2023-07-10 15:27:00 +02:00
|
|
|
package query
|
|
|
|
|
|
|
|
import (
|
2024-12-19 10:37:46 +01:00
|
|
|
"context"
|
2023-07-10 15:27:00 +02:00
|
|
|
"database/sql"
|
|
|
|
"database/sql/driver"
|
|
|
|
_ "embed"
|
|
|
|
"fmt"
|
|
|
|
"regexp"
|
|
|
|
"testing"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/muhlemmer/gu"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
|
|
|
|
"github.com/zitadel/zitadel/internal/api/authz"
|
|
|
|
"github.com/zitadel/zitadel/internal/database"
|
|
|
|
"github.com/zitadel/zitadel/internal/domain"
|
|
|
|
"github.com/zitadel/zitadel/internal/query/projection"
|
2023-12-08 16:30:55 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/zerrors"
|
2023-07-10 15:27:00 +02:00
|
|
|
)
|
|
|
|
|
|
|
|
func TestQueries_AuthRequestByID(t *testing.T) {
|
|
|
|
expQuery := regexp.QuoteMeta(fmt.Sprintf(
|
|
|
|
authRequestByIDQuery,
|
|
|
|
asOfSystemTime,
|
|
|
|
))
|
|
|
|
|
|
|
|
cols := []string{
|
|
|
|
projection.AuthRequestColumnID,
|
|
|
|
projection.AuthRequestColumnCreationDate,
|
|
|
|
projection.AuthRequestColumnLoginClient,
|
|
|
|
projection.AuthRequestColumnClientID,
|
|
|
|
projection.AuthRequestColumnScope,
|
|
|
|
projection.AuthRequestColumnRedirectURI,
|
|
|
|
projection.AuthRequestColumnPrompt,
|
|
|
|
projection.AuthRequestColumnUILocales,
|
|
|
|
projection.AuthRequestColumnLoginHint,
|
|
|
|
projection.AuthRequestColumnMaxAge,
|
|
|
|
projection.AuthRequestColumnHintUserID,
|
|
|
|
}
|
|
|
|
type args struct {
|
|
|
|
shouldTriggerBulk bool
|
|
|
|
id string
|
|
|
|
checkLoginClient bool
|
|
|
|
}
|
|
|
|
tests := []struct {
|
2024-12-19 10:37:46 +01:00
|
|
|
name string
|
|
|
|
args args
|
|
|
|
expect sqlExpectation
|
|
|
|
permissionCheck domain.PermissionCheck
|
|
|
|
want *AuthRequest
|
|
|
|
wantErr error
|
2023-07-10 15:27:00 +02:00
|
|
|
}{
|
|
|
|
{
|
|
|
|
name: "success, all values",
|
|
|
|
args: args{
|
|
|
|
shouldTriggerBulk: false,
|
|
|
|
id: "123",
|
|
|
|
checkLoginClient: true,
|
|
|
|
},
|
|
|
|
expect: mockQuery(expQuery, cols, []driver.Value{
|
|
|
|
"id",
|
|
|
|
testNow,
|
|
|
|
"loginClient",
|
|
|
|
"clientID",
|
2023-10-19 12:19:10 +02:00
|
|
|
database.TextArray[string]{"a", "b", "c"},
|
2023-07-10 15:27:00 +02:00
|
|
|
"example.com",
|
2024-03-27 14:48:22 +01:00
|
|
|
database.NumberArray[domain.Prompt]{domain.PromptLogin, domain.PromptConsent},
|
2023-10-19 12:19:10 +02:00
|
|
|
database.TextArray[string]{"en", "fi"},
|
2023-07-10 15:27:00 +02:00
|
|
|
"me@example.com",
|
|
|
|
int64(time.Minute),
|
|
|
|
"userID",
|
|
|
|
}, "123", "instanceID"),
|
|
|
|
want: &AuthRequest{
|
|
|
|
ID: "id",
|
|
|
|
CreationDate: testNow,
|
|
|
|
