test: move jwt iat claim test from io tests to spec tests
Signed-off-by: Taimoor Zaeem <taimoorzaeem@gmail.com>
This commit is contained in:
committed by
Steve Chavez
parent
feb4853273
commit
0bc9fe813f
@@ -3,7 +3,6 @@
|
|||||||
from datetime import datetime, timedelta, timezone
|
from datetime import datetime, timedelta, timezone
|
||||||
from operator import attrgetter
|
from operator import attrgetter
|
||||||
import signal
|
import signal
|
||||||
import time
|
|
||||||
import pytest
|
import pytest
|
||||||
|
|
||||||
from config import BASEDIR, CONFIGSDIR, FIXTURES, SECRET
|
from config import BASEDIR, CONFIGSDIR, FIXTURES, SECRET
|
||||||
@@ -115,28 +114,6 @@ def test_jwt_aud_in_role_claim_key(jwtaudroleclaim, defaultenv):
|
|||||||
assert response.status_code == jwtaudroleclaim["expected_status"]
|
assert response.status_code == jwtaudroleclaim["expected_status"]
|
||||||
|
|
||||||
|
|
||||||
def test_iat_claim(defaultenv):
|
|
||||||
"""
|
|
||||||
A claim with an 'iat' (issued at) attribute should be successful.
|
|
||||||
|
|
||||||
The PostgREST time cache leads to issues here, see:
|
|
||||||
https://github.com/PostgREST/postgrest/issues/1139
|
|
||||||
|
|
||||||
"""
|
|
||||||
|
|
||||||
env = {**defaultenv, "PGRST_JWT_SECRET": SECRET}
|
|
||||||
|
|
||||||
claim = {"role": "postgrest_test_author", "iat": datetime.now(timezone.utc)}
|
|
||||||
headers = jwtauthheader(claim, SECRET)
|
|
||||||
|
|
||||||
with run(env=env) as postgrest:
|
|
||||||
for _ in range(10):
|
|
||||||
response = postgrest.session.get("/authors_only", headers=headers)
|
|
||||||
assert response.status_code == 200
|
|
||||||
|
|
||||||
time.sleep(0.1)
|
|
||||||
|
|
||||||
|
|
||||||
def test_jwt_secret_reload(tmp_path, defaultenv):
|
def test_jwt_secret_reload(tmp_path, defaultenv):
|
||||||
"JWT secret should be reloaded from file when PostgREST is sent SIGUSR2."
|
"JWT secret should be reloaded from file when PostgREST is sent SIGUSR2."
|
||||||
config = (CONFIGSDIR / "sigusr2-settings.config").read_text()
|
config = (CONFIGSDIR / "sigusr2-settings.config").read_text()
|
||||||
|
|||||||
@@ -84,6 +84,13 @@ spec withConfig = withConfig baseCfg $ describe "authorization" $ do
|
|||||||
request methodGet "/authors_only" [auth] ""
|
request methodGet "/authors_only" [auth] ""
|
||||||
`shouldRespondWith` 200
|
`shouldRespondWith` 200
|
||||||
|
|
||||||
|
it "succeeds with a valid iat claim in jwt" $ do
|
||||||
|
currentTime <- liftIO $ relativeSeconds 0
|
||||||
|
let jwtPayload = [json|{ "role": "postgrest_test_author", "iat": #{currentTime} }|]
|
||||||
|
auth = authHeaderJWT $ generateJWT jwtPayload
|
||||||
|
request methodGet "/authors_only" [auth] ""
|
||||||
|
`shouldRespondWith` 200
|
||||||
|
|
||||||
it "fails when auth header is sent empty" $ do
|
it "fails when auth header is sent empty" $ do
|
||||||
let auth = authHeaderJWT ""
|
let auth = authHeaderJWT ""
|
||||||
request methodGet "/authors_only" [auth] ""
|
request methodGet "/authors_only" [auth] ""
|
||||||
|
|||||||
Reference in New Issue
Block a user