refactor: extract WebHostFixture + TestAuthPolicyProvider to shared lib
Yavsc.Blogs.Tests will need a fixture too. Lifting the cross-cutting plumbing (Kestrel + self-signed cert + address discovery + lazy init) into a new Yavsc.Tests.Shared project lets the next fixture inherit from it without copying 200+ lines of setup boilerplate, and keeps the Org.Tests fixture focused on its IdentityServer + SMTP seed. * New project src/Yavsc.Tests.Shared with WebHostFixture (abstract) and TestAuthPolicyProvider (test auth bypass via X-Test-Role). * WebServerFixture in Org.Tests now inherits from WebHostFixture; BuildApp + ConfigurePipelineAsync hold only Org-specific work. * Two shared package versions promoted to the root Directory.Packages.props. * Tests still 30/30 green.
This commit is contained in:
parent
20a6f22ec3
commit
349ddc03f5
12 changed files with 460 additions and 355 deletions
|
|
@ -1,9 +1,7 @@
|
|||
|
||||
using IdentityServer8.EntityFramework.Entities;
|
||||
using IdentityServer8.Models;
|
||||
using Microsoft.AspNetCore.Authorization;
|
||||
using Microsoft.AspNetCore.Builder;
|
||||
using Microsoft.AspNetCore.Hosting;
|
||||
using Microsoft.AspNetCore.Hosting.Server;
|
||||
using Microsoft.AspNetCore.Hosting.Server.Features;
|
||||
using Microsoft.AspNetCore.Identity;
|
||||
|
|
@ -12,372 +10,272 @@ using Microsoft.Extensions.Configuration;
|
|||
using Microsoft.Extensions.DependencyInjection;
|
||||
using Microsoft.Extensions.Logging;
|
||||
using Microsoft.Extensions.Options;
|
||||
using System.Net;
|
||||
using System.Security.Cryptography;
|
||||
using System.Security.Cryptography.X509Certificates;
|
||||
using Yavsc;
|
||||
using Yavsc.Extensions;
|
||||
using Yavsc.Interfaces;
|
||||
using Yavsc.Models;
|
||||
using Yavsc.Server.Helpers;
|
||||
using Yavsc.Tests.Shared;
|
||||
using Client = IdentityServer8.EntityFramework.Entities.Client;
|
||||
using Yavsc.Org.Tests.Fakes;
|
||||
|
||||
namespace Yavsc.Org.Tests;
|
||||
|
||||
namespace Yavsc.Org.Tests
|
||||
|
||||
/// <summary>
|
||||
/// Specialisation of <see cref="WebHostFixture"/> for the Yavsc.Org
|
||||
/// host. Adds:
|
||||
/// <list type="bullet">
|
||||
/// <item><description>In-memory configuration (<c>ConnectionStrings</c>,
|
||||
/// <c>Smtp</c>) before <c>ConfigureWebAppServices</c> runs.</description></item>
|
||||
/// <item><description>Test-only <see cref="TestAuthPolicyProvider"/>
|
||||
/// (from <c>Yavsc.Tests.Shared</c>) swapped in for
|
||||
/// <see cref="IAuthorizationPolicyProvider"/>.</description></item>
|
||||
/// <item><description>Recording <see cref="RecordingSmtpClientFactory"/>
|
||||
/// fake for <see cref="ISmtpClientFactory"/>.</description></item>
|
||||
/// <item><description>IdentityServer8 client + API scope + test user
|
||||
/// seeded into the in-memory database.</description></item>
|
||||
/// </list>
|
||||
/// All cross-cutting Kestrel / cert / address plumbing is inherited
|
||||
/// from <see cref="WebHostFixture"/>.