LoginClient: "loginClient",
|
|
|
|
ClientID: "clientID",
|
|
|
|
Scope: []string{"a", "b", "c"},
|
|
|
|
RedirectURI: "example.com",
|
|
|
|
Prompt: []domain.Prompt{domain.PromptLogin, domain.PromptConsent},
|
|
|
|
UiLocales: []string{"en", "fi"},
|
|
|
|
LoginHint: gu.Ptr("me@example.com"),
|
|
|
|
MaxAge: gu.Ptr(time.Minute),
|
|
|
|
HintUserID: gu.Ptr("userID"),
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "success, null values",
|
|
|
|
args: args{
|
|
|
|
shouldTriggerBulk: false,
|
|
|
|
id: "123",
|
|
|
|
checkLoginClient: true,
|
|
|
|
},
|
|
|
|
expect: mockQuery(expQuery, cols, []driver.Value{
|
|
|
|
"id",
|
|
|
|
testNow,
|
|
|
|
"loginClient",
|
|
|
|
"clientID",
|
2023-10-19 12:19:10 +02:00
|
|
|
database.TextArray[string]{"a", "b", "c"},
|
2023-07-10 15:27:00 +02:00
|
|
|
"example.com",
|
2024-03-27 14:48:22 +01:00
|
|
|
database.NumberArray[domain.Prompt]{domain.PromptLogin, domain.PromptConsent},
|
2023-10-19 12:19:10 +02:00
|
|
|
database.TextArray[string]{"en", "fi"},
|
2024-03-27 14:48:22 +01:00
|
|
|
nil,
|
|
|
|
nil,
|
|
|
|
nil,
|
2023-07-10 15:27:00 +02:00
|
|
|
}, "123", "instanceID"),
|
|
|
|
want: &AuthRequest{
|
|
|
|
ID: "id",
|
|
|
|
CreationDate: testNow,
|
|
|
|
LoginClient: "loginClient",
|
|
|
|
ClientID: "clientID",
|
|
|
|
Scope: []string{"a", "b", "c"},
|
|
|
|
RedirectURI: "example.com",
|
|
|
|
Prompt: []domain.Prompt{domain.PromptLogin, domain.PromptConsent},
|
|
|
|
UiLocales: []string{"en", "fi"},
|
|
|
|
LoginHint: nil,
|
|
|
|
MaxAge: nil,
|
|
|
|
HintUserID: nil,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "no rows",
|
|
|
|
args: args{
|
|
|
|
shouldTriggerBulk: false,
|
|
|
|
id: "123",
|
|
|
|
},
|
2023-08-22 14:49:02 +02:00
|
|
|
expect: mockQueryScanErr(expQuery, cols, nil, "123", "instanceID"),
|
2023-12-08 16:30:55 +02:00
|
|
|
wantErr: zerrors.ThrowNotFound(sql.ErrNoRows, "QUERY-Thee9", "Errors.AuthRequest.NotExisting"),
|
2023-07-10 15:27:00 +02:00
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "query error",
|
|
|
|
args: args{
|
|
|
|
shouldTriggerBulk: false,
|
|
|
|
id: "123",
|
|
|
|
},
|
|
|
|
expect: mockQueryErr(expQuery, sql.ErrConnDone, "123", "instanceID"),
|
2023-12-08 16:30:55 +02:00
|
|
|
wantErr: zerrors.ThrowInternal(sql.ErrConnDone, "QUERY-Ou8ue", "Errors.Internal"),
|
2023-07-10 15:27:00 +02:00
|
|
|
},
|
|
|
|
{
|
2024-12-19 10:37:46 +01:00
|
|
|
name: "wrong login client / not permitted",
|
2023-07-10 15:27:00 +02:00
|
|
|
args: args{
|
|
|
|
shouldTriggerBulk: false,
|
|
|
|
id: "123",
|
|
|
|
checkLoginClient: true,
|
|
|
|
},
|
|
|
|
expect: mockQuery(expQuery, cols, []driver.Value{
|
|
|
|
"id",
|
|
|
|
testNow,
|
|
|
