3 # This file is part of Koha.
5 # Koha is free software; you can redistribute it and/or modify it under the
6 # terms of the GNU General Public License as published by the Free Software
7 # Foundation; either version 3 of the License, or (at your option) any later
10 # Koha is distributed in the hope that it will be useful, but WITHOUT ANY
11 # WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
12 # A PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 # You should have received a copy of the GNU General Public License along
15 # with Koha; if not, write to the Free Software Foundation, Inc.,
16 # 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
24 use Module::Load::Conditional qw(can_load);
31 use t::lib::TestBuilder;
33 my $t = Test::Mojo->new('Koha::REST::V1');
34 my $schema = Koha::Database->new->schema;
35 my $builder = t::lib::TestBuilder->new();
37 if ( can_load( modules => { 'Net::OAuth2::AuthorizationServer' => undef } ) ) {
41 plan skip_all => 'Net::OAuth2::AuthorizationServer not available';
44 subtest '/oauth/token tests' => sub {
48 $schema->storage->txn_begin;
50 my $patron = $builder->build_object({
51 class => 'Koha::Patrons',
53 flags => 0 # no permissions
57 # Missing parameter grant_type
58 $t->post_ok('/api/v1/oauth/token')
62 $t->post_ok('/api/v1/oauth/token', form => { grant_type => 'password' })
64 ->json_is({error => 'Unimplemented grant type'});
66 t::lib::Mocks::mock_preference('RESTOAuth2ClientCredentials', 1);
68 # No client_id/client_secret
69 $t->post_ok('/api/v1/oauth/token', form => { grant_type => 'client_credentials' })
71 ->json_is({error => 'unauthorized_client'});
73 my $api_key = Koha::ApiKey->new({ patron_id => $patron->id, description => 'blah' })->store;
76 grant_type => 'client_credentials',
77 client_id => $api_key->client_id,
78 client_secret => $api_key->secret
80 $t->post_ok('/api/v1/oauth/token', form => $formData)
82 ->json_is('/expires_in' => 3600)
83 ->json_is('/token_type' => 'Bearer')
84 ->json_has('/access_token');
86 my $access_token = $t->tx->res->json->{access_token};
88 # Without access token, it returns 401
89 $t->get_ok('/api/v1/patrons')->status_is(401);
91 # With access token, but without permissions, it returns 403
92 my $tx = $t->ua->build_tx(GET => '/api/v1/patrons');
93 $tx->req->headers->authorization("Bearer $access_token");
94 $t->request_ok($tx)->status_is(403);
96 # With access token and permissions, it returns 200
97 $patron->flags(2**4)->store;
98 $tx = $t->ua->build_tx(GET => '/api/v1/patrons');
99 $tx->req->headers->authorization("Bearer $access_token");
100 $t->request_ok($tx)->status_is(200);
103 my $token = Koha::OAuthAccessTokens->find($access_token);
104 $token->expires( time - 1 )->store;
105 $tx = $t->ua->build_tx( GET => '/api/v1/patrons' );
106 $tx->req->headers->authorization("Bearer $access_token");
111 $api_key->active(0)->store;
112 $t->post_ok('/api/v1/oauth/token', form => $formData)
114 ->json_is({ error => 'unauthorized_client' });
116 # disable client credentials grant
117 t::lib::Mocks::mock_preference('RESTOAuth2ClientCredentials', 0);
120 $api_key->active(1)->store;
122 $t->post_ok('/api/v1/oauth/token', form => $formData )
124 ->json_is({ error => 'Unimplemented grant type' });
126 $schema->storage->txn_rollback;
129 subtest 'Net::OAuth2::AuthorizationServer missing tests' => sub {
133 my $load_conditional = Test::MockModule->new('Module::Load::Conditional');
135 # Enable the client credentials grant syspref
136 t::lib::Mocks::mock_preference( 'RESTOAuth2ClientCredentials', 1 );
138 my $patron = $builder->build_object({ class => 'Koha::Patrons', value => { flags => 2**4 } });
139 my $api_key = Koha::ApiKey->new({ patron_id => $patron->id, description => 'blah' })->store;
142 grant_type => 'client_credentials',
143 client_id => $api_key->client_id,
144 client_secret => $api_key->secret
147 $t->post_ok( '/api/v1/oauth/token', form => $form_data )->status_is(200)
148 ->json_is( '/expires_in' => 3600 )->json_is( '/token_type' => 'Bearer' )
149 ->json_has('/access_token');
151 my $access_token = $t->tx->res->json->{access_token};
153 $load_conditional->mock( 'can_load', sub { return 0; } );
155 my $tx = $t->ua->build_tx( GET => '/api/v1/patrons' );
156 $tx->req->headers->authorization("Bearer $access_token");
160 $t->post_ok( '/api/v1/oauth/token', form => $form_data )
162 ->json_is( { error => 'Unimplemented grant type' } );