FIRVerifyAssertionRequestTests.m 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252
  1. /*
  2. * Copyright 2017 Google
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * http://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. #import <XCTest/XCTest.h>
  17. #import "FirebaseAuth/Sources/Public/FirebaseAuth/FIRAuthErrors.h"
  18. #import "FirebaseAuth/Sources/Backend/FIRAuthBackend.h"
  19. #import "FirebaseAuth/Sources/Backend/RPC/FIRGetOOBConfirmationCodeResponse.h"
  20. #import "FirebaseAuth/Sources/Backend/RPC/FIRVerifyAssertionRequest.h"
  21. #import "FirebaseAuth/Sources/Backend/RPC/FIRVerifyAssertionResponse.h"
  22. #import "FirebaseAuth/Tests/Unit/FIRFakeBackendRPCIssuer.h"
  23. /** @var kTestAPIKey
  24. @brief Fake API key used for testing.
  25. */
  26. static NSString *const kTestAPIKey = @"APIKey";
  27. /** @var kTestFirebaseAppID
  28. @brief Fake Firebase app ID used for testing.
  29. */
  30. static NSString *const kTestFirebaseAppID = @"appID";
  31. /** @var kTestPostBodyKey
  32. @brief The name of the "postBody" property in the response.
  33. */
  34. static NSString *const kPostBodyKey = @"postBody";
  35. /** @var kExpectedAPIURL
  36. @brief The expected URL for test calls.
  37. */
  38. static NSString *const kExpectedAPIURL =
  39. @"https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyAssertion?key=APIKey";
  40. /** @var kIDTokenKey
  41. @brief The name of the "idToken" property in the response.
  42. */
  43. static NSString *const kIDTokenKey = @"idToken";
  44. /** @var kTestAccessToken
  45. @brief Fake access token used for testing.
  46. */
  47. static NSString *const kTestAccessToken = @"ACCESS_TOKEN";
  48. /** @var kProviderIDKey
  49. @brief The key for the "providerId" value in the request.
  50. */
  51. static NSString *const kProviderIDKey = @"providerId";
  52. /** @var kTestProviderID
  53. @brief Fake provider ID used for testing.
  54. */
  55. static NSString *const kTestProviderID = @"ProviderID";
  56. /** @var kProviderIDTokenKey
  57. @brief The key for the "id_token" value in the request.
  58. */
  59. static NSString *const kProviderIDTokenKey = @"id_token";
  60. /** @var kTestProviderIDToken
  61. @brief Fake provider ID token used for testing.
  62. */
  63. static NSString *const kTestProviderIDToken = @"ProviderIDToken";
  64. /** @var kInputEmailKey
  65. @brief The key for the "inputEmail" value in the request.
  66. */
  67. static NSString *const kInputEmailKey = @"identifier";
  68. /** @var kTestInputEmail
  69. @brief Fake input email used for testing.
  70. */
  71. static NSString *const kTestInputEmail = @"testInputEmail";
  72. /** @var kPendingTokenKey
  73. @brief The key for the "pendingToken" value in the request.
  74. */
  75. static NSString *const kPendingTokenKey = @"pendingToken";
  76. /** @var kTestPendingToken
  77. @brief Fake pending token used for testing.
  78. */
  79. static NSString *const kTestPendingToken = @"testPendingToken";
  80. /** @var kProviderAccessTokenKey
  81. @brief The key for the "access_token" value in the request.
  82. */
  83. static NSString *const kProviderAccessTokenKey = @"access_token";
  84. /** @var kTestProviderAccessToken
  85. @brief Fake @c providerAccessToken used for testing the request.
  86. */
  87. static NSString *const kTestProviderAccessToken = @"testProviderAccessToken";
  88. /** @var kProviderOAuthTokenSecretKey
  89. @brief The key for the "oauth_token_secret" value in the request.
  90. */
  91. static NSString *const kProviderOAuthTokenSecretKey = @"oauth_token_secret";
  92. /** @var kTestProviderOAuthTokenSecret
  93. @brief Fake @c providerOAuthTokenSecret used for testing the request.
