1 /* 2 * Copyright 2019, Google LLC 3 * 4 * Redistribution and use in source and binary forms, with or without 5 * modification, are permitted provided that the following conditions are 6 * met: 7 * 8 * * Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * * Redistributions in binary form must reproduce the above 11 * copyright notice, this list of conditions and the following disclaimer 12 * in the documentation and/or other materials provided with the 13 * distribution. 14 * 15 * * Neither the name of Google LLC nor the names of its 16 * contributors may be used to endorse or promote products derived from 17 * this software without specific prior written permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 20 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 21 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR 22 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT 23 * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 24 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT 25 * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 26 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 27 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 28 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE 29 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 30 */ 31 32 package com.google.auth.oauth2; 33 34 import static org.junit.Assert.assertEquals; 35 import static org.junit.Assert.assertNotNull; 36 import static org.junit.Assert.assertNull; 37 import static org.junit.Assert.assertTrue; 38 39 import java.util.Collections; 40 import java.util.Map; 41 import org.junit.Test; 42 import org.junit.runner.RunWith; 43 import org.junit.runners.JUnit4; 44 45 @RunWith(JUnit4.class) 46 public class JwtClaimsTest { 47 48 @Test testMergeOverwritesFields()49 public void testMergeOverwritesFields() { 50 JwtClaims claims1 = 51 JwtClaims.newBuilder() 52 .setAudience("audience-1") 53 .setIssuer("issuer-1") 54 .setSubject("subject-1") 55 .build(); 56 JwtClaims claims2 = 57 JwtClaims.newBuilder() 58 .setAudience("audience-2") 59 .setIssuer("issuer-2") 60 .setSubject("subject-2") 61 .build(); 62 JwtClaims merged = claims1.merge(claims2); 63 64 assertEquals("audience-2", merged.getAudience()); 65 assertEquals("issuer-2", merged.getIssuer()); 66 assertEquals("subject-2", merged.getSubject()); 67 } 68 69 @Test testMergeDefaultValues()70 public void testMergeDefaultValues() { 71 JwtClaims claims1 = 72 JwtClaims.newBuilder() 73 .setAudience("audience-1") 74 .setIssuer("issuer-1") 75 .setSubject("subject-1") 76 .build(); 77 JwtClaims claims2 = JwtClaims.newBuilder().setAudience("audience-2").build(); 78 JwtClaims merged = claims1.merge(claims2); 79 80 assertEquals("audience-2", merged.getAudience()); 81 assertEquals("issuer-1", merged.getIssuer()); 82 assertEquals("subject-1", merged.getSubject()); 83 } 84 85 @Test testMergeNull()86 public void testMergeNull() { 87 JwtClaims claims1 = JwtClaims.newBuilder().build(); 88 JwtClaims claims2 = JwtClaims.newBuilder().build(); 89 JwtClaims merged = claims1.merge(claims2); 90 91 assertNull(merged.getAudience()); 92 assertNull(merged.getIssuer()); 93 assertNull(merged.getSubject()); 94 assertNotNull(merged.getAdditionalClaims()); 95 assertTrue(merged.getAdditionalClaims().isEmpty()); 96 } 97 98 @Test testEquals()99 public void testEquals() { 100 JwtClaims claims1 = 101 JwtClaims.newBuilder() 102 .setAudience("audience-1") 103 .setIssuer("issuer-1") 104 .setSubject("subject-1") 105 .build(); 106 JwtClaims claims2 = 107 JwtClaims.newBuilder() 108 .setAudience("audience-1") 109 .setIssuer("issuer-1") 110 .setSubject("subject-1") 111 .build(); 112 113 assertEquals(claims1, claims2); 114 } 115 116 @Test testAdditionalClaimsDefaults()117 public void testAdditionalClaimsDefaults() { 118 JwtClaims claims = JwtClaims.newBuilder().build(); 119 assertNotNull(claims.getAdditionalClaims()); 120 assertTrue(claims.getAdditionalClaims().isEmpty()); 121 } 122 123 @Test testMergeAdditionalClaims()124 public void testMergeAdditionalClaims() { 125 JwtClaims claims1 = 126 JwtClaims.newBuilder().setAdditionalClaims(Collections.singletonMap("foo", "bar")).build(); 127 JwtClaims claims2 = 128 JwtClaims.newBuilder() 129 .setAdditionalClaims(Collections.singletonMap("asdf", "qwer")) 130 .build(); 131 JwtClaims merged = claims1.merge(claims2); 132 133 assertNull(merged.getAudience()); 134 assertNull(merged.getIssuer()); 135 assertNull(merged.getSubject()); 136 Map<String, String> mergedAdditionalClaims = merged.getAdditionalClaims(); 137 assertNotNull(mergedAdditionalClaims); 138 assertEquals(2, mergedAdditionalClaims.size()); 139 assertEquals("bar", mergedAdditionalClaims.get("foo")); 140 assertEquals("qwer", mergedAdditionalClaims.get("asdf")); 141 } 142 143 @Test testIsComplete()144 public void testIsComplete() { 145 // Test JwtClaim is complete if audience is not set but scope is provided. 146 JwtClaims claims = 147 JwtClaims.newBuilder() 148 .setIssuer("issuer-1") 149 .setSubject("subject-1") 150 .setAdditionalClaims(Collections.singletonMap("scope", "foo")) 151 .build(); 152 assertTrue(claims.isComplete()); 153 } 154 } 155