Passed
Pull Request — master (#11)
by Pol
02:31
created

RpUserInfoBadSubClaimTest::getTestId()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 3
Code Lines 1

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 1
eloc 1
nc 1
nop 0
dl 0
loc 3
rs 10
c 1
b 0
f 0
1
<?php
2
3
declare(strict_types=1);
4
5
namespace Facile\OpenIDClient\ConformanceTest\RpTest\UserInfoEndpoint;
6
7
use PHPUnit\Framework\Assert;
8
use PHPUnit\Framework\AssertionFailedError;
9
use Facile\OpenIDClient\ConformanceTest\RpTest\AbstractRpTest;
10
use Facile\OpenIDClient\ConformanceTest\TestInfo;
11
use Facile\OpenIDClient\Session\AuthSession;
12
use Facile\OpenIDClient\Service\AuthorizationService;
13
use Facile\OpenIDClient\Service\UserInfoService;
14
use function Facile\OpenIDClient\base64url_encode;
15
16
/**
17
 * Make a UserInfo Request and verify the 'sub' value of the UserInfo Response by comparing it with the ID Token's 'sub' value.
18
 *
19
 * Identify the invalid 'sub' value and reject the UserInfo Response.
20
 */
21
class RpUserInfoBadSubClaimTest extends AbstractRpTest
22
{
23
    public function getTestId(): string
24
    {
25
        return 'rp-userinfo-bad-sub-claim';
26
    }
27
28
    public function execute(TestInfo $testInfo): void
29
    {
30
        $client = $this->registerClient($testInfo);
31
32
        // Get authorization redirect uri
33
        $authorizationService = new AuthorizationService();
0 ignored issues
show
Bug introduced by
The call to Facile\OpenIDClient\Serv...nService::__construct() has too few arguments starting with tokenSetFactory. ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-call  annotation

33
        $authorizationService = /** @scrutinizer ignore-call */ new AuthorizationService();

This check compares calls to functions or methods with their respective definitions. If the call has less arguments than are defined, it raises an issue.

If a function is defined several times with a different number of parameters, the check may pick up the wrong definition and report false positives. One codebase where this has been known to happen is Wordpress. Please note the @ignore annotation hint above.

Loading history...
34
        $userInfoService = new UserInfoService();
0 ignored issues
show
Bug introduced by
The call to Facile\OpenIDClient\Serv...oService::__construct() has too few arguments starting with userInfoVerifierBuilder. ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-call  annotation

34
        $userInfoService = /** @scrutinizer ignore-call */ new UserInfoService();

This check compares calls to functions or methods with their respective definitions. If the call has less arguments than are defined, it raises an issue.

If a function is defined several times with a different number of parameters, the check may pick up the wrong definition and report false positives. One codebase where this has been known to happen is Wordpress. Please note the @ignore annotation hint above.

Loading history...
35
36
        $authSession = AuthSession::fromArray([
37
            'nonce' => base64url_encode(\random_bytes(32)),
38
        ]);
39
        $uri = $authorizationService->getAuthorizationUri($client, [
40
            'response_type' => $testInfo->getResponseType(),
41
            'nonce' => $authSession->getNonce(),
42
        ]);
43
44
        // Simulate a redirect and create the server request
45
        $serverRequest = $this->simulateAuthRedirect($uri);
46
47
        $params = $authorizationService->getCallbackParams($serverRequest, $client);
48
        $tokenSet = $authorizationService->callback($client, $params, null, $authSession);
49
50
        try {
51
            $userInfoService->getUserInfo($client, $tokenSet);
52
            throw new AssertionFailedError('No assertions');
53
        } catch (\Throwable $e) {
54
            Assert::assertRegExp('/Userinfo sub mismatch/', $e->getMessage());
0 ignored issues
show
Deprecated Code introduced by
The function PHPUnit\Framework\Assert::assertRegExp() has been deprecated: https://github.com/sebastianbergmann/phpunit/issues/4086 ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-deprecated  annotation

54
            /** @scrutinizer ignore-deprecated */ Assert::assertRegExp('/Userinfo sub mismatch/', $e->getMessage());

This function has been deprecated. The supplier of the function has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the function will be removed and what other function to use instead.

Loading history...
55
        }
56
    }
57
}
58