test: device login through a later issuer-bound authorization server
Extend the real-wire device fixture with a `multi_issuer` mode whose protected-resource metadata lists an issuer-mismatching server before the valid one, and run the production CLI login through it. Red on main (`Authorization server metadata issuer mismatch`), green with the scan. Ported from PR #112068.
This commit is contained in:
@@ -46,7 +46,8 @@ def oauth_fixture(mode="success"):
|
||||
return self.reply(401, {}, {"WWW-Authenticate": f'Bearer resource_metadata="{base}/prm"'})
|
||||
if self.path == "/prm" or "oauth-protected-resource" in self.path:
|
||||
return self.reply(200, {"resource": base + ("/wrong" if mode == "resource" else "/mcp"),
|
||||
"authorization_servers": [base]})
|
||||
"authorization_servers": ([base + "/wrong", base]
|
||||
if mode == "multi_issuer" else [base])})
|
||||
if "oauth-authorization-server" in self.path:
|
||||
metadata = {"issuer": base + ("/wrong" if mode == "issuer" else ""),
|
||||
"authorization_endpoint": base + "/authorize", "token_endpoint": base + "/token",
|
||||
|
||||
@@ -6,7 +6,7 @@ import pytest
|
||||
from evals.mcp_device_flow import DEVICE_GRANT, run_cli
|
||||
|
||||
|
||||
@pytest.mark.parametrize("mode", ["success", "preregistered"])
|
||||
@pytest.mark.parametrize("mode", ["success", "preregistered", "multi_issuer"])
|
||||
def test_device_login_registers_authorizes_and_persists(mode):
|
||||
result = run_cli(Path(__file__).resolve().parents[2], mode)
|
||||
assert result["token_persisted"], result
|
||||
@@ -20,7 +20,7 @@ def test_device_login_registers_authorizes_and_persists(mode):
|
||||
assert all(row["data"]["resource"].endswith("/mcp") for row in polls)
|
||||
if mode == "success":
|
||||
assert polls[2]["at"] - polls[1]["at"] >= 5
|
||||
else:
|
||||
elif mode == "preregistered":
|
||||
assert not any(row["path"] == "/register" for row in result["wire"])
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user