Passed
Push — master ( f80f70...56399a )
by Thomas Mauro
03:05 queued 10s
created

RpNonceUnlessCodeFlowTest   A

Complexity

Total Complexity 3

Size/Duplication

Total Lines 38
Duplicated Lines 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
eloc 18
dl 0
loc 38
rs 10
c 1
b 0
f 0
wmc 3

2 Methods

Rating   Name   Duplication   Size   Complexity  
A getTestId() 0 3 1
A execute() 0 30 2
1
<?php
2
3
declare(strict_types=1);
4
5
namespace Facile\OpenIDClient\ConformanceTest\RpTest\NonceRequestParameter;
6
7
use PHPUnit\Framework\Assert;
8
use PHPUnit\Framework\AssertionFailedError;
9
use Facile\OpenIDClient\ConformanceTest\RpTest\AbstractRpTest;
10
use Facile\OpenIDClient\ConformanceTest\TestInfo;
11
use Facile\OpenIDClient\Exception\InvalidArgumentException;
12
use Facile\OpenIDClient\Session\AuthSession;
13
use Facile\OpenIDClient\Service\AuthorizationService;
14
use Facile\OpenIDClient\Service\UserInfoService;
15
use function Facile\OpenIDClient\base64url_encode;
16
17
/**
18
 * Always send a 'nonce' value as a request parameter while using implicit or hybrid flow.
19
 * Verify the 'nonce' value returned in the ID Token.
20
 *
21
 * An ID Token, either from the Authorization Endpoint or from the Token Endpoint, containing the same 'nonce' value
22
 * as passed in the authentication request when using hybrid flow or implicit flow.
23
 */
24
class RpNonceUnlessCodeFlowTest extends AbstractRpTest
25
{
26
27
    public function getTestId(): string
28
    {
29
        return 'rp-nonce-unless-code-flow';
30
    }
31
32
    public function execute(TestInfo $testInfo): void
33
    {
34
        $client = $this->registerClient($testInfo);
35
36
        $authorizationService = new AuthorizationService();
0 ignored issues
show
Bug introduced by
The call to Facile\OpenIDClient\Serv...nService::__construct() has too few arguments starting with tokenSetFactory. ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-call  annotation

36
        $authorizationService = /** @scrutinizer ignore-call */ new AuthorizationService();

This check compares calls to functions or methods with their respective definitions. If the call has less arguments than are defined, it raises an issue.

If a function is defined several times with a different number of parameters, the check may pick up the wrong definition and report false positives. One codebase where this has been known to happen is Wordpress. Please note the @ignore annotation hint above.

Loading history...
37
38
        try {
39
            $authorizationService->getAuthorizationUri($client, [
40
                'response_type' => $testInfo->getResponseType(),
41
            ]);
42
43
            throw new AssertionFailedError('No assertion');
44
        } catch (InvalidArgumentException $e) {
45
            Assert::assertRegExp('/nonce MUST be provided for implicit and hybrid flows/', $e->getMessage());
0 ignored issues
show
Deprecated Code introduced by
The function PHPUnit\Framework\Assert::assertRegExp() has been deprecated: https://github.com/sebastianbergmann/phpunit/issues/4086 ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-deprecated  annotation

45
            /** @scrutinizer ignore-deprecated */ Assert::assertRegExp('/nonce MUST be provided for implicit and hybrid flows/', $e->getMessage());

This function has been deprecated. The supplier of the function has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the function will be removed and what other function to use instead.

Loading history...
46
        }
47
48
        $nonce = base64url_encode(\random_bytes(32));
49
        $authSession = AuthSession::fromArray(['nonce' => $nonce]);
50
51
        $uri = $authorizationService->getAuthorizationUri($client, [
52
            'response_type' => $testInfo->getResponseType(),
53
            'nonce' => $nonce,
54
        ]);
55
        // Simulate a redirect and create the server request
56
        $serverRequest = $this->simulateAuthRedirect($uri);
57
58
        $params = $authorizationService->getCallbackParams($serverRequest, $client);
59
        $tokenSet = $authorizationService->callback($client, $params, null, $authSession);
0 ignored issues
show
Unused Code introduced by
The assignment to $tokenSet is dead and can be removed.
Loading history...
60
61
        Assert::assertTrue(true);
62
    }
63
}
64