Ticket #24932: oauth-remove-token.patch

File oauth-remove-token.patch, 4.2 KB (added by wangi, 19 hours ago)
  • src/org/openstreetmap/josm/io/auth/JosmPreferencesCredentialAgent.java

    diff --git src/org/openstreetmap/josm/io/auth/JosmPreferencesCredentialAgent.java src/org/openstreetmap/josm/io/auth/JosmPreferencesCredentialAgent.java
    index 6c228404b6..b23f2012e8 100644
    public class JosmPreferencesCredentialAgent extends AbstractCredentialsAgent {  
    134134            keySet.addAll(Config.getPref().getSensitive()); // Just in case we decide to not return sensitive keys in getKeySet
    135135            // Assume we want to remove all access tokens
    136136            for (OAuthVersion oauthType : OAuthVersion.values()) {
    137                 final String hostKey = "oauth.access-token.parameters." + oauthType + "." + host;
     137                final String hostKey = "oauth.access-token.object." + oauthType + "." + host;
    138138                final String parametersKey = "oauth.access-token.parameters." + oauthType + "." + host;
    139139                if (keySet.contains(hostKey)) {
    140140                    Config.getPref().removeSensitive(hostKey);
  • test/unit/org/openstreetmap/josm/io/auth/JosmPreferencesCredentialAgentTest.java

    diff --git test/unit/org/openstreetmap/josm/io/auth/JosmPreferencesCredentialAgentTest.java test/unit/org/openstreetmap/josm/io/auth/JosmPreferencesCredentialAgentTest.java
    index 8011cbc9c3..ef32f68bed 100644
     
    11// License: GPL. For details, see LICENSE file.
    22package org.openstreetmap.josm.io.auth;
    33
     4import static org.junit.jupiter.api.Assertions.assertFalse;
     5import static org.junit.jupiter.api.Assertions.assertNotNull;
     6import static org.junit.jupiter.api.Assertions.assertNull;
     7
     8import org.junit.jupiter.api.Test;
     9import org.openstreetmap.josm.data.oauth.OAuth20Exception;
     10import org.openstreetmap.josm.data.oauth.OAuth20Parameters;
     11import org.openstreetmap.josm.data.oauth.OAuth20Token;
     12import org.openstreetmap.josm.spi.preferences.Config;
     13import org.openstreetmap.josm.testutils.annotations.BasicPreferences;
    414import org.openstreetmap.josm.testutils.annotations.HTTP;
    515
    616/**
    … … class JosmPreferencesCredentialAgentTest implements CredentialsAgentTest<JosmPre  
    1323    public JosmPreferencesCredentialAgent createAgent() {
    1424        return new JosmPreferencesCredentialAgent();
    1525    }
     26
     27    /**
     28     * Removing an OAuth token removes it from the preferences, not only the parameters stored with it.
     29     * <p>
     30     * Non-regression test: both keys were built with the {@code parameters} prefix, so the token itself stayed in the
     31     * preferences in clear text. {@link CredentialsAgentTest#testLookupAndStoreOAuthTokens} did not notice, because a
     32     * lookup needs both keys and so already fails once the parameters are gone.
     33     * @throws CredentialsAgentException if the token cannot be stored or removed
     34     * @throws OAuth20Exception if the token cannot be built
     35     */
     36    @Test
     37    @BasicPreferences
     38    void testRemoveOAuthTokenRemovesItFromThePreferences() throws CredentialsAgentException, OAuth20Exception {
     39        final String host = "example.org";
     40        final String tokenKey = "oauth.access-token.object.OAuth20." + host;
     41        final String parametersKey = "oauth.access-token.parameters.OAuth20." + host;
     42        final JosmPreferencesCredentialAgent agent = createAgent();
     43        agent.storeOAuthAccessToken(host, new OAuth20Token(new OAuth20Parameters("clientId", null,
     44                "https://example.org/api", "https://example.org/api", "http://127.0.0.1:8111/oauth_authorization"),
     45                "{\"access_token\": \"a-secret-token\", \"token_type\": \"bearer\"}"));
     46        assertNotNull(Config.getPref().get(tokenKey, null));
     47        assertNotNull(Config.getPref().get(parametersKey, null));
     48
     49        agent.storeOAuthAccessToken(host, null);
     50
     51        assertNull(Config.getPref().get(tokenKey, null), "the token is still stored in the preferences");
     52        assertNull(Config.getPref().get(parametersKey, null));
     53        assertFalse(Config.getPref().getSensitive().contains(tokenKey));
     54        assertFalse(Config.getPref().getSensitive().contains(parametersKey));
     55    }
    1656}