RPCBaseTests.swift 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328
  1. // Copyright 2023 Google LLC
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. import Foundation
  15. import XCTest
  16. @testable import FirebaseAuth
  17. @available(iOS 13, tvOS 13, macOS 10.15, macCatalyst 13, watchOS 7, *)
  18. class RPCBaseTests: XCTestCase {
  19. let kEmail = "user@company.com"
  20. let kFakePassword = "!@#$%^"
  21. let kDisplayName = "User Doe"
  22. let kLocalID = "testLocalId"
  23. let kFakeOobCode = "fakeOobCode"
  24. let kRefreshToken = "fakeRefreshToken"
  25. let kCustomToken = "CUSTOM_TOKEN"
  26. let kFakeEmailSignInLink = "https://test.app.goo.gl/?link=https://test.firebase" +
  27. "app.com/__/auth/action?apiKey%3DtestAPIKey%26mode%3DsignIn%26oobCode%3Dtestoobcode%26continueU" +
  28. "rl%3Dhttps://test.apps.com&ibi=com.test.com&ifl=https://test.firebaseapp.com/__/auth/" +
  29. "action?apiKey%3DtestAPIKey%26mode%3DsignIn%26oobCode%3Dtestoobcode%26continueUrl%3Dhttps://" +
  30. "test.apps.com"
  31. let kFakeEmailSignInDeeplink =
  32. "https://example.domain.com/?apiKey=testAPIKey&oobCode=testoobcode&mode=signIn"
  33. let kContinueURL = "continueURL"
  34. let kIosBundleID = "testBundleID"
  35. let kAndroidPackageName = "androidpackagename"
  36. let kAndroidMinimumVersion = "3.0"
  37. let kDynamicLinkDomain = "test.page.link"
  38. let kLinkDomain = "link.firebaseapp.com"
  39. let kTestPhotoURL = "https://host.domain/image"
  40. let kCreationDateTimeIntervalInSeconds = 1_505_858_500.0
  41. let kLastSignInDateTimeIntervalInSeconds = 1_505_858_583.0
  42. let kTestPhoneNumber = "415-555-1234"
  43. let kIdToken = "FAKE_ID_TOKEN"
  44. static let kOAuthSessionID = "sessionID"
  45. static let kOAuthRequestURI = "requestURI"
  46. let kGoogleIDToken = "GOOGLE_ID_TOKEN"
  47. let kGoogleAccessToken = "GOOGLE_ACCESS_TOKEN"
  48. let kGoogleID = "GOOGLE_ID"
  49. let kGoogleEmail = "usergmail.com"
  50. let kGoogleDisplayName = "Google Doe"
  51. let kGoogleProfile = ["email": "usergmail.com", "given_name": "MyFirst", "family_name": "MyLast"]
  52. let kUserName = "User Doe"
  53. /** @var kTestAPIKey
  54. @brief Fake API key used for testing.
  55. */
  56. let kTestAPIKey = "APIKey"
  57. /** @var kTestFirebaseAppID
  58. @brief Fake Firebase app ID used for testing.
  59. */
  60. let kTestFirebaseAppID = "appID"
  61. /** @var kTestIdentifier
  62. @brief Fake identifier key used for testing.
  63. */
  64. let kTestIdentifier = "Identifier"
  65. var rpcIssuer: FakeBackendRPCIssuer!
  66. var authBackend: AuthBackend!
  67. override func setUp() {
  68. rpcIssuer = FakeBackendRPCIssuer()
  69. authBackend = AuthBackend(rpcIssuer: rpcIssuer)
  70. }
  71. override func tearDown() {
  72. rpcIssuer = nil
  73. authBackend = nil
  74. }
  75. /** @fn checkRequest
  76. @brief Tests the encoding of a request.
  77. */
  78. func checkRequest(request: any AuthRPCRequest,
  79. expected: String,
  80. key: String,
  81. value: String?,
  82. checkPostBody: Bool = false) async throws {
  83. rpcIssuer.respondBlock = {
  84. XCTAssertEqual(self.rpcIssuer.requestURL?.absoluteString, expected)
  85. if checkPostBody {
  86. XCTAssertNil(request.unencodedHTTPRequestBody)
  87. } else if let requestDictionary = self.rpcIssuer.decodedRequest as? [String: AnyHashable] {
  88. XCTAssertEqual(requestDictionary[key], value)
  89. } else {
  90. XCTFail("decodedRequest is not a dictionary")
  91. }
  92. // Dummy response to unblock await.
