken()
expect(token).to.eql('test-app-token')
expect(store.appToken).to.eql('test-app-token')
expect(store.clientId).to.eql('test-id')
expect(store.clientSecret).to.eql('test-secret')
})
it('should throw if we cannot create an app', async () => {
authApis({
mockAppURL: () =>
new Response('Throttled', {
status: 429,
statusText: 'Throttled',
headers: { 'Content-Type': 'text/plain' },
}),
})
const store = useOAuthStore()
await expect(store.ensureAppToken()).rejects.toThrowError('Throttled')
})
it('should throw if we cannot obtain app token', async () => {
authApis({
mockOAuthTokenURL: () =>
new Response('Throttled', {
status: 429,
statusText: 'Throttled',
headers: { 'Content-Type': 'text/plain' },
}),
})
const store = useOAuthStore()
await expect(store.getAppToken()).rejects.toThrowError('Throttled')
})
})
})