Skip to content

Commit dae1029

Browse files
committed
oauth2: update oauth2 tests for the OIDC review hardening
Align the existing provider and command tests with the hardened behavior: verifyUser resolves through the nonce-aware path, the verified-email tests stub the four-argument resolveEmail, the token helper sets email_verified, and the command test mocks the nonce overload. All 110 oauth2 tests pass.
1 parent 57c9fe0 commit dae1029

3 files changed

Lines changed: 14 additions & 14 deletions

File tree

‎plugins/user-authenticators/oauth2/src/main/java/org/apache/cloudstack/oauth2/oidc/GenericOIDCOAuth2Provider.java‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -155,7 +155,7 @@ public boolean verifyUser(String email, String secretCode, Long domainId, String
155155

156156
String verifiedEmail = verifiedEmailCache.asMap().remove(verifiedEmailKey(providerName, secretCode, domainId));
157157
if (verifiedEmail == null) {
158-
verifiedEmail = resolveEmail(secretCode, domainId, providerName);
158+
verifiedEmail = resolveEmail(secretCode, domainId, providerName, null);
159159
}
160160
if (StringUtils.isBlank(verifiedEmail) || !email.equals(verifiedEmail)) {
161161
throw new CloudRuntimeException("Unable to verify the email address with the provided secret");

‎plugins/user-authenticators/oauth2/src/test/java/org/apache/cloudstack/oauth2/api/command/VerifyOAuthCodeAndGetUserCmdTest.java‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@ public void testAuthenticate() {
7474
params.put("provider", providerArray);
7575

7676
when(oauth2mgr.resolveDomainId(any())).thenReturn(null);
77-
when(oauth2mgr.verifySecretCodeAndFetchEmail(eq("secretcode"), eq("provider"), any())).thenReturn("test@example.com");
77+
when(oauth2mgr.verifySecretCodeAndFetchEmail(eq("secretcode"), eq("provider"), any(), any())).thenReturn("test@example.com");
7878

7979
String response = cmd.authenticate("command", params, session, remoteAddress, responseType, auditTrailSb, req, resp);
8080

‎plugins/user-authenticators/oauth2/src/test/java/org/apache/cloudstack/oauth2/oidc/GenericOIDCOAuth2ProviderTest.java‎

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,7 @@ private String idToken(String issuer, String audience, String email, long expire
103103
String payload = "{"
104104
+ "\"iss\":\"" + issuer + "\","
105105
+ "\"aud\":[\"" + audience + "\"],"
106-
+ (email == null ? "" : "\"email\":\"" + email + "\",")
106+
+ (email == null ? "" : "\"email\":\"" + email + "\",\"email_verified\":true,")
107107
+ "\"exp\":" + (System.currentTimeMillis() / 1000L + expiresInSeconds) + ","
108108
+ "\"sub\":\"12345\""
109109
+ "}";
@@ -378,8 +378,8 @@ public void testEveryCallExchangesItsOwnAuthorizationCode() {
378378
doReturn(metadata()).when(provider).getMetadata(registration);
379379
doReturn("token-for-first").when(provider).exchangeAuthorizationCode(eq("first-code"), any(), any());
380380
doReturn("token-for-second").when(provider).exchangeAuthorizationCode(eq("second-code"), any(), any());
381-
doReturn("first@example.com").when(provider).validateAndExtractEmail(eq("token-for-first"), any(), any());
382-
doReturn("second@example.com").when(provider).validateAndExtractEmail(eq("token-for-second"), any(), any());
381+
doReturn("first@example.com").when(provider).validateAndExtractEmail(eq("token-for-first"), any(), any(), any());
382+
doReturn("second@example.com").when(provider).validateAndExtractEmail(eq("token-for-second"), any(), any(), any());
383383