  93. return try self.rpcIssuer.respond(withJSON: [:])
  94. }
  95. let _ = try await authBackend.call(with: request)
  96. }
  97. /** @fn checkBackendError
  98. @brief This test checks error messages from the backend map to the expected error codes
  99. */
  100. func checkBackendError(request: any AuthRPCRequest,
  101. message: String = "",
  102. reason: String? = nil,
  103. json: [String: AnyHashable]? = nil,
  104. errorCode: AuthErrorCode,
  105. errorReason: String? = nil,
  106. underlyingErrorKey: String? = nil,
  107. checkLocalizedDescription: String? = nil) async throws {
  108. rpcIssuer.respondBlock = {
  109. if let json = json {
  110. return try self.rpcIssuer.respond(withJSON: json)
  111. } else if let reason = reason {
  112. return try self.rpcIssuer.respond(underlyingErrorMessage: reason, message: message)
  113. } else {
  114. return try self.rpcIssuer.respond(serverErrorMessage: message)
  115. }
  116. }
  117. do {
  118. let _ = try await authBackend.call(with: request)
  119. XCTFail("Did not throw expected error")
  120. return
  121. } catch {
  122. let rpcError = error as NSError
  123. XCTAssertEqual(rpcError.code, errorCode.rawValue)
  124. if errorCode == .internalError {
  125. let underlyingError = try XCTUnwrap(rpcError.userInfo[NSUnderlyingErrorKey] as? NSError)
  126. XCTAssertNotNil(underlyingError.userInfo[AuthErrorUtils.userInfoDeserializedResponseKey])
  127. }
  128. if let errorReason {
  129. XCTAssertEqual(errorReason, rpcError.userInfo[NSLocalizedFailureReasonErrorKey] as? String)
  130. }
  131. if let checkLocalizedDescription {
  132. let localizedDescription = try XCTUnwrap(rpcError
  133. .userInfo[NSLocalizedDescriptionKey] as? String)
  134. XCTAssertEqual(checkLocalizedDescription, localizedDescription)
  135. }
  136. }
  137. }
  138. func makeRequestConfiguration() -> AuthRequestConfiguration {
  139. return AuthRequestConfiguration(
  140. apiKey: kTestAPIKey,
  141. appID: kTestFirebaseAppID
  142. )
  143. }
  144. static let kFakeAccessToken =
  145. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZDBhODBiYzh" +
  146. "jM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  147. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vZmItc2EtdXBncm" +
  148. "FkZWQiLCJhdWQiOiJ0ZXN0X2F1ZCIsImF1dGhfdGltZSI6MTUyMjM2MDU0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZCIs" +
  149. "InN1YiI6InRlc3Rfc3ViIiwiaWF0IjoxNTIyMzYwNTU3LCJleHAiOjE1MjIzNjQxNTcsImVtYWlsIjoiYXVuaXRlc3R1c2" +
  150. "VyQGdtYWlsLmNvbSIsImVtYWlsX3ZlcmlmaWVkIjpmYWxzZSwiZmlyZWJhc2UiOnsiaWRlbnRpdGllcyI6eyJlbWFpbCI6" +
  151. "WyJhdW5pdGVzdHVzZXJAZ21haWwuY29tIl19LCJzaWduX2luX3Byb3ZpZGVyIjoicGFzc3dvcmQifX0=." +
  152. "WFQqSrpVnxx7m" +
  153. "UrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  154. "BKkcbZuq8O7iDVpOvqKC" +
  155. "3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  156. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjN" +
  157. "hHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  158. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbW" +
  159. "lddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  160. static let kFakeAccessTokenLength415 =
  161. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZD" +
  162. "BhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  163. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vdGVzd" +
  164. "CIsImF1ZCI6InRlc3RfYXVkIiwiYXV0aF90aW1lIjoxNTIyMzYwNTQ5LCJ1c2VyX2lkIjoidGVzdF91c2VyX2lkIiwic3V" +
  165. "iIjoidGVzdF9zdWIiLCJpYXQiOjE1MjIzNjA1NTcsImV4cCI6MTUyMjM2NDE1NywiZW1haWwiOiJhdW5pdGVzdHVzZXJAZ" +
