MAPG-142 redefine tokens and increase OAuth security with nonce
This commit is contained in:
10 files changed
+63
-32
No files matched your search
@@ -13,6 +13,7 @@ final class GoogleOAuthTest extends TestCase
|
||||
{
|
||||
$_ENV['GOOGLE_OAUTH_CLIENT_ID'] = 'xyz';
|
||||
$state = 'random_state_string';
|
||||
$nonce = 'random_nonce_string';
|
||||
$redirectUrl = 'http://example.com/oauth';
|
||||
|
||||
$requestMock = $this->getMockBuilder(IRequest::class)
|
||||
@@ -20,7 +21,7 @@ final class GoogleOAuthTest extends TestCase
|
||||
->getMock();
|
||||
$googleOAuth = new GoogleOAuth($requestMock);
|
||||
|
||||
$dialogUrl = $googleOAuth->getDialogUrl($state, $redirectUrl);
|
||||
$dialogUrl = $googleOAuth->getDialogUrl($state, $redirectUrl, $nonce);
|
||||
$dialogUrlParsed = explode('?', $dialogUrl);
|
||||
|
||||
$this->assertEquals('https://accounts.google.com/o/oauth2/v2/auth', $dialogUrlParsed[0]);
|
||||
@@ -33,15 +34,10 @@ final class GoogleOAuthTest extends TestCase
|
||||
'scope' => 'openid email',
|
||||
'redirect_uri' => $redirectUrl,
|
||||
'state' => $state,
|
||||
'nonce' => hash('sha256', random_bytes(10) . microtime()),
|
||||
'nonce' => $nonce,
|
||||
];
|
||||
|
||||
$this->assertEquals($expectedQueryParams['response_type'], $dialogUrlQueryParams['response_type']);
|
||||
$this->assertEquals($expectedQueryParams['client_id'], $dialogUrlQueryParams['client_id']);
|
||||
$this->assertEquals($expectedQueryParams['scope'], $dialogUrlQueryParams['scope']);
|
||||
$this->assertEquals($expectedQueryParams['redirect_uri'], $dialogUrlQueryParams['redirect_uri']);
|
||||
$this->assertEquals($expectedQueryParams['state'], $dialogUrlQueryParams['state']);
|
||||
$this->assertMatchesRegularExpression('/^[a-f0-9]{64}$/', $dialogUrlQueryParams['nonce']);
|
||||
$this->assertEquals($expectedQueryParams, $dialogUrlQueryParams);
|
||||
}
|
||||
|
||||
public function testCanRequestToken(): void
|
||||
|
||||
Reference in new issue
Block a user