| | 4 | import static org.junit.jupiter.api.Assertions.assertFalse; |
| | 5 | import static org.junit.jupiter.api.Assertions.assertNotNull; |
| | 6 | import static org.junit.jupiter.api.Assertions.assertNull; |
| | 7 | |
| | 8 | import org.junit.jupiter.api.Test; |
| | 9 | import org.openstreetmap.josm.data.oauth.OAuth20Exception; |
| | 10 | import org.openstreetmap.josm.data.oauth.OAuth20Parameters; |
| | 11 | import org.openstreetmap.josm.data.oauth.OAuth20Token; |
| | 12 | import org.openstreetmap.josm.spi.preferences.Config; |
| | 13 | import org.openstreetmap.josm.testutils.annotations.BasicPreferences; |
| | 26 | |
| | 27 | /** |
| | 28 | * Removing an OAuth token removes it from the preferences, not only the parameters stored with it. |
| | 29 | * <p> |
| | 30 | * Non-regression test: both keys were built with the {@code parameters} prefix, so the token itself stayed in the |
| | 31 | * preferences in clear text. {@link CredentialsAgentTest#testLookupAndStoreOAuthTokens} did not notice, because a |
| | 32 | * lookup needs both keys and so already fails once the parameters are gone. |
| | 33 | * @throws CredentialsAgentException if the token cannot be stored or removed |
| | 34 | * @throws OAuth20Exception if the token cannot be built |
| | 35 | */ |
| | 36 | @Test |
| | 37 | @BasicPreferences |
| | 38 | void testRemoveOAuthTokenRemovesItFromThePreferences() throws CredentialsAgentException, OAuth20Exception { |
| | 39 | final String host = "example.org"; |
| | 40 | final String tokenKey = "oauth.access-token.object.OAuth20." + host; |
| | 41 | final String parametersKey = "oauth.access-token.parameters.OAuth20." + host; |
| | 42 | final JosmPreferencesCredentialAgent agent = createAgent(); |
| | 43 | agent.storeOAuthAccessToken(host, new OAuth20Token(new OAuth20Parameters("clientId", null, |
| | 44 | "https://example.org/api", "https://example.org/api", "http://127.0.0.1:8111/oauth_authorization"), |
| | 45 | "{\"access_token\": \"a-secret-token\", \"token_type\": \"bearer\"}")); |
| | 46 | assertNotNull(Config.getPref().get(tokenKey, null)); |
| | 47 | assertNotNull(Config.getPref().get(parametersKey, null)); |
| | 48 | |
| | 49 | agent.storeOAuthAccessToken(host, null); |
| | 50 | |
| | 51 | assertNull(Config.getPref().get(tokenKey, null), "the token is still stored in the preferences"); |
| | 52 | assertNull(Config.getPref().get(parametersKey, null)); |
| | 53 | assertFalse(Config.getPref().getSensitive().contains(tokenKey)); |
| | 54 | assertFalse(Config.getPref().getSensitive().contains(parametersKey)); |
| | 55 | } |