  166. "21haWwuY29tIiwiZW1haWxfdmVyaWZpZWQiOmZhbHNlLCJmaXJlYmFzZSI6eyJpZGVudGl0aWVzIjp7ImVtYWlsIjpbImF" +
  167. "1bml0ZXN0dXNlckBnbWFpbC5jb20iXX0sInNpZ25faW5fcHJvdmlkZXIiOiJwYXNzd29yZCJ9fQ=.WFQqSrpVnxx7m" +
  168. "UrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  169. "BKkcbZuq8O7iDVpOvqKC" +
  170. "3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  171. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjN" +
  172. "hHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  173. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbW" +
  174. "lddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  175. static let kFakeAccessTokenLength416 =
  176. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZD" +
  177. "BhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  178. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vdGVzd" +
  179. "DIiLCJhdWQiOiJ0ZXN0X2F1ZCIsImF1dGhfdGltZSI6MTUyMjM2MDU0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZCIsInN" +
  180. "1YiI6InRlc3Rfc3ViIiwiaWF0IjoxNTIyMzYwNTU3LCJleHAiOjE1MjIzNjQxNTcsImVtYWlsIjoiYXVuaXRlc3R1c2VyQ" +
  181. "GdtYWlsLmNvbSIsImVtYWlsX3ZlcmlmaWVkIjpmYWxzZSwiZmlyZWJhc2UiOnsiaWRlbnRpdGllcyI6eyJlbWFpbCI6WyJ" +
  182. "hdW5pdGVzdHVzZXJAZ21haWwuY29tIl19LCJzaWduX2luX3Byb3ZpZGVyIjoicGFzc3dvcmQifX0=.WFQqSrpVnxx7m" +
  183. "UrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  184. "BKkcbZuq8O7iDVpOvqKC" +
  185. "3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  186. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjN" +
  187. "hHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  188. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbW" +
  189. "lddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  190. static let kFakeAccessTokenLength523 =
  191. "eyJhbGciOimnuzI1NiIsImtpZCI6ImY1YjE4Mjc2YTQ4NjYxZD" +
  192. "BhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  193. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2dsZS5jb20vdGVzd" +
  194. "DQiLCJhdWQiOiJ0ZXN0X2F1ZCIsImF1dGhfdGltZSI6MTUyMjM2MDU0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZF81NDM" +
  195. "yIiwic3ViIjoidGVzdF9zdWIiLCJpYXQiOjE1MjIzNjA1NTcsImV4cCI6MTUyMjM2NDE1OSwiZW1haWwiOiJhdW5pdGVzd" +
  196. "HVzZXI0QGdtYWlsLmNvbSIsImVtYWlsX3ZlcmlmaWVkIjp0cnVlLCJmaXJlYmFzZSI6eyJpZGVudGl0aWVzIjp7ImVtYWl" +
  197. "sIjpbImF1bml0ZXN0dXNlckBnbWFpbC5jb20iXX0sInNpZ25faW5fcHJvdmlkZXIiOiJwYXNzd29yZCJ9fQ=." +
  198. "WFQqSrpVn" +
  199. "xx7mUrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-aTYMvND3-4aS3qRnN2kvk9KJAaF3eI_" +
  200. "BKkcbZuq8O7iDVpO" +
  201. "vqKC3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  202. "XtBt1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH" +
  203. "7jjNhHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  204. "dDV7jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqV" +
  205. "kPbWlddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  206. static let kFakeAccessTokenWithBase64 =
  207. "ey?hbGciOimnuzI1NiIsImtpZCI6ImY1YjE4M" +
  208. "jc2YTQ4NjYxZDBhODBiYzhjM2U5NDM0OTc0ZDFmMWRiNTEifQ." +
  209. "eyJpc3MiOiJodHRwczovL3NlY3VyZXRva2VuLmdvb2ds" +
  210. "ZS5jb20vZmItc2EtdXBncmFkZWQiLCJhdWQiOiI_Pz8_Pz8_Pz8_Pj4-Pj4-Pj4-" +
  211. "PiIsImF1dGhfdGltZSI6MTUyMjM2MD" +
  212. "U0OSwidXNlcl9pZCI6InRlc3RfdXNlcl9pZCIsInN1YiI6InRlc3Rfc3ViIiwiaWF0IjoxNTIyMzYwNTU3LCJleHAiOjE1" +
  213. "MjIzNjQxNTcsImVtYWlsIjoiPj4-Pj4-Pj4_Pz8_Pz8_" +
  214. "P0BnbWFpbC5jb20iLCJlbWFpbF92ZXJpZmllZCI6ZmFsc2UsIm" +
  215. "ZpcmViYXNlIjp7ImlkZW50aXRpZXMiOnsiZW1haWwiOlsiYXVuaXRlc3R1c2VyQGdtYWlsLmNvbSJdfSwic2lnbl9pbl9w" +
  216. "cm92aWRlciI6IlBhc3N3b3JkIn19.WFQqSrpVnxx7mUrdKZA517Sp4ZBt-l2xQzGKNMVE90JB3vuNa-NyWZC-" +
  217. "aTYMvND3-" +