384384
assertEquals("first@example.com", provider.verifySecretCodeAndFetchEmail("first-code", null, REGISTRATION));
385385
assertEquals("second@example.com", provider.verifySecretCodeAndFetchEmail("second-code", null, REGISTRATION));
@@ -391,7 +391,7 @@ public void testEveryCallExchangesItsOwnAuthorizationCode() {
391391
@Test(expected = CloudRuntimeException.class)
392392
public void testVerifyUserRejectsAnEmailThatDoesNotMatchTheToken() {
393393
when(oauthProviderDao.findByProviderAndDomainWithGlobalFallback(REGISTRATION, null)).thenReturn(registration);
394-
doReturn("someone-else@example.com").when(provider).resolveEmail("code", null, REGISTRATION);
394+
doReturn("someone-else@example.com").when(provider).resolveEmail("code", null, REGISTRATION, null);
395395

396396
provider.verifyUser("user@example.com", "code", null, REGISTRATION);
397397
}
@@ -402,38 +402,38 @@ public void testVerifyUserRejectsAnEmailThatDoesNotMatchTheToken() {
402402
*/
403403
@Test
404404
public void testLoginAfterVerificationDoesNotRedeemTheCodeAgain() {
405-
doReturn("user@example.com").when(provider).resolveEmail("code", null, REGISTRATION);
405+
doReturn("user@example.com").when(provider).resolveEmail("code", null, REGISTRATION, null);
406406

407407
assertEquals("user@example.com", provider.verifySecretCodeAndFetchEmail("code", null, REGISTRATION));
408408
assertTrue(provider.verifyUser("user@example.com", "code", null, REGISTRATION));
409409

410-
verify(provider, times(1)).resolveEmail("code", null, REGISTRATION);
410+
verify(provider, times(1)).resolveEmail("code", null, REGISTRATION, null);
411411
}
412412

413413
@Test
414414
public void testVerifiedCodeIsServedFromTheCacheOnlyOnce() {
415-
doReturn("user@example.com").when(provider).resolveEmail("code", null, REGISTRATION);
415+
doReturn("user@example.com").when(provider).resolveEmail("code", null, REGISTRATION, null);
416416

417417
provider.verifySecretCodeAndFetchEmail("code", null, REGISTRATION);
418418
provider.verifyUser("user@example.com", "code", null, REGISTRATION);
419419
provider.verifyUser("user@example.com", "code", null, REGISTRATION);
420420

421-
verify(provider, times(2)).resolveEmail("code", null, REGISTRATION);
421+
verify(provider, times(2)).resolveEmail("code", null, REGISTRATION, null);
422422
}
423423

424424
@Test(expected = CloudRuntimeException.class)
425425
public void testAnotherCodeIsNeverAnsweredFromTheCache() {
426-
doReturn("user@example.com").when(provider).resolveEmail("user-code", null, REGISTRATION);
427-
doThrow(new CloudRuntimeException("invalid_grant")).when(provider).resolveEmail("unrelated-code", null, REGISTRATION);
426+
doReturn("user@example.com").when(provider).resolveEmail("user-code", null, REGISTRATION, null);
427+
doThrow(new CloudRuntimeException("invalid_grant")).when(provider).resolveEmail("unrelated-code", null, REGISTRATION, null);
428428

429429
provider.verifySecretCodeAndFetchEmail("user-code", null, REGISTRATION);
430430
provider.verifyUser("user@example.com", "unrelated-code", null, REGISTRATION);
431431
}
432432

433433
@Test(expected = CloudRuntimeException.class)
434434
public void testCachedCodeIsScopedToItsRegistration() {
435-
doReturn("user@example.com").when(provider).resolveEmail("code", null, REGISTRATION);
436-
doThrow(new CloudRuntimeException("invalid_grant")).when(provider).resolveEmail("code", null, "other-idp");
435+
doReturn("user@example.com").when(provider).resolveEmail("code", null, REGISTRATION, null);
436+
doThrow(new CloudRuntimeException("invalid_grant")).when(provider).resolveEmail("code", null, "other-idp", null);
437437

438438
provider.verifySecretCodeAndFetchEmail("code", null, REGISTRATION);
439439
provider.verifyUser("user@example.com", "code", null, "other-idp");

0 commit comments

Comments
 (0)