Check the state (#509)

* - Verify that the state received alongside the authorization code is consistent with the one sent
- Refactor URL parsing for the local server way and the interactive way
- Add tests for interactive way

* Resurrect public methods parse_response_code and get_authorization_code

* Use new method parse_oatuh_response_url for parse_response_code implementation.
This commit is contained in:
foobuzz authored and GitHub committed 2020-06-20 21:48:19 +01:00
1 parent d7ebc611b2
commit ed136d15df
3 files changed
+75 -20

No files matched your search

+41 -1
View File
@@ -119,7 +119,7 @@ class OAuthCacheTest(unittest.TestCase):
self.assertTrue(fi.write.called)
class TestSpotifyOAuth(unittest.TestCase):
class TestSpotifyOAuthGetAuthorizeUrl(unittest.TestCase):
def test_get_authorize_url_doesnt_pass_state_by_default(self):
oauth = SpotifyOAuth("CLID", "CLISEC", "REDIR")
@@ -168,6 +168,46 @@ class TestSpotifyOAuth(unittest.TestCase):
parsed_qs = urllibparse.parse_qs(parsed_url.query)
self.assertTrue(parsed_qs['show_dialog'])
class TestSpotifyOAuthGetAuthResponseInteractive(unittest.TestCase):
@patch('spotipy.oauth2.webbrowser')
@patch(
'spotipy.oauth2.SpotifyOAuth._get_user_input',
return_value="redir.io?code=abcde"
)
def test_get_auth_response_without_state(self, webbrowser_mock, get_user_input_mock):
oauth = SpotifyOAuth("CLID", "CLISEC", "redir.io")
code = oauth.get_auth_response()
self.assertEqual(code, "abcde")
@patch('spotipy.oauth2.webbrowser')
@patch(
'spotipy.oauth2.SpotifyOAuth._get_user_input',
return_value="redir.io?code=abcde&state=wxyz"
)
def test_get_auth_response_with_consistent_state(self, webbrowser_mock, get_user_input_mock):
oauth = SpotifyOAuth("CLID", "CLISEC", "redir.io", state='wxyz')
code = oauth.get_auth_response()
self.assertEqual(code, "abcde")
@patch('spotipy.oauth2.webbrowser')
@patch(
'spotipy.oauth2.SpotifyOAuth._get_user_input',
return_value="redir.io?code=abcde&state=someotherstate"
)
def test_get_auth_response_with_inconsistent_state(self, webbrowser_mock, get_user_input_mock):
oauth = SpotifyOAuth("CLID", "CLISEC", "redir.io", state='wxyz')
with self.assertRaisesRegexp(
SpotifyOauthError,
"Received inconsistent state from OAuth server."
):
oauth.get_auth_response()
class TestSpotifyClientCredentials(unittest.TestCase):
def test_spotify_client_credentials_get_access_token(self):
oauth = SpotifyClientCredentials(client_id='ID', client_secret='SECRET')
with self.assertRaises(SpotifyOauthError) as error: