(t *testing.T)
| 160 | } |
| 161 | |
| 162 | func TestAuthenticationSuccessScopeError(t *testing.T) { |
| 163 | auth := NewAuthorizer(&tokenIntrospectedSuccessful{&IntrospectResponse{ |
| 164 | Active: true, |
| 165 | Scope: "ABC DEF DFE", |
| 166 | ClientID: "ClientId", |
| 167 | UserID: "UserId", |
| 168 | }}, &Config{}).WithScope("DE") |
| 169 | |
| 170 | w := httptest.NewRecorder() |
| 171 | r := httptest.NewRequest("GET", "/", nil) |
| 172 | r.Header.Add("Authorization", "Bearer bearer") |
| 173 | |
| 174 | _, b := auth.Authorize(r, w) |
| 175 | |
| 176 | resp := w.Result() |
| 177 | body, err := io.ReadAll(resp.Body) |
| 178 | defer resp.Body.Close() |
| 179 | if err != nil { |
| 180 | t.Fatal(err) |
| 181 | } |
| 182 | if b { |
| 183 | t.Errorf("Expected error in Authentication, but was succesfull with code %d and body %v", resp.StatusCode, string(body)) |
| 184 | } |
| 185 | if got, ex := w.Code, http.StatusForbidden; got != ex { |
| 186 | t.Errorf("Expected status code %d, got %d", ex, got) |
| 187 | } |
| 188 | if got, ex := string(body), "Forbidden - requires scope \"DE\"\n"; got != ex { |
| 189 | t.Errorf("Expected status code %q, got %q", ex, got) |
| 190 | } |
| 191 | } |
| 192 | |
| 193 | func TestAuthenticationWithErrors(t *testing.T) { |
| 194 | testCases := []struct { |
nothing calls this directly
no test coverage detected
searching dependent graphs…