RPCBaseTests.swift 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326
  1. // Copyright 2023 Google LLC
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. import Foundation
  15. import XCTest
  16. @testable import FirebaseAuth
  17. @available(iOS 13, tvOS 13, macOS 10.15, macCatalyst 13, watchOS 7, *)
  18. class RPCBaseTests: XCTestCase {
  19. let kEmail = "user@company.com"
  20. let kFakePassword = "!@#$%^"
  21. let kDisplayName = "User Doe"
  22. let kLocalID = "testLocalId"
  23. let kFakeOobCode = "fakeOobCode"
  24. let kRefreshToken = "fakeRefreshToken"
  25. let kCustomToken = "CUSTOM_TOKEN"
  26. let kFakeEmailSignInLink = "https://test.app.goo.gl/?link=https://test.firebase" +
  27. "app.com/__/auth/action?apiKey%3DtestAPIKey%26mode%3DsignIn%26oobCode%3Dtestoobcode%26continueU" +
  28. "rl%3Dhttps://test.apps.com&ibi=com.test.com&ifl=https://test.firebaseapp.com/__/auth/" +
  29. "action?apiKey%3DtestAPIKey%26mode%3DsignIn%26oobCode%3Dtestoobcode%26continueUrl%3Dhttps://" +
  30. "test.apps.com"
  31. let kFakeEmailSignInDeeplink =
  32. "https://example.domain.com/?apiKey=testAPIKey&oobCode=testoobcode&mode=signIn"
  33. let kContinueURL = "continueURL"
  34. let kIosBundleID = "testBundleID"
  35. let kAndroidPackageName = "androidpackagename"
  36. let kAndroidMinimumVersion = "3.0"
  37. let kLinkDomain = "link.firebaseapp.com"
  38. let kTestPhotoURL = "https://host.domain/image"
  39. let kCreationDateTimeIntervalInSeconds = 1_505_858_500.0
  40. let kLastSignInDateTimeIntervalInSeconds = 1_505_858_583.0
  41. let kTestPhoneNumber = "415-555-1234"
  42. let kIdToken = "FAKE_ID_TOKEN"
  43. static let kOAuthSessionID = "sessionID"
  44. static let kOAuthRequestURI = "requestURI"
  45. let kGoogleIDToken = "GOOGLE_ID_TOKEN"
  46. let kGoogleAccessToken = "GOOGLE_ACCESS_TOKEN"
  47. let kGoogleID = "GOOGLE_ID"
  48. let kGoogleEmail = "usergmail.com"
  49. let kGoogleDisplayName = "Google Doe"
  50. let kGoogleProfile = ["email": "usergmail.com", "given_name": "MyFirst", "family_name": "MyLast"]
  51. let kUserName = "User Doe"
  52. /** @var kTestAPIKey
  53. @brief Fake API key used for testing.
  54. */
  55. let kTestAPIKey = "APIKey"
  56. /** @var kTestFirebaseAppID
  57. @brief Fake Firebase app ID used for testing.
  58. */
  59. let kTestFirebaseAppID = "appID"
  60. /** @var kTestIdentifier
  61. @brief Fake identifier key used for testing.
  62. */
  63. let kTestIdentifier = "Identifier"
  64. var rpcIssuer: FakeBackendRPCIssuer!
  65. var authBackend: AuthBackend!
  66. override func setUp() {
  67. rpcIssuer = FakeBackendRPCIssuer()
  68. authBackend = AuthBackend(rpcIssuer: rpcIssuer)
  69. }
  70. override func tearDown() {
  71. rpcIssuer = nil
  72. authBackend = nil
  73. }
  74. /** @fn checkRequest
  75. @brief Tests the encoding of a request.
  76. */
  77. func checkRequest(request: any AuthRPCRequest,
  78. expected: String,
  79. key: String,
  80. value: String?,
  81. checkPostBody: Bool = false) async throws {
  82. rpcIssuer.respondBlock = {
  83. XCTAssertEqual(self.rpcIssuer.requestURL?.absoluteString, expected)
  84. if checkPostBody {
  85. XCTAssertNil(request.unencodedHTTPRequestBody)
  86. } else if let requestDictionary = self.rpcIssuer.decodedRequest as? [String: AnyHashable] {
  87. XCTAssertEqual(requestDictionary[key], value)
  88. } else {
  89. XCTFail("decodedRequest is not a dictionary")
  90. }
  91. // Dummy response to unblock await.
