-
Notifications
You must be signed in to change notification settings - Fork 8
Expand file tree
/
Copy pathTokenValidationShould.cs
More file actions
88 lines (69 loc) · 2.71 KB
/
TokenValidationShould.cs
File metadata and controls
88 lines (69 loc) · 2.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
using AzureFunctions.Extensions.OpenIDConnect.Tests;
namespace AzureFunctions.Extensions.OpenIDConnect.InProcess.Tests
{
using Configuration;
using FluentAssertions;
using Microsoft.Extensions.DependencyInjection;
using Microsoft.IdentityModel.Tokens;
using NUnit.Framework;
using System.Collections.Generic;
public class TokenValidationShould
{
[Test]
public void BeSecure_When_Using_Audience_And_Issuer()
{
// Arrange
var collection = ServiceCollectionFixture.MinimalAzFunctionsServices();
var audience = "my_audience";
var issuer = "https://me.secure.com";
collection.AddOpenIDConnect(builder =>
{
builder.SetIssuerBaseUrlConfiguration("http://anyurl.com");
builder.SetTokenValidation(audience, issuer);
});
var provider = collection.BuildServiceProvider();
var expected = new TokenValidationParameters
{
RequireSignedTokens = true,
ValidateIssuerSigningKey = true,
ValidateLifetime = true,
ValidateAudience = true,
ValidAudience = audience,
ValidateIssuer = true,
ValidIssuer = issuer
};
// Act
var tokenValidationParameters = provider.GetService<TokenValidationParameters>();
// Assert
tokenValidationParameters.Should().BeEquivalentTo(expected);
}
[Test]
public void BeSecure_When_Using_Audiences_And_Issuer()
{
// Arrange
var collection = ServiceCollectionFixture.MinimalAzFunctionsServices();
var audiences = new List<string> { "my_audience_1", "my_audience_2" };
var issuer = "https://me.secure.com";
collection.AddOpenIDConnect(builder =>
{
builder.SetIssuerBaseUrlConfiguration("http://anyurl.com");
builder.SetTokenValidation(audiences, issuer);
});
var provider = collection.BuildServiceProvider();
var expected = new TokenValidationParameters
{
RequireSignedTokens = true,
ValidateIssuerSigningKey = true,
ValidateLifetime = true,
ValidateAudience = true,
ValidAudiences = audiences,
ValidateIssuer = true,
ValidIssuer = issuer
};
// Act
var tokenValidationParameters = provider.GetService<TokenValidationParameters>();
// Assert
tokenValidationParameters.Should().BeEquivalentTo(expected);
}
}
}