Changeset 19638 in josm


Ignore:
Timestamp:
2026-10-06T09:00:18+02:00 (2 hours ago)
Author:
stoecker
Message:

oauth2 for a non-OSM fails setup on upload, patch by wangi, fix #24925

Location:
trunk
Files:
1 added
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/org/openstreetmap/josm/data/oauth/OAuthParameters.java

    r19627 r19638  
    263263                    return remembered;
    264264                }
    265                 return createDefault(apiUrl, oAuthVersion);
     265                // Use the URL as it was given: apiUrl is the host by now, which is never a valid URL, so
     266                // createDefault() would silently fall back to the API currently configured in the preferences.
     267                return createDefault(originalApiUrl, oAuthVersion);
    266268            default:
    267269                throw new IllegalArgumentException("Unknown OAuth version: " + oAuthVersion);
  • trunk/src/org/openstreetmap/josm/io/OsmConnection.java

    r19536 r19638  
    3434import org.openstreetmap.josm.tools.JosmRuntimeException;
    3535import org.openstreetmap.josm.tools.Logging;
     36import org.openstreetmap.josm.tools.Utils;
    3637
    3738/**
    … …  
    147148     */
    148149    private void obtainOAuth20Token() throws MissingOAuthAccessTokenException {
     150        if (Utils.isEmpty(this.oAuth20Parameters.getClientId())) {
     151            // Without a client id the authorization request is rejected by the server with "Missing required
     152            // parameter: client_id", so do not send the user to the browser at all. The message of the exception
     153            // is for the log only; what the user is shown already points at the preferences, which is where the
     154            // client id of an OAuth application registered on this server has to be entered.
     155            throw new MissingOAuthAccessTokenException(
     156                    "No OAuth client id for " + OsmApi.getOsmApi().getServerUrl() + ", cannot request a token");
     157        }
    149158        if (!Boolean.TRUE.equals(GuiHelper.runInEDTAndWaitAndReturn(() ->
    150159                ConditionalOptionPaneUtil.showConfirmationDialog("oauth.oauth20.obtain.automatically",
    … …  
    201210    protected void addOAuth20AuthorizationHeader(HttpClient connection) throws OsmTransferException {
    202211        if (this.oAuth20Parameters == null) {
    203             this.oAuth20Parameters = OAuthParameters.createFromApiUrl(connection.getURL().getHost(), OAuthVersion.OAuth20);
     212            // The parameters are stored under the API URL, so look them up with the API URL and not with the
     213            // host of the request: OAuthParameters.createFromApiUrl() reduces it to the host itself where that
     214            // is what it needs.
     215            this.oAuth20Parameters = OAuthParameters.createFromApiUrl(OsmApi.getOsmApi().getServerUrl(), OAuthVersion.OAuth20);
    204216        }
    205217        OAuthAccessTokenHolder holder = OAuthAccessTokenHolder.getInstance();
  • trunk/test/unit/org/openstreetmap/josm/data/oauth/OAuthParametersTest.java

    r19519 r19638  
    66import static org.junit.jupiter.api.Assertions.assertNotNull;
    77
     8import org.junit.jupiter.api.AfterEach;
    89import org.junit.jupiter.api.Test;
    910import org.openstreetmap.josm.TestUtils;
     11import org.openstreetmap.josm.io.NetworkManager;
     12import org.openstreetmap.josm.io.OnlineResource;
    1013import org.openstreetmap.josm.spi.preferences.Config;
     14import org.openstreetmap.josm.testutils.annotations.BasicPreferences;
    1115import org.openstreetmap.josm.tools.Logging;
    1216
    … …  
    1721 * Unit tests for class {@link OAuthParameters}.
    1822 */
     23@BasicPreferences
    1924class OAuthParametersTest {
     25
     26    @AfterEach
     27    void tearDown() {
     28        NetworkManager.setOnline(OnlineResource.ALL);
     29        // the API URL is static state shared with the other tests of this class
     30        Config.getPref().put("osm-server.url", null);
     31    }
     32
     33    /**
     34     * {@link OAuthParameters#createFromApiUrl} answers for the server it is asked about, whichever server is
     35     * configured in the preferences, and finds the parameters the user entered in the advanced OAuth settings.
     36     * <p>
     37     * Non-regression test for #24925: the URL was reduced to the host before the fallback to
     38     * {@link OAuthParameters#createDefault}, and a host is never a valid URL, so the defaults of the configured
     39     * API were returned instead of those of the server which was asked about.
     40     */
     41    @Test
     42    void testCreateFromApiUrlUsesTheRequestedServer() {
     43        // the RFC 8414 lookup must not make a network request
     44        NetworkManager.setOffline(OnlineResource.ALL);
     45        final String thirdParty = "https://nonprod-mapops.example.org/api";
     46        Config.getPref().put("osm-server.url", thirdParty);
     47
     48        // a server JOSM has a client id for is answered with that client id, not with the configured server's
     49        assertEquals("Hl5yIhFS-Egj6aY7A35ouLOuZl0EHjj8JJQQ46IO96E",
     50                OAuthParameters.createFromApiUrl("https://api.openhistoricalmap.org/api", OAuthVersion.OAuth20).getClientId());
     51        // a server JOSM knows nothing about has no client id until the user enters one
     52        assertEquals("", OAuthParameters.createFromApiUrl(thirdParty, OAuthVersion.OAuth20).getClientId());
     53
     54        // once the parameters are remembered - as the authentication preferences do, under the API URL - they
     55        // are found both by the API URL and by the host, which is what a connection has at hand
     56        new OAuth20Parameters("entered-client-id", null, thirdParty, thirdParty, "http://127.0.0.1:8111/oauth_authorization")
     57                .rememberPreferences();
     58        assertEquals("entered-client-id",
     59                OAuthParameters.createFromApiUrl(thirdParty, OAuthVersion.OAuth20).getClientId());
     60        assertEquals("https://api.openhistoricalmap.org/api",
     61                OAuthParameters.createFromApiUrl("https://api.openhistoricalmap.org/api", OAuthVersion.OAuth20).getApiUrl());
     62    }
     63
    2064    /**
    2165     * Unit test of method {@link OAuthParameters#createDefault}.
Note: See TracChangeset for help on using the changeset viewer.