  218. "4aS3qRnN2kvk9KJAaF3eI_BKkcbZuq8O7iDVpOvqKC3QcW0PnwqSPChL3XqoDF322FcBEgemwwgaEVZMuo7GhJvHw-" +
  219. "XtBt" +
  220. "1KRXOoGHcr3P6RsvoulUouKQmqt6TP27eZtrgH7jjNhHm7gjX_WaRmgTOvYsuDbBBGdE15yIVZ3acI4cFUgwMRhaW-" +
  221. "dDV7" +
  222. "jTOqZGYJlTsI5oRMehphoVnYnEedJga28r4mqVkPbWlddL4dVVm85FYmQcRc0b2CLMnSevBDlwu754ZUZmRgnuvDA"
  223. func setFakeSecureTokenService(fakeAccessToken: String = RPCBaseTests.kFakeAccessToken) {
  224. rpcIssuer?.fakeSecureTokenServiceJSON = ["access_token": fakeAccessToken,
  225. "expires_in": "3600"]
  226. }
  227. func setFakeGetAccountProvider(withNewDisplayName displayName: String = "User Doe",
  228. withLocalID localID: String = "testLocalId",
  229. withProviderID providerID: String = "testProviderID",
  230. withFederatedID federatedID: String = "testFederatedId",
  231. withEmail email: String = "user@company.com",
  232. withPasswordHash passwordHash: String? = nil) {
  233. let kProviderUserInfoKey = "providerUserInfo"
  234. let kPhotoUrlKey = "photoUrl"
  235. let kProviderIDkey = "providerId"
  236. let kDisplayNameKey = "displayName"
  237. let kFederatedIDKey = "federatedId"
  238. let kEmailKey = "email"
  239. let kPasswordHashKey = "passwordHash"
  240. let kTestPasswordHash = passwordHash
  241. let kEmailVerifiedKey = "emailVerified"
  242. let kLocalIDKey = "localId"
  243. rpcIssuer?.fakeGetAccountProviderJSON = [[
  244. kProviderUserInfoKey: [[
  245. kProviderIDkey: providerID,
  246. kDisplayNameKey: displayName,
  247. kPhotoUrlKey: kTestPhotoURL,
  248. kFederatedIDKey: federatedID,
  249. kEmailKey: email,
  250. ]],
  251. kLocalIDKey: localID,
  252. kDisplayNameKey: displayName,
  253. kEmailKey: email,
  254. kPhotoUrlKey: kTestPhotoURL,
  255. kEmailVerifiedKey: true,
  256. kPasswordHashKey: kTestPasswordHash,
  257. "phoneNumber": kTestPhoneNumber,
  258. ]]
  259. }
  260. func setFakeGoogleGetAccountProvider() {
  261. setFakeGetAccountProvider(withNewDisplayName: kGoogleDisplayName,
  262. withProviderID: GoogleAuthProvider.id,
  263. withFederatedID: kGoogleID,
  264. withEmail: kGoogleEmail)
  265. }
  266. func setFakeGetAccountProviderAnonymous() {
  267. let kPasswordHashKey = "passwordHash"
  268. let kTestPasswordHash = "testPasswordHash"
  269. let kLocalIDKey = "localId"
  270. rpcIssuer?.fakeGetAccountProviderJSON = [[
  271. kLocalIDKey: kLocalID,
  272. kPasswordHashKey: kTestPasswordHash,
  273. ]]
  274. }
  275. func fakeActionCodeSettings() -> ActionCodeSettings {
  276. let settings = ActionCodeSettings()
  277. settings.iOSBundleID = kIosBundleID
  278. settings.setAndroidPackageName(kAndroidPackageName,
  279. installIfNotAvailable: true,
  280. minimumVersion: kAndroidMinimumVersion)
  281. settings.handleCodeInApp = true
  282. settings.url = URL(string: kContinueURL)
  283. settings.dynamicLinkDomain = kDynamicLinkDomain
  284. settings.linkDomain = kLinkDomain
  285. return settings
  286. }
  287. func assertUserGoogle(_ user: User?) throws {
  288. let user = try XCTUnwrap(user)
  289. XCTAssertEqual(user.uid, kLocalID)
  290. XCTAssertEqual(user.displayName, kGoogleDisplayName)
  291. XCTAssertEqual(user.providerData.count, 1)
  292. let googleUserInfo = user.providerData[0]
  293. XCTAssertEqual(googleUserInfo.providerID, GoogleAuthProvider.id)
  294. XCTAssertEqual(googleUserInfo.uid, kGoogleID)
  295. XCTAssertEqual(googleUserInfo.displayName, kGoogleDisplayName)
  296. XCTAssertEqual(googleUserInfo.email, kGoogleEmail)
  297. }
  298. /// Sleep long enough for pending async task to start.
  299. static func waitSleep() {
  300. usleep(10000)
  301. }
  302. }