  94. */
  95. static NSString *const kTestProviderOAuthTokenSecret = @"testProviderOAuthTokenSecret";
  96. /** @var kReturnSecureTokenKey
  97. @brief The key for the "returnSecureToken" value in the request.
  98. */
  99. static NSString *const kReturnSecureTokenKey = @"returnSecureToken";
  100. /** @var kAutoCreateKey
  101. @brief The key for the "auto-create" value in the request.
  102. */
  103. static NSString *const kAutoCreateKey = @"autoCreate";
  104. /** @class FIRVerifyAssertionRequestTests
  105. @brief Tests for @c FIRVerifyAssertionReuqest
  106. */
  107. @interface FIRVerifyAssertionRequestTests : XCTestCase
  108. @end
  109. @implementation FIRVerifyAssertionRequestTests {
  110. /** @var _RPCIssuer
  111. @brief This backend RPC issuer is used to fake network responses for each test in the suite.
  112. In the @c setUp method we initialize this and set @c FIRAuthBackend's RPC issuer to it.
  113. */
  114. FIRFakeBackendRPCIssuer *_RPCIssuer;
  115. /** @var _requestConfiguration
  116. @brief This is the request configuration used for testing.
  117. */
  118. FIRAuthRequestConfiguration *_requestConfiguration;
  119. }
  120. - (void)setUp {
  121. [super setUp];
  122. FIRFakeBackendRPCIssuer *RPCIssuer = [[FIRFakeBackendRPCIssuer alloc] init];
  123. [FIRAuthBackend setDefaultBackendImplementationWithRPCIssuer:RPCIssuer];
  124. _RPCIssuer = RPCIssuer;
  125. _requestConfiguration = [[FIRAuthRequestConfiguration alloc] initWithAPIKey:kTestAPIKey
  126. appID:kTestFirebaseAppID];
  127. }
  128. - (void)tearDown {
  129. _RPCIssuer = nil;
  130. _requestConfiguration = nil;
  131. [FIRAuthBackend setDefaultBackendImplementationWithRPCIssuer:nil];
  132. [super tearDown];
  133. }
  134. /** @fn testVerifyAssertionRequestMissingTokens
  135. @brief Tests the request with missing @c providerAccessToken and @c provideIDToken.
  136. @remarks The request creation will raise an @c NSInvalidArgumentException exception when both
  137. these tokens are missing.
  138. */
  139. - (void)testVerifyAssertionRequestMissingTokens {
  140. FIRVerifyAssertionRequest *request =
  141. [[FIRVerifyAssertionRequest alloc] initWithProviderID:kTestProviderID
  142. requestConfiguration:_requestConfiguration];
  143. FIRVerifyAssertionResponseCallback callback =
  144. ^(FIRVerifyAssertionResponse *_Nullable response, NSError *_Nullable error) {
  145. };
  146. void (^verifyAssertionBlock)(void) = ^{
  147. [FIRAuthBackend verifyAssertion:request callback:callback];
  148. };
  149. XCTAssertThrowsSpecificNamed(verifyAssertionBlock(), NSException, NSInvalidArgumentException,
  150. @"Either IDToken or accessToken must be supplied.");
  151. XCTAssertNil(_RPCIssuer.decodedRequest[kPostBodyKey]);
  152. }
  153. /** @fn testVerifyAssertionRequestProviderAccessToken
  154. @brief Tests the verify assertion request with the @c providerAccessToken field set.
