feat(auth): add RP-initiated logout and OAuth unit tests

OAuth logout now terminates the IdP session via end_session_endpoint
with HTTPS-only URL validation. Adds 14 unit tests for PKCE and
OAuth discovery.
This commit is contained in:
Matthieu MALVACHE
2026-02-26 00:08:57 +01:00
committed by Matthieu MALVACHE
parent ec06b0c494
commit 7b6b8fc132
6 changed files with 218 additions and 16 deletions
+108
View File
@@ -0,0 +1,108 @@
import { describe, it, expect, vi, beforeEach } from 'vitest';
import type { OAuthMetadata } from '../oauth/discovery';
const VALID_METADATA: OAuthMetadata = {
issuer: 'https://auth.example.com',
authorization_endpoint: 'https://auth.example.com/authorize',
token_endpoint: 'https://auth.example.com/token',
revocation_endpoint: 'https://auth.example.com/revoke',
end_session_endpoint: 'https://auth.example.com/logout',
};
describe('oauth/discovery', () => {
let discoverOAuth: typeof import('../oauth/discovery').discoverOAuth;
beforeEach(async () => {
vi.restoreAllMocks();
vi.unstubAllGlobals();
vi.resetModules();
const mod = await import('../oauth/discovery');
discoverOAuth = mod.discoverOAuth;
});
it('discovers metadata from oauth-authorization-server', async () => {
vi.stubGlobal('fetch', vi.fn().mockResolvedValueOnce({
ok: true,
json: () => Promise.resolve(VALID_METADATA),
}));
const result = await discoverOAuth('https://mail.example.com');
expect(result).toEqual(VALID_METADATA);
expect(fetch).toHaveBeenCalledTimes(1);
expect(fetch).toHaveBeenCalledWith(
'https://mail.example.com/.well-known/oauth-authorization-server'
);
});
it('falls back to openid-configuration when first returns 404', async () => {
vi.stubGlobal('fetch', vi.fn()
.mockResolvedValueOnce({ ok: false, status: 404 })
.mockResolvedValueOnce({
ok: true,
json: () => Promise.resolve(VALID_METADATA),
}));
const result = await discoverOAuth('https://fallback.example.com');
expect(result).toEqual(VALID_METADATA);
expect(fetch).toHaveBeenCalledTimes(2);
expect(fetch).toHaveBeenNthCalledWith(
2,
'https://fallback.example.com/.well-known/openid-configuration'
);
});
it('returns null when both endpoints fail', async () => {
const consoleSpy = vi.spyOn(console, 'error').mockImplementation(() => {});
vi.stubGlobal('fetch', vi.fn()
.mockResolvedValueOnce({ ok: false, status: 404 })
.mockResolvedValueOnce({ ok: false, status: 404 }));
const result = await discoverOAuth('https://fail.example.com');
expect(result).toBeNull();
expect(consoleSpy).toHaveBeenCalled();
});
it('parses optional fields (revocation_endpoint, end_session_endpoint)', async () => {
vi.stubGlobal('fetch', vi.fn().mockResolvedValueOnce({
ok: true,
json: () => Promise.resolve(VALID_METADATA),
}));
const result = await discoverOAuth('https://optional.example.com');
expect(result?.revocation_endpoint).toBe('https://auth.example.com/revoke');
expect(result?.end_session_endpoint).toBe('https://auth.example.com/logout');
});
it('returns null when required fields (authorization_endpoint, token_endpoint) are missing', async () => {
const consoleSpy = vi.spyOn(console, 'error').mockImplementation(() => {});
vi.stubGlobal('fetch', vi.fn()
.mockResolvedValueOnce({
ok: true,
json: () => Promise.resolve({ issuer: 'https://auth.example.com' }),
})
.mockResolvedValueOnce({ ok: false, status: 404 }));
const result = await discoverOAuth('https://incomplete.example.com');
expect(result).toBeNull();
expect(consoleSpy).toHaveBeenCalled();
});
it('caches results — second call for same server URL does not re-fetch', async () => {
vi.stubGlobal('fetch', vi.fn().mockResolvedValueOnce({
ok: true,
json: () => Promise.resolve(VALID_METADATA),
}));
const first = await discoverOAuth('https://cached.example.com');
const second = await discoverOAuth('https://cached.example.com');
expect(first).toEqual(VALID_METADATA);
expect(second).toEqual(VALID_METADATA);
expect(fetch).toHaveBeenCalledTimes(1);
});
});
+61
View File
@@ -0,0 +1,61 @@
import { describe, it, expect } from 'vitest';
import { generateCodeVerifier, generateCodeChallenge, generateState } from '../oauth/pkce';
describe('oauth/pkce', () => {
describe('generateCodeVerifier', () => {
it('returns a 43-character base64url string', () => {
const verifier = generateCodeVerifier();
expect(verifier).toHaveLength(43);
expect(verifier).toMatch(/^[A-Za-z0-9_-]+$/);
});
it('contains no base64 padding or unsafe characters', () => {
for (let i = 0; i < 20; i++) {
const verifier = generateCodeVerifier();
expect(verifier).not.toMatch(/[+/=]/);
}
});
it('generates unique values', () => {
const a = generateCodeVerifier();
const b = generateCodeVerifier();
expect(a).not.toBe(b);
});
});
describe('generateCodeChallenge', () => {
it('returns a base64url string different from the verifier', async () => {
const verifier = generateCodeVerifier();
const challenge = await generateCodeChallenge(verifier);
expect(challenge).toMatch(/^[A-Za-z0-9_-]+$/);
expect(challenge).not.toBe(verifier);
});
it('produces the RFC 7636 Appendix B test vector', async () => {
const verifier = 'dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk';
const challenge = await generateCodeChallenge(verifier);
expect(challenge).toBe('E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM');
});
it('is deterministic for the same verifier', async () => {
const verifier = generateCodeVerifier();
const a = await generateCodeChallenge(verifier);
const b = await generateCodeChallenge(verifier);
expect(a).toBe(b);
});
});
describe('generateState', () => {
it('returns a 43-character base64url string', () => {
const state = generateState();
expect(state).toHaveLength(43);
expect(state).toMatch(/^[A-Za-z0-9_-]+$/);
});
it('generates unique values per call', () => {
const a = generateState();
const b = generateState();
expect(a).not.toBe(b);
});
});
});