  92. return try self.rpcIssuer.respond(withJSON: [:])
  93. }
  94. let _ = try await authBackend.call(with: request)
  95. }
  96. /** @fn checkBackendError
  97. @brief This test checks error messages from the backend map to the expected error codes
  98. */
  99. func checkBackendError(request: any AuthRPCRequest,
  100. message: String = "",
  101. reason: String? = nil,
  102. json: [String: AnyHashable]? = nil,
  103. errorCode: AuthErrorCode,
  104. errorReason: String? = nil,
  105. underlyingErrorKey: String? = nil,
  106. checkLocalizedDescription: String? = nil) async throws {
  107. rpcIssuer.respondBlock = {
  108. if let json = json {
  109. return try self.rpcIssuer.respond(withJSON: json)
  110. } else if let reason = reason {
  111. return try self.rpcIssuer.respond(underlyingErrorMessage: reason, message: message)
  112. } else {
  113. return try self.rpcIssuer.respond(serverErrorMessage: message)
  114. }
  115. }
  116. do {
  117. let _ = try await authBackend.call(with: request)
  118. XCTFail("Did not throw expected error")
  119. return
  120. } catch {
  121. let rpcError = error as NSError
  122. XCTAssertEqual(rpcError.code, errorCode.rawValue)
  123. if errorCode == .internalError {
  124. let underlyingError = try XCTUnwrap(rpcError.userInfo[NSUnderlyingErrorKey] as? NSError)
  125. XCTAssertNotNil(underlyingError.userInfo[AuthErrorUtils.userInfoDeserializedResponseKey])
  126. }
  127. if let errorReason {
  128. XCTAssertEqual(errorReason, rpcError.userInfo[NSLocalizedFailureReasonErrorKey] as? String)
  129. }
  130. if let checkLocalizedDescription {
  131. let localizedDescription = try XCTUnwrap(rpcError
  132. .userInfo[NSLocalizedDescriptionKey] as? String)
  133. XCTAssertEqual(checkLocalizedDescription, localizedDescription)
  134. }
  135. }
  136. }
  137. func makeRequestConfiguration() -> AuthRequestConfiguration {
  138. return AuthRequestConfiguration(
  139. apiKey: kTestAPIKey,
  140. appID: kTestFirebaseAppID
  141. )
  142. }
  143. static let kFakeAccessToken =
  144. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZDBhODBiYzh" +
  145. "jM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  146. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vZmItc2EtdXBncm" +
  147. "FkZWQiLCJhdWQiOiJ0ZXN0X2F1ZCIsImF1dGhfdGltZSI6MTUyMjM2MDU0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZCIs" +
  148. "InN1YiI6InRlc3Rfc3ViIiwiaWF0IjoxNTIyMzYwNTU3LCJleHAiOjE1MjIzNjQxNTcsImVtYWlsIjoiYXVuaXRlc3R1c2" +
  149. "VyQGdtYWlsLmNvbSIsImVtYWlsX3ZlcmlmaWVkIjpmYWxzZSwiZmlyZWJhc2UiOnsiaWRlbnRpdGllcyI6eyJlbWFpbCI6" +
  150. "WyJhdW5pdGVzdHVzZXJAZ21haWwuY29tIl19LCJzaWduX2luX3Byb3ZpZGVyIjoicGFzc3dvcmQifX0=." +
  151. "WFQqSrpVnxx7m" +
  152. "UrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  153. "BKkcbZuq8O7iDVpOvqKC" +
  154. "3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  155. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjN" +
  156. "hHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  157. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbW" +
  158. "lddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  159. static let kFakeAccessTokenLength415 =
  160. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZD" +
  161. "BhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  162. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vdGVzd" +
  163. "CIsImF1ZCI6InRlc3RfYXVkIiwiYXV0aF90aW1lIjoxNTIyMzYwNTQ5LCJ1c2VyX2lkIjoidGVzdF91c2VyX2lkIiwic3V" +
  164. "iIjoidGVzdF9zdWIiLCJpYXQiOjE1MjIzNjA1NTcsImV4cCI6MTUyMjM2NDE1NywiZW1haWwiOiJhdW5pdGVzdHVzZXJAZ" +