|
||||
/// </summary>
|
||||
[CollectionDefinition("Yavsc Server")]
|
||||
public sealed class WebServerFixture : WebHostFixture
|
||||
{
|
||||
private static IConfiguration? _sharedConfiguration;
|
||||
private static SiteSettings? _sharedSiteSettings;
|
||||
private static ILogger? _sharedLogger;
|
||||
private static string? _sharedTestClientId;
|
||||
private static string? _sharedTestClientSecret;
|
||||
private static string? _sharedTestingUserName;
|
||||
private static string? _sharedTestingUserPassword;
|
||||
private static string? _sharedTestingUserEmail;
|
||||
private static RecordingSmtpClientFactory? _sharedSmtpClientFactory;
|
||||
|
||||
[CollectionDefinition("Yavsc Server")]
|
||||
public class WebServerFixture : IDisposable
|
||||
public IConfiguration? Configuration { get; private set; }
|
||||
public string? TestClientId { get; private set; }
|
||||
public string? TestClientSecret { get; set; }
|
||||
public string? TestingUserName { get; private set; }
|
||||
public string? TestingUserPassword { get; private set; }
|
||||
public string? TestingUserEmail { get; set; }
|
||||
public string? ProtectedTestingApiKey { get; internal set; }
|
||||
public ApplicationUser? TestingUser { get; private set; }
|
||||
public bool DbCreated { get; internal set; }
|
||||
public SiteSettings? SiteSettings { get; set; }
|
||||
public RecordingSmtpClientFactory? SmtpClientFactory { get; private set; }
|
||||
public ILogger? Logger { get; internal set; }
|
||||
|
||||
protected override WebApplication BuildApp(WebApplicationBuilder builder)
|
||||
{
|
||||
private static readonly Lazy<X509Certificate2> _selfSignedCertificate = new Lazy<X509Certificate2>(CreateSelfSignedCertificate);
|
||||
private static readonly object _sync = new object();
|
||||
private static WebApplication? _app;
|
||||
private static bool _isInitialized = false;
|
||||
private static int _instanceCount = 0;
|
||||
private static readonly List<string> _sharedAddresses = new List<string>();
|
||||
private static string? _sharedTestClientId;
|
||||
private static string? _sharedTestClientSecret;
|
||||
private static string? _sharedTestingUserName;
|
||||
private static string? _sharedTestingUserPassword;
|
||||
private static string? _sharedTestingUserEmail;
|
||||
private static RecordingSmtpClientFactory? _sharedSmtpClientFactory;
|
||||
private static IServiceProvider? _sharedServices;
|
||||
private static IConfiguration? _sharedConfiguration;
|
||||
private static SiteSettings? _sharedSiteSettings;
|
||||
private static Microsoft.Extensions.Logging.ILogger? _sharedLogger;
|
||||
|
||||
public List<string> Addresses { get; private set; } = new List<string>();
|
||||
public Microsoft.Extensions.Logging.ILogger? Logger { get; internal set; }
|
||||
|
||||
private SiteSettings? siteSettings;
|
||||
|
||||
public IConfiguration? Configuration { get; private set; }
|
||||
|
||||
public string? TestClientId { get; private set; }
|
||||
|
||||
public IServiceProvider? Services { get; private set; }
|
||||
public string? TestingUserName { get; private set; }
|
||||
public string? TestingUserPassword { get; private set; }
|
||||
|
||||
public string? ProtectedTestingApiKey { get; internal set; }
|
||||
public ApplicationUser? TestingUser { get; private set; }
|
||||
public bool DbCreated { get; internal set; }
|
||||
public SiteSettings? SiteSettings { get => siteSettings; set => siteSettings = value; }
|
||||
public string? TestClientSecret { get; set; }
|
||||
public string? TestingUserEmail { get; set; }
|
||||
public RecordingSmtpClientFactory? SmtpClientFactory { get; private set; }
|
||||
public WebServerFixture()
|
||||
{
|
||||
lock (_sync)
|
||||
// WebApplication.CreateBuilder defaults WebRootPath to
|
||||
// {ContentRoot}/wwwroot. The test assembly runs from
|
||||
// src/Yavsc.Org.Tests/bin/.../, which has no wwwroot of
|
||||
// its own — so point the host at the Yavsc.Org project's
|
||||
// wwwroot so that ConfigurePipeline's static-assets middleware
|
||||
// can resolve it. The AddConfiguration extension takes care of
|
||||
// that plus the in-memory overrides below.