  155. @remarks The presence of the @c providerAccessToken will prevent an @c
  156. NSInvalidArgumentException exception from being raised.
  157. */
  158. - (void)testVerifyAssertionRequestProviderAccessToken {
  159. FIRVerifyAssertionRequest *request =
  160. [[FIRVerifyAssertionRequest alloc] initWithProviderID:kTestProviderID
  161. requestConfiguration:_requestConfiguration];
  162. request.providerAccessToken = kTestProviderAccessToken;
  163. request.returnSecureToken = NO;
  164. [FIRAuthBackend
  165. verifyAssertion:request
  166. callback:^(FIRVerifyAssertionResponse *_Nullable response, NSError *_Nullable error){
  167. }];
  168. NSArray<NSURLQueryItem *> *queryItems = @[
  169. [NSURLQueryItem queryItemWithName:kProviderIDKey value:kTestProviderID],
  170. [NSURLQueryItem queryItemWithName:kProviderAccessTokenKey value:kTestProviderAccessToken],
  171. ];
  172. NSURLComponents *components = [[NSURLComponents alloc] init];
  173. [components setQueryItems:queryItems];
  174. XCTAssertEqualObjects(_RPCIssuer.requestURL.absoluteString, kExpectedAPIURL);
  175. XCTAssertNotNil(_RPCIssuer.decodedRequest[kPostBodyKey]);
  176. XCTAssertEqualObjects(_RPCIssuer.decodedRequest[kPostBodyKey], [components query]);
  177. XCTAssertNil(_RPCIssuer.decodedRequest[kIDTokenKey]);
  178. XCTAssertNil(_RPCIssuer.decodedRequest[kReturnSecureTokenKey]);
  179. // Auto-create flag Should be true by default.
  180. XCTAssertTrue([_RPCIssuer.decodedRequest[kAutoCreateKey] boolValue]);
  181. }
  182. /** @fn testVerifyAssertionRequestOptionalFields
  183. @brief Tests the verify assertion request with all optinal fields set.
  184. */
  185. - (void)testVerifyAssertionRequestOptionalFields {
  186. FIRVerifyAssertionRequest *request =
  187. [[FIRVerifyAssertionRequest alloc] initWithProviderID:kTestProviderID
  188. requestConfiguration:_requestConfiguration];
  189. request.providerIDToken = kTestProviderIDToken;
  190. request.providerAccessToken = kTestProviderAccessToken;
  191. request.accessToken = kTestAccessToken;
  192. request.inputEmail = kTestInputEmail;
  193. request.pendingToken = kTestPendingToken;
  194. request.providerOAuthTokenSecret = kTestProviderOAuthTokenSecret;
  195. request.autoCreate = NO;
  196. [FIRAuthBackend
  197. verifyAssertion:request
  198. callback:^(FIRVerifyAssertionResponse *_Nullable response, NSError *_Nullable error){
  199. }];
  200. NSArray<NSURLQueryItem *> *queryItems = @[
  201. [NSURLQueryItem queryItemWithName:kProviderIDKey value:kTestProviderID],
  202. [NSURLQueryItem queryItemWithName:kProviderIDTokenKey value:kTestProviderIDToken],
  203. [NSURLQueryItem queryItemWithName:kProviderAccessTokenKey value:kTestProviderAccessToken],
  204. [NSURLQueryItem queryItemWithName:kProviderOAuthTokenSecretKey
  205. value:kTestProviderOAuthTokenSecret],
  206. [NSURLQueryItem queryItemWithName:kInputEmailKey value:kTestInputEmail],
  207. ];
  208. NSURLComponents *components = [[NSURLComponents alloc] init];
  209. [components setQueryItems:queryItems];
  210. XCTAssertEqualObjects(_RPCIssuer.requestURL.absoluteString, kExpectedAPIURL);
  211. XCTAssertNotNil(_RPCIssuer.decodedRequest[kPostBodyKey]);
  212. XCTAssertEqualObjects(_RPCIssuer.decodedRequest[kPostBodyKey], [components query]);
  213. XCTAssertEqualObjects(_RPCIssuer.decodedRequest[kIDTokenKey], kTestAccessToken);
  214. XCTAssertTrue([_RPCIssuer.decodedRequest[kReturnSecureTokenKey] boolValue]);
  215. XCTAssertFalse([_RPCIssuer.decodedRequest[kAutoCreateKey] boolValue]);
  216. }
  217. @end