  165. "21haWwuY29tIiwiZW1haWxfdmVyaWZpZWQiOmZhbHNlLCJmaXJlYmFzZSI6eyJpZGVudGl0aWVzIjp7ImVtYWlsIjpbImF" +
  166. "1bml0ZXN0dXNlckBnbWFpbC5jb20iXX0sInNpZ25faW5fcHJvdmlkZXIiOiJwYXNzd29yZCJ9fQ=.WFQqSrpVnxx7m" +
  167. "UrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  168. "BKkcbZuq8O7iDVpOvqKC" +
  169. "3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  170. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjN" +
  171. "hHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  172. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbW" +
  173. "lddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  174. static let kFakeAccessTokenLength416 =
  175. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZD" +
  176. "BhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  177. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vdGVzd" +
  178. "DIiLCJhdWQiOiJ0ZXN0X2F1ZCIsImF1dGhfdGltZSI6MTUyMjM2MDU0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZCIsInN" +
  179. "1YiI6InRlc3Rfc3ViIiwiaWF0IjoxNTIyMzYwNTU3LCJleHAiOjE1MjIzNjQxNTcsImVtYWlsIjoiYXVuaXRlc3R1c2VyQ" +
  180. "GdtYWlsLmNvbSIsImVtYWlsX3ZlcmlmaWVkIjpmYWxzZSwiZmlyZWJhc2UiOnsiaWRlbnRpdGllcyI6eyJlbWFpbCI6WyJ" +
  181. "hdW5pdGVzdHVzZXJAZ21haWwuY29tIl19LCJzaWduX2luX3Byb3ZpZGVyIjoicGFzc3dvcmQifX0=.WFQqSrpVnxx7m" +
  182. "UrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  183. "BKkcbZuq8O7iDVpOvqKC" +
  184. "3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  185. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjN" +
  186. "hHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  187. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbW" +
  188. "lddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  189. static let kFakeAccessTokenLength523 =
  190. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZD" +
  191. "BhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  192. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vdGVzd" +
  193. "DQiLCJhdWQiOiJ0ZXN0X2F1ZCIsImF1dGhfdGltZSI6MTUyMjM2MDU0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZF81NDM" +
  194. "yIiwic3ViIjoidGVzdF9zdWIiLCJpYXQiOjE1MjIzNjA1NTcsImV4cCI6MTUyMjM2NDE1OSwiZW1haWwiOiJhdW5pdGVzd" +
  195. "HVzZXI0QGdtYWlsLmNvbSIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJmaXJlYmFzZSI6eyJpZGVudGl0aWVzIjp7ImVtYWl" +
  196. "sIjpbImF1bml0ZXN0dXNlckBnbWFpbC5jb20iXX0sInNpZ25faW5fcHJvdmlkZXIiOiJwYXNzd29yZCJ9fQ=." +
  197. "WFQqSrpVn" +
  198. "xx7mUrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  199. "BKkcbZuq8O7iDVpO" +
  200. "vqKC3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  201. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH" +
  202. "7jjNhHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  203. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqV" +
  204. "kPbWlddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  205. static let kFakeAccessTokenWithBase64 =
  206. "ey?hbGciOimnuzI1NiIsImtpZCI6ImY1YjE4M" +
  207. "jc2YTQ4NjYxZDBhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  208. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2ds" +
  209. "ZS5jb20vZmItc2EtdXBncmFkZWQiLCJhdWQiOiI_Pz8_Pz8_Pz8_Pj4-Pj4-Pj4-" +
  210. "PiIsImF1dGhfdGltZSI6MTUyMjM2MD" +
  211. "U0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZCIsInN1YiI6InRlc3Rfc3ViIiwiaWF0IjoxNTIyMzYwNTU3LCJleHAiOjE1" +
  212. "MjIzNjQxNTcsImVtYWlsIjoiPj4-Pj4-Pj4_Pz8_Pz8_" +
  213. "P0BnbWFpbC5jb20iLCJlbWFpbF92ZXJpZmllZCI6ZmFsc2UsIm" +
  214. "ZpcmViYXNlIjp7ImlkZW50aXRpZXMiOnsiZW1haWwiOlsiYXVuaXRlc3R1c2VyQGdtYWlsLmNvbSJdfSwic2lnbl9pbl9w" +
  215. "cm92aWRlciI6IlBhc3N3b3JkIn19.WFQqSrpVnxx7mUrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-" +