|
"wrongLoginClient",
|
|
|
|
"clientID",
|
2023-10-19 12:19:10 +02:00
|
|
|
database.TextArray[string]{"a", "b", "c"},
|
2023-07-10 15:27:00 +02:00
|
|
|
"example.com",
|
2024-03-27 14:48:22 +01:00
|
|
|
database.NumberArray[domain.Prompt]{domain.PromptLogin, domain.PromptConsent},
|
2023-10-19 12:19:10 +02:00
|
|
|
database.TextArray[string]{"en", "fi"},
|
2024-03-27 14:48:22 +01:00
|
|
|
nil,
|
|
|
|
nil,
|
|
|
|
nil,
|
2023-07-10 15:27:00 +02:00
|
|
|
}, "123", "instanceID"),
|
2024-12-19 10:37:46 +01:00
|
|
|
permissionCheck: func(ctx context.Context, permission, orgID, resourceID string) (err error) {
|
|
|
|
return zerrors.ThrowPermissionDenied(nil, "id", "not permitted")
|
|
|
|
},
|
|
|
|
wantErr: zerrors.ThrowPermissionDenied(nil, "id", "not permitted"),
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "other login client / permitted",
|
|
|
|
args: args{
|
|
|
|
shouldTriggerBulk: false,
|
|
|
|
id: "123",
|
|
|
|
checkLoginClient: true,
|
|
|
|
},
|
|
|
|
expect: mockQuery(expQuery, cols, []driver.Value{
|
|
|
|
"id",
|
|
|
|
testNow,
|
|
|
|
"otherLoginClient",
|
|
|
|
"clientID",
|
|
|
|
database.TextArray[string]{"a", "b", "c"},
|
|
|
|
"example.com",
|
|
|
|
database.NumberArray[domain.Prompt]{domain.PromptLogin, domain.PromptConsent},
|
|
|
|
database.TextArray[string]{"en", "fi"},
|
|
|
|
nil,
|
|
|
|
nil,
|
|
|
|
nil,
|
|
|
|
}, "123", "instanceID"),
|
|
|
|
permissionCheck: func(ctx context.Context, permission, orgID, resourceID string) (err error) {
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
want: &AuthRequest{
|
|
|
|
ID: "id",
|
|
|
|
CreationDate: testNow,
|
|
|
|
LoginClient: "otherLoginClient",
|
|
|
|
ClientID: "clientID",
|
|
|
|
Scope: []string{"a", "b", "c"},
|
|
|
|
RedirectURI: "example.com",
|
|
|
|
Prompt: []domain.Prompt{domain.PromptLogin, domain.PromptConsent},
|
|
|
|
UiLocales: []string{"en", "fi"},
|
|
|
|
LoginHint: nil,
|
|
|
|
MaxAge: nil,
|
|
|
|
HintUserID: nil,
|
|
|
|
},
|
2023-07-10 15:27:00 +02:00
|
|
|
},
|
|
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
|
|
execMock(t, tt.expect, func(db *sql.DB) {
|
|
|
|
q := &Queries{
|
|
|
|
client: &database.DB{
|
|
|
|
DB: db,
|
|
|
|
Database: &prepareDB{},
|
|
|
|
},
|
2024-12-19 10:37:46 +01:00
|
|
|
checkPermission: tt.permissionCheck,
|
2023-07-10 15:27:00 +02:00
|
|
|
}
|
|
|
|
ctx := authz.NewMockContext("instanceID", "orgID", "loginClient")
|
|
|
|
|
|
|
|
got, err := q.AuthRequestByID(ctx, tt.args.shouldTriggerBulk, tt.args.id, tt.args.checkLoginClient)
|
|
|
|
require.ErrorIs(t, err, tt.wantErr)
|
|
|
|
assert.Equal(t, tt.want, got)
|
|
|
|
})
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|