Koha/t/db_dependent/api/v1/oauth.t
Julian Maurice ccc034195e Bug 20402: Fix oauth.t
GET /patrons now requires { "borrowers": 1 } instead of
{ "borrowers": "edit_borrowers" }

Signed-off-by: Josef Moravec <josef.moravec@gmail.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
2018-05-08 15:55:42 -03:00

96 lines
3 KiB
Perl
Executable file

#!/usr/bin/env perl
# This file is part of Koha.
#
# Koha is free software; you can redistribute it and/or modify it under the
# terms of the GNU General Public License as published by the Free Software
# Foundation; either version 3 of the License, or (at your option) any later
# version.
#
# Koha is distributed in the hope that it will be useful, but WITHOUT ANY
# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
# A PARTICULAR PURPOSE. See the GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License along
# with Koha; if not, write to the Free Software Foundation, Inc.,
# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
use Modern::Perl;
use Test::More tests => 1;
use Test::Mojo;
use Koha::Database;
use Koha::Patrons;
use t::lib::Mocks;
use t::lib::TestBuilder;
my $t = Test::Mojo->new('Koha::REST::V1');
my $schema = Koha::Database->new->schema;
my $builder = t::lib::TestBuilder->new();
subtest '/oauth/token tests' => sub {
plan tests => 19;
$schema->storage->txn_begin;
my $borrower = $builder->build({
source => 'Borrower',
value => {
surname => 'Test OAuth',
flags => 0,
},
});
my $patron = Koha::Patrons->find($borrower->{borrowernumber});
# Missing parameter grant_type
$t->post_ok('/api/v1/oauth/token')
->status_is(400);
# Wrong grant type
$t->post_ok('/api/v1/oauth/token', form => { grant_type => 'password' })
->status_is(400)
->json_is({error => 'Unimplemented grant type'});
# No client_id/client_secret
$t->post_ok('/api/v1/oauth/token', form => { grant_type => 'client_credentials' })
->status_is(403)
->json_is({error => 'unauthorized_client'});
my ($client_id, $client_secret) = ('client1', 'secr3t');
t::lib::Mocks::mock_config('api_client', {
'client_id' => $client_id,
'client_secret' => $client_secret,
patron_id => $patron->borrowernumber,
});
my $formData = {
grant_type => 'client_credentials',
client_id => $client_id,
client_secret => $client_secret,
};
$t->post_ok('/api/v1/oauth/token', form => $formData)
->status_is(200)
->json_is('/expires_in' => 3600)
->json_is('/token_type' => 'Bearer')
->json_has('/access_token');
my $access_token = $t->tx->res->json->{access_token};
# Without access token, it returns 401
$t->get_ok('/api/v1/patrons')->status_is(401);
# With access token, but without permissions, it returns 403
my $tx = $t->ua->build_tx(GET => '/api/v1/patrons');
$tx->req->headers->authorization("Bearer $access_token");
$t->request_ok($tx)->status_is(403);
# With access token and permissions, it returns 200
$patron->flags(2**4)->store;
$tx = $t->ua->build_tx(GET => '/api/v1/patrons');
$tx->req->headers->authorization("Bearer $access_token");
$t->request_ok($tx)->status_is(200);
$schema->storage->txn_rollback;
};