mirror of
https://github.com/pocket-id/pocket-id.git
synced 2026-10-03 00:09:03 +02:00
fix: PAR parameters not respected by authorize page
This commit is contained in:
@@ -940,6 +940,55 @@ test.describe('Pushed Authorization Requests (PAR)', () => {
|
||||
expect(tokenResult.error).toBeUndefined();
|
||||
});
|
||||
|
||||
test('par-request-info resolves the stored request parameters', async ({ page }) => {
|
||||
const state = 'par-info-state-9f3a';
|
||||
const parResult = await oidcUtil.pushAuthorizationRequest(page, {
|
||||
clientId: client.id,
|
||||
clientSecret: client.secret,
|
||||
redirectUri: client.callbackUrl,
|
||||
scope: 'openid profile',
|
||||
state,
|
||||
responseMode: 'form_post'
|
||||
});
|
||||
expect(parResult.request_uri).toBeDefined();
|
||||
|
||||
const res = await page.request.get('/api/oidc/par-request-info', {
|
||||
params: { client_id: client.id, request_uri: parResult.request_uri! }
|
||||
});
|
||||
expect(res.ok()).toBe(true);
|
||||
|
||||
const body = await res.json();
|
||||
expect(body.scope).toBe('openid profile');
|
||||
expect(body.redirectURI).toBe(client.callbackUrl);
|
||||
expect(body.state).toBe(state);
|
||||
expect(body.responseMode).toBe('form_post');
|
||||
});
|
||||
|
||||
test('PAR full flow carries the resolved state into the callback redirect', async ({ page }) => {
|
||||
const state = 'par-flow-state-7b21';
|
||||
const parResult = await oidcUtil.pushAuthorizationRequest(page, {
|
||||
clientId: client.id,
|
||||
clientSecret: client.secret,
|
||||
redirectUri: client.callbackUrl,
|
||||
state,
|
||||
responseMode: 'form_post'
|
||||
});
|
||||
expect(parResult.request_uri).toBeDefined();
|
||||
|
||||
const urlParams = new URLSearchParams({
|
||||
client_id: client.id,
|
||||
request_uri: parResult.request_uri!
|
||||
});
|
||||
|
||||
const formPostRequestPromise = waitForFormPostRequest(page, client.callbackUrl);
|
||||
await page.goto(`/authorize?${urlParams.toString()}`);
|
||||
|
||||
const request = await formPostRequestPromise;
|
||||
const formData = new URLSearchParams(request.postData() ?? '');
|
||||
expect(formData.get('code')).toBeTruthy();
|
||||
expect(formData.get('state')).toBe(state);
|
||||
});
|
||||
|
||||
test('PAR full flow shows consent screen when authorization is required', async ({ page }) => {
|
||||
// The parClient is pre-authorized for "openid profile email"; pushing a different
|
||||
// scope means consent is required and the consent screen must be shown rather than
|
||||
|
||||
@@ -75,8 +75,14 @@ export async function pushAuthorizationRequest(
|
||||
codeChallengeMethod?: string;
|
||||
nonce?: string;
|
||||
state?: string;
|
||||
responseMode?: string;
|
||||
}
|
||||
): Promise<{ request_uri?: string; expires_in?: number; error?: string; error_description?: string }> {
|
||||
): Promise<{
|
||||
request_uri?: string;
|
||||
expires_in?: number;
|
||||
error?: string;
|
||||
error_description?: string;
|
||||
}> {
|
||||
const form: Record<string, string> = {
|
||||
client_id: params.clientId,
|
||||
response_type: params.responseType ?? 'code',
|
||||
@@ -88,6 +94,7 @@ export async function pushAuthorizationRequest(
|
||||
if (params.codeChallengeMethod) form.code_challenge_method = params.codeChallengeMethod;
|
||||
if (params.nonce) form.nonce = params.nonce;
|
||||
if (params.state) form.state = params.state;
|
||||
if (params.responseMode) form.response_mode = params.responseMode;
|
||||
|
||||
return page.request
|
||||
.post('/api/oidc/par', {
|
||||
|
||||
Reference in New Issue
Block a user