|
||||
builder.AddConfiguration(null).AddInMemoryCollection(new Dictionary<string, string?>
|
||||
{
|
||||
_instanceCount++;
|
||||
if (!_isInitialized)
|
||||
{
|
||||
[$"ConnectionStrings:{YavscConstants.YavscConnectionStringName}"] = "InMemory",
|
||||
// SMTP test config: UserName non-null so MailSender
|
||||
// exercises the Authenticate branch — the
|
||||
// RecordingSmtpClient captures it.
|
||||
["Smtp:Host"] = "smtp.test.local",
|
||||
["Smtp:Port"] = "465",
|
||||
["Smtp:UserName"] = "test-user",
|
||||
["Smtp:Password"] = "test-pass",
|
||||
});
|
||||
|
||||
SetupHost().Wait();
|
||||
_isInitialized = true;
|
||||
}
|
||||
Configuration = builder.Configuration;
|
||||
|
||||
CopySharedState();
|
||||
}
|
||||
}
|
||||
// Swap the production authorization policy provider for
|
||||
// TestAuthPolicyProvider BEFORE ConfigureWebAppServices
|
||||
// runs. ConfigureWebAppServices calls builder.Build() at
|
||||
// the end, which freezes the service collection. Tests
|
||||
// can satisfy [Authorize("AdministratorOnly")] (and any
|
||||
// other policy that requires a role) by sending an
|
||||
// X-Test-Role header; the production policy is replaced
|
||||
// by the test one via the last-write-wins semantics of
|
||||
// IServiceCollection.AddSingleton.
|
||||
builder.Services.AddSingleton<IAuthorizationPolicyProvider, TestAuthPolicyProvider>();
|
||||
|
||||
public void Dispose()
|
||||
// Replace the production ISmtpClientFactory (added later
|
||||
// by ConfigureWebAppServices via TryAddSingleton) with a
|
||||
// recording fake. By pre-registering here, the prod
|
||||
// TryAdd becomes a no-op and tests get a single shared
|
||||
// fake they can assert against.
|
||||
var smtpFactory = new RecordingSmtpClientFactory();
|
||||
builder.Services.AddSingleton<ISmtpClientFactory>(smtpFactory);
|
||||
_sharedSmtpClientFactory = smtpFactory;
|
||||
|
||||
var app = builder.ConfigureWebAppServices();
|
||||
SiteSettings = app.Services.GetRequiredService<IOptions<SiteSettings>>().Value;
|
||||
|
||||
using (var migrationScope = app.Services.CreateScope())
|
||||
{
|
||||
lock (_sync)
|
||||
var db = migrationScope.ServiceProvider.GetRequiredService<ApplicationDbContext>();
|
||||
db.Database.EnsureDeleted();
|
||||
db.Database.EnsureCreated();
|
||||
TestingUserName = "Tester";
|
||||
TestingUserPassword = "Test123!";
|
||||
TestClientId = "testClientId";
|
||||
TestingUserEmail = "test@no-reply.com";
|
||||
TestingUser = null;
|
||||
TestClientSecret = Guid.CreateVersion7().ToString();
|
||||
EnsureUser(TestingUserName, TestingUserPassword, TestingUserEmail, migrationScope);
|
||||
AddAuthorizedClient(migrationScope, TestClientId, TestClientSecret);
|
||||
TestingUser = db.Users.FirstOrDefaultAsync(u => u.UserName == TestingUserName).Result;
|
||||
|
||||
// Add test API scope if it doesn't exist
|
||||
var testScope = db.ApiScopes.FirstOrDefault(s => s.Name == "test");
|
||||
if (testScope == null)
|
||||
{
|
||||
_instanceCount--;
|
||||
if (_instanceCount == 0 && _app != null)
|
||||
db.ApiScopes.Add(new IdentityServer8.EntityFramework.Entities.ApiScope
|
||||
{
|
||||
_app.StopAsync().Wait();
|
||||
_app = null;
|
||||
_isInitialized = false;
|
||||
_sharedAddresses.Clear();
|
||||
_sharedServices = null;
|
||||
_sharedConfiguration = null;
