test: device login through a later issuer-bound authorization server

Extend the real-wire device fixture with a `multi_issuer` mode whose
protected-resource metadata lists an issuer-mismatching server before the
valid one, and run the production CLI login through it. Red on main
(`Authorization server metadata issuer mismatch`), green with the scan.

Ported from PR #112068.
This commit is contained in:
KoNit-K
2026-09-15 11:50:50 -07:00
committed by Teknium
parent e133f3f607
commit 551fe883d9
2 changed files with 4 additions and 3 deletions
+2 -1
View File
@@ -46,7 +46,8 @@ def oauth_fixture(mode="success"):
return self.reply(401, {}, {"WWW-Authenticate": f'Bearer resource_metadata="{base}/prm"'})
if self.path == "/prm" or "oauth-protected-resource" in self.path:
return self.reply(200, {"resource": base + ("/wrong" if mode == "resource" else "/mcp"),
"authorization_servers": [base]})
"authorization_servers": ([base + "/wrong", base]
if mode == "multi_issuer" else [base])})
if "oauth-authorization-server" in self.path:
metadata = {"issuer": base + ("/wrong" if mode == "issuer" else ""),
"authorization_endpoint": base + "/authorize", "token_endpoint": base + "/token",