  216. "aTYMvND3-" +
  217. "4aS3qRnN2kvk9KJAaF3eI_BKkcbZuq8O7iDVpOvqKC3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  218. "XtBt" +
  219. "1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjNhHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  220. "dDV7" +
  221. "jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbWlddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  222. func setFakeSecureTokenService(fakeAccessToken: String = RPCBaseTests.kFakeAccessToken) {
  223. rpcIssuer?.fakeSecureTokenServiceJSON = ["access_token": fakeAccessToken,
  224. "expires_in": "3600"]
  225. }
  226. func setFakeGetAccountProvider(withNewDisplayName displayName: String = "User Doe",
  227. withLocalID localID: String = "testLocalId",
  228. withProviderID providerID: String = "testProviderID",
  229. withFederatedID federatedID: String = "testFederatedId",
  230. withEmail email: String = "user@company.com",
  231. withPasswordHash passwordHash: String? = nil) {
  232. let kProviderUserInfoKey = "providerUserInfo"
  233. let kPhotoUrlKey = "photoUrl"
  234. let kProviderIDkey = "providerId"
  235. let kDisplayNameKey = "displayName"
  236. let kFederatedIDKey = "federatedId"
  237. let kEmailKey = "email"
  238. let kPasswordHashKey = "passwordHash"
  239. let kTestPasswordHash = passwordHash
  240. let kEmailVerifiedKey = "emailVerified"
  241. let kLocalIDKey = "localId"
  242. rpcIssuer?.fakeGetAccountProviderJSON = [[
  243. kProviderUserInfoKey: [[
  244. kProviderIDkey: providerID,
  245. kDisplayNameKey: displayName,
  246. kPhotoUrlKey: kTestPhotoURL,
  247. kFederatedIDKey: federatedID,
  248. kEmailKey: email,
  249. ]],
  250. kLocalIDKey: localID,
  251. kDisplayNameKey: displayName,
  252. kEmailKey: email,
  253. kPhotoUrlKey: kTestPhotoURL,
  254. kEmailVerifiedKey: true,
  255. kPasswordHashKey: kTestPasswordHash,
  256. "phoneNumber": kTestPhoneNumber,
  257. ]]
  258. }
  259. func setFakeGoogleGetAccountProvider() {
  260. setFakeGetAccountProvider(withNewDisplayName: kGoogleDisplayName,
  261. withProviderID: GoogleAuthProvider.id,
  262. withFederatedID: kGoogleID,
  263. withEmail: kGoogleEmail)
  264. }
  265. func setFakeGetAccountProviderAnonymous() {
  266. let kPasswordHashKey = "passwordHash"
  267. let kTestPasswordHash = "testPasswordHash"
  268. let kLocalIDKey = "localId"
  269. rpcIssuer?.fakeGetAccountProviderJSON = [[
  270. kLocalIDKey: kLocalID,
  271. kPasswordHashKey: kTestPasswordHash,
  272. ]]
  273. }
  274. func fakeActionCodeSettings() -> ActionCodeSettings {
  275. let settings = ActionCodeSettings()
  276. settings.iOSBundleID = kIosBundleID
  277. settings.setAndroidPackageName(kAndroidPackageName,
  278. installIfNotAvailable: true,
  279. minimumVersion: kAndroidMinimumVersion)
  280. settings.handleCodeInApp = true
  281. settings.url = URL(string: kContinueURL)
  282. settings.linkDomain = kLinkDomain
  283. return settings
  284. }
  285. func assertUserGoogle(_ user: User?) throws {
  286. let user = try XCTUnwrap(user)
  287. XCTAssertEqual(user.uid, kLocalID)
  288. XCTAssertEqual(user.displayName, kGoogleDisplayName)
  289. XCTAssertEqual(user.providerData.count, 1)
  290. let googleUserInfo = user.providerData[0]
  291. XCTAssertEqual(googleUserInfo.providerID, GoogleAuthProvider.id)
  292. XCTAssertEqual(googleUserInfo.uid, kGoogleID)
  293. XCTAssertEqual(googleUserInfo.displayName, kGoogleDisplayName)
  294. XCTAssertEqual(googleUserInfo.email, kGoogleEmail)
  295. }
  296. /// Sleep long enough for pending async task to start.
  297. static func waitSleep() {
  298. usleep(10000)
  299. }
  300. }