|
||||
_sharedSiteSettings = null;
|
||||
_sharedLogger = null;
|
||||
_sharedTestClientId = null;
|
||||
_sharedTestClientSecret = null;
|
||||
_sharedTestingUserName = null;
|
||||
_sharedTestingUserPassword = null;
|
||||
_sharedTestingUserEmail = null;
|
||||
_sharedSmtpClientFactory = null;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private void CopySharedState()
|
||||
{
|
||||
Addresses = new List<string>(_sharedAddresses);
|
||||
Logger = _sharedLogger;
|
||||
Configuration = _sharedConfiguration;
|
||||
Services = _sharedServices;
|
||||
SiteSettings = _sharedSiteSettings;
|
||||
TestClientId = _sharedTestClientId;
|
||||
TestClientSecret = _sharedTestClientSecret;
|
||||
TestingUserName = _sharedTestingUserName;
|
||||
TestingUserPassword = _sharedTestingUserPassword;
|
||||
TestingUserEmail = _sharedTestingUserEmail;
|
||||
SmtpClientFactory = _sharedSmtpClientFactory;
|
||||
}
|
||||
|
||||
public async Task SetupHost()
|
||||
{
|
||||
var builder = WebApplication.CreateBuilder();
|
||||
|
||||
// WebApplication.CreateBuilder defaults WebRootPath to
|
||||
// {ContentRoot}/wwwroot. The test assembly runs from
|
||||
// src/Yavsc.Org.Tests/bin/.../, which has no wwwroot of
|
||||
// its own — so point the host at the Yavsc.Org project's
|
||||
// wwwroot so that ConfigurePipeline's
|
||||
|
||||
|
||||
builder.AddConfiguration(null).AddInMemoryCollection(new Dictionary<string, string?>
|
||||
{
|
||||
[$"ConnectionStrings:{YavscConstants.YavscConnectionStringName}"] = "InMemory",
|
||||
// SMTP test config: UserName non-null so MailSender
|
||||
// exercises the Authenticate branch — the
|
||||
// RecordingSmtpClient captures it.
|
||||
["Smtp:Host"] = "smtp.test.local",
|
||||
["Smtp:Port"] = "465",
|
||||
["Smtp:UserName"] = "test-user",
|
||||
["Smtp:Password"] = "test-pass",
|
||||
Name = "test",
|
||||
Enabled = true,
|
||||
DisplayName = "Test API Scope",
|
||||
Description = "Scope for testing purposes",
|
||||
UserClaims = new List<IdentityServer8.EntityFramework.Entities.ApiScopeClaim>
|
||||
{
|
||||
new IdentityServer8.EntityFramework.Entities.ApiScopeClaim { Type = "role" },
|
||||
new IdentityServer8.EntityFramework.Entities.ApiScopeClaim { Type = "email" }
|
||||
}
|
||||
});
|
||||
|
||||
// Configure Kestrel for HTTPS with self-signed certificate on a dynamic port
|
||||
builder.WebHost.ConfigureKestrel(options =>
|
||||
{
|
||||
options.Listen(IPAddress.Loopback, 0, listenOptions =>
|
||||
// Add a basic API resource for the test scope
|
||||
var apiResource = new IdentityServer8.EntityFramework.Entities.ApiResource
|
||||
{
|
||||
listenOptions.UseHttps(_selfSignedCertificate.Value);
|
||||
});
|
||||
});
|
||||
|
||||
Configuration = builder.Configuration;
|
||||
|
||||
// Swap the production authorization policy provider for
|
||||
// TestAuthPolicyProvider BEFORE ConfigureWebAppServices
|
||||
// runs. ConfigureWebAppServices calls builder.Build() at
|
||||
// the end, which freezes the service collection. Tests
|
||||
// can satisfy [Authorize("AdministratorOnly")] (and any
|
||||
// other policy that requires a role) by sending an
|
||||
// X-Test-Role header; the production policy is replaced
|
||||
// by the test one via the last-write-wins semantics of
|
||||
// IServiceCollection.AddSingleton.
|
||||
builder.Services.AddSingleton<IAuthorizationPolicyProvider, TestAuthPolicyProvider>();
|
||||
|
||||
// Replace the production ISmtpClientFactory (added later
|
||||
// by ConfigureWebAppServices via TryAddSingleton) with a
|
||||
// recording fake. By pre-registering here, the prod
|
||||
// TryAdd becomes a no-op and tests get a single shared
|
||||
// fake they can assert against.
|
||||
var smtpFactory = new RecordingSmtpClientFactory();
|
||||
builder.Services.AddSingleton<ISmtpClientFactory>(smtpFactory);
|
||||
_sharedSmtpClientFactory = smtpFactory;
|
||||
|
||||
_app = builder.ConfigureWebAppServices();
|
||||
|
||||
// Note: a recording ISmtpClientFactory is registered
|
||||
// BEFORE ConfigureWebAppServices() above (further up in
|
||||
// this method) so the production TryAddSingleton inside
|
||||
// ConfigureWebAppServices becomes a no-op.
|
||||
// _sharedSmtpClientFactory is captured there.
|
||||
|
||||
// The MSBuild target CopyYavscOrgStaticAssets in
|
||||
// Yavsc.Org.Tests.csproj mirrors the Yavsc.Org static
|
||||
// assets manifest into the test bin directory. Call
|
||||
// MapStaticAssets() with the explicit path so the test
|
||||
// host resolves the manifest by file location rather
|
||||
// than by {AssemblyName}.staticwebassets.* convention
|
||||
// (which would look for Yavsc.Org.Tests.staticwebassets.*,
|
||||
// a file we don't produce).
|
||||
var testRuntimeManifest = Path.Combine(AppContext.BaseDirectory,
|
||||
"Yavsc.Org.staticwebassets.runtime.json");
|
||||
|
||||
Services = _app.Services;
|
||||
SiteSettings = _app.Services.GetRequiredService<IOptions<SiteSettings>>().Value;
|
||||
|
||||
using (var migrationScope = _app.Services.CreateScope())
|
||||
{
|
||||
var db = migrationScope.ServiceProvider.GetRequiredService<ApplicationDbContext>();
|
||||
db.Database.EnsureDeleted();
|
||||
db.Database.EnsureCreated();
|
||||
TestingUserName = "Tester";
|
||||
TestingUserPassword = "Test123!";
|
||||
TestClientId = "testClientId";
|
||||
TestingUserEmail = "test@no-reply.com";
|
||||
TestingUser = null;
|
||||
TestClientSecret = Guid.CreateVersion7().ToString();
|
||||
EnsureUser(TestingUserName, TestingUserPassword, TestingUserEmail, migrationScope);
|
||||
AddAuthorizedClient(migrationScope, TestClientId, TestClientSecret);
|
||||
TestingUser = await db.Users.FirstOrDefaultAsync(u => u.UserName == TestingUserName);
|
||||
|
||||
// Add test API scope if it doesn't exist
|
||||
var testScope = db.ApiScopes.FirstOrDefault(s => s.Name == "test");
|
||||
if (testScope == null)
|
||||
{
|
||||
db.ApiScopes.Add(new IdentityServer8.EntityFramework.Entities.ApiScope
|
||||
{
|
||||
Name = "test",
|
||||
Enabled = true,
|
||||
DisplayName = "Test API Scope",
|
||||
Description = "Scope for testing purposes",
|
||||
UserClaims = new List<IdentityServer8.EntityFramework.Entities.ApiScopeClaim>
|
||||
{
|
||||
new IdentityServer8.EntityFramework.Entities.ApiScopeClaim { Type = "role" },
|
||||
new IdentityServer8.EntityFramework.Entities.ApiScopeClaim { Type = "email" }
|
||||
}
|
||||
});
|
||||
|
||||
// Add a basic API resource for the test scope
|
||||
var apiResource = new IdentityServer8.EntityFramework.Entities.ApiResource
|
||||
{
|
||||
Name = "testapi",
|
||||
DisplayName = "Test API",
|
||||
Enabled = true,
|
||||
Scopes = new List<IdentityServer8.EntityFramework.Entities.ApiResourceScope>
|
||||
{
|
||||
new IdentityServer8.EntityFramework.Entities.ApiResourceScope
|
||||
{
|
||||
Scope = "test"
|
||||
}
|
||||
}
|
||||
};
|
||||
db.ApiResources.Add(apiResource);
|
||||
db.SaveChanges();
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
|
||||
_app = await _app.ConfigurePipeline(testRuntimeManifest);
|
||||
|
||||
await _app.StartAsync();
|
||||
|
||||
_sharedServices = _app.Services;
|
||||
_sharedConfiguration = Configuration;
|
||||
_sharedSiteSettings = SiteSettings;
|
||||
_sharedTestClientId = TestClientId;
|
||||
_sharedTestClientSecret = TestClientSecret;
|
||||
_sharedTestingUserName = TestingUserName;
|
||||
_sharedTestingUserPassword = TestingUserPassword;
|
||||
_sharedTestingUserEmail = TestingUserEmail;
|
||||
_sharedLogger = _app.Services.GetRequiredService<ILoggerFactory>().CreateLogger<WebServerFixture>();
|
||||
Logger = _sharedLogger;
|
||||
|
||||
var server = _app.Services.GetRequiredService<IServer>();
|
||||
var addressFeatures = server.Features.Get<IServerAddressesFeature>();
|
||||
|
||||
if (addressFeatures?.Addresses != null)
|
||||
{
|
||||
_sharedAddresses.Clear();
|
||||
foreach (var address in addressFeatures.Addresses)
|
||||
{
|
||||
_sharedAddresses.Add(address);
|
||||
Addresses.Add(address);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private void AddAuthorizedClient(IServiceScope scope, string testClientId, string testClientSecret)
|
||||
{
|
||||
var configDb = scope.ServiceProvider.GetRequiredService<IdentityServer8.EntityFramework.DbContexts.ConfigurationDbContext>();
|
||||
if (configDb == null)
|
||||
throw new InvalidOperationException("ConfigurationDbContext is not available for IdentityServer client seeding.");
|
||||
|
||||
Client testingClient = new Client
|
||||
{
|
||||
ClientId = testClientId,
|
||||
AccessTokenLifetime = 3600000,
|
||||
AccessTokenType = 1,
|
||||
ClientName = "Testing client",
|
||||
Enabled = true,
|
||||
RequireClientSecret = true
|
||||
};
|
||||
configDb.Set<Client>().Add(testingClient);
|
||||
configDb.SaveChanges();
|
||||
|
||||
var apiScope = new IdentityServer8.EntityFramework.Entities.ApiScope
|
||||
{
|
||||
Name = "test",
|
||||
DisplayName = "Test Scope",
|
||||
Description = "Scope for testing",
|
||||
Enabled = true,
|
||||
Required = false,
|
||||
ShowInDiscoveryDocument = true,
|
||||
Emphasize = false
|
||||
};
|
||||
configDb.Set<IdentityServer8.EntityFramework.Entities.ApiScope>().Add(apiScope);
|
||||
|
||||
ClientSecret secret = new ClientSecret
|
||||
{
|
||||
Value = testClientSecret.Sha256(),
|
||||
Type = IdentityServer8.IdentityServerConstants.SecretTypes.SharedSecret,
|
||||
ClientId = testingClient.Id
|
||||
};
|
||||
configDb.Set<ClientSecret>().Add(secret);
|
||||
|
||||
configDb.Set<ClientGrantType>().Add(new ClientGrantType
|
||||
{
|
||||
ClientId = testingClient.Id,
|
||||
GrantType = "client_credentials"
|
||||
});
|
||||
configDb.Set<ClientGrantType>().Add(new ClientGrantType
|
||||
{
|
||||
ClientId = testingClient.Id,
|
||||
GrantType = "password"
|
||||
});
|
||||
configDb.Set<ClientScope>().Add(new ClientScope
|
||||
{
|
||||
ClientId = testingClient.Id,
|
||||
Scope = "test"
|
||||
});
|
||||
|
||||
configDb.SaveChanges();
|
||||
}
|
||||
|
||||
public void EnsureUser(string testingUserName, string password, string email, IServiceScope scope)
|
||||
{
|
||||
if (TestingUser == null)
|
||||
{
|
||||
|
||||
var userManager =
|
||||
scope.ServiceProvider.GetRequiredService<UserManager<ApplicationUser>>();
|
||||
|
||||
TestingUser = new ApplicationUser
|
||||
{
|
||||
UserName = testingUserName,
|
||||
Email = testingUserName + "@example.com",
|
||||
EmailConfirmed = true
|
||||
Name = "testapi",
|
||||
DisplayName = "Test API",
|
||||
Enabled = true,
|
||||
Scopes = new List<IdentityServer8.EntityFramework.Entities.ApiResourceScope>
|
||||
{
|
||||
new IdentityServer8.EntityFramework.Entities.ApiResourceScope { Scope = "test" }
|
||||
}
|
||||
};
|
||||
|
||||
var result = userManager.CreateAsync(TestingUser, password).Result;
|
||||
|
||||
Assert.True(result.Succeeded);
|
||||
|
||||
ApplicationDbContext dbContext =
|
||||
scope.ServiceProvider.GetRequiredService<ApplicationDbContext>();
|
||||
TestingUser = dbContext.Users.FirstOrDefault(u => u.UserName == testingUserName);
|
||||
db.ApiResources.Add(apiResource);
|
||||
db.SaveChanges();
|
||||
}
|
||||
}
|
||||
|
||||
private static X509Certificate2 CreateSelfSignedCertificate()
|
||||
_sharedConfiguration = Configuration;
|
||||
_sharedSiteSettings = SiteSettings;
|
||||
_sharedTestClientId = TestClientId;
|
||||
_sharedTestClientSecret = TestClientSecret;
|
||||
_sharedTestingUserName = TestingUserName;
|
||||
_sharedTestingUserPassword = TestingUserPassword;
|
||||
_sharedTestingUserEmail = TestingUserEmail;
|
||||
_sharedLogger = app.Services.GetRequiredService<ILoggerFactory>().CreateLogger<WebServerFixture>();
|
||||
Logger = _sharedLogger;
|
||||
SmtpClientFactory = smtpFactory;
|
||||
|
||||
return app;
|
||||
}
|
||||
|
||||
protected override async Task<WebApplication> ConfigurePipelineAsync(WebApplication app)
|
||||
{
|
||||
// The MSBuild target CopyYavscOrgStaticAssets in
|
||||
// Yavsc.Org.Tests.csproj mirrors the Yavsc.Org static
|
||||
// assets manifest into the test bin directory. Call
|
||||
// MapStaticAssets() with the explicit path so the test
|
||||
// host resolves the manifest by file location rather
|
||||
// than by {AssemblyName}.staticwebassets.* convention
|
||||
// (which would look for Yavsc.Org.Tests.staticwebassets.*,
|
||||
// a file we don't produce).
|
||||
var testRuntimeManifest = Path.Combine(AppContext.BaseDirectory,
|
||||
"Yavsc.Org.staticwebassets.runtime.json");
|
||||
return await app.ConfigurePipeline(testRuntimeManifest);
|
||||
}
|
||||
|
||||
protected override void CopySpecialisedSharedState()
|
||||
{
|
||||
TestClientId = _sharedTestClientId;
|
||||
TestClientSecret = _sharedTestClientSecret;
|
||||
TestingUserName = _sharedTestingUserName;
|
||||
TestingUserPassword = _sharedTestingUserPassword;
|
||||
TestingUserEmail = _sharedTestingUserEmail;
|
||||
SmtpClientFactory = _sharedSmtpClientFactory;
|
||||
Configuration = _sharedConfiguration;
|
||||
SiteSettings = _sharedSiteSettings;
|
||||
Logger = _sharedLogger;
|
||||
}
|
||||
|
||||
private void AddAuthorizedClient(IServiceScope scope, string testClientId, string testClientSecret)
|
||||
{
|
||||
var configDb = scope.ServiceProvider.GetRequiredService<IdentityServer8.EntityFramework.DbContexts.ConfigurationDbContext>();
|
||||
if (configDb == null)
|
||||
throw new InvalidOperationException("ConfigurationDbContext is not available for IdentityServer client seeding.");
|
||||
|
||||
Client testingClient = new Client
|
||||
{
|
||||
var rsa = RSA.Create(2048);
|
||||
var certRequest = new CertificateRequest("CN=localhost", rsa, HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1);
|
||||
ClientId = testClientId,
|
||||
AccessTokenLifetime = 3600000,
|
||||
AccessTokenType = 1,
|
||||
ClientName = "Testing client",
|
||||
Enabled = true,
|
||||
RequireClientSecret = true
|
||||
};
|
||||
configDb.Set<Client>().Add(testingClient);
|
||||
configDb.SaveChanges();
|
||||
|
||||
certRequest.CertificateExtensions.Add(
|
||||
new X509KeyUsageExtension(X509KeyUsageFlags.DataEncipherment | X509KeyUsageFlags.KeyEncipherment | X509KeyUsageFlags.DigitalSignature, false));
|
||||
var apiScope = new IdentityServer8.EntityFramework.Entities.ApiScope
|
||||
{
|
||||
Name = "test",
|
||||
DisplayName = "Test Scope",
|
||||
Description = "Scope for testing",
|
||||
Enabled = true,
|
||||
Required = false,
|
||||
ShowInDiscoveryDocument = true,
|
||||
Emphasize = false
|
||||
};
|
||||
configDb.Set<IdentityServer8.EntityFramework.Entities.ApiScope>().Add(apiScope);
|
||||
|
||||
certRequest.CertificateExtensions.Add(
|
||||
new X509EnhancedKeyUsageExtension(
|
||||
new OidCollection { new Oid("1.3.6.1.5.5.7.3.1") }, false));
|
||||
ClientSecret secret = new ClientSecret
|
||||
{
|
||||
Value = testClientSecret.Sha256(),
|
||||
Type = IdentityServer8.IdentityServerConstants.SecretTypes.SharedSecret,
|
||||
ClientId = testingClient.Id
|
||||
};
|
||||
configDb.Set<ClientSecret>().Add(secret);
|
||||
|
||||
var certificate = certRequest.CreateSelfSigned(new DateTimeOffset(DateTime.UtcNow.AddDays(-1)), new DateTimeOffset(DateTime.UtcNow.AddDays(3650)));
|
||||
return certificate;
|
||||
configDb.Set<ClientGrantType>().Add(new ClientGrantType
|
||||
{
|
||||
ClientId = testingClient.Id,
|
||||
GrantType = "client_credentials"
|
||||
});
|
||||
configDb.Set<ClientGrantType>().Add(new ClientGrantType
|
||||
{
|
||||
ClientId = testingClient.Id,
|
||||
GrantType = "password"
|
||||
});
|
||||
configDb.Set<ClientScope>().Add(new ClientScope
|
||||
{
|
||||
ClientId = testingClient.Id,
|
||||
Scope = "test"
|
||||
});
|
||||
|
||||
configDb.SaveChanges();
|
||||
}
|
||||
|
||||
public void EnsureUser(string testingUserName, string password, string email, IServiceScope scope)
|
||||
{
|
||||
if (TestingUser == null)
|
||||
{
|
||||
var userManager = scope.ServiceProvider.GetRequiredService<UserManager<ApplicationUser>>();
|
||||
|
||||
TestingUser = new ApplicationUser
|
||||
{
|
||||
UserName = testingUserName,
|
||||
Email = testingUserName + "@example.com",
|
||||
EmailConfirmed = true
|
||||
};
|
||||
|
||||
var result = userManager.CreateAsync(TestingUser, password).Result;
|
||||
|
||||
Assert.True(result.Succeeded);
|
||||
|
||||
ApplicationDbContext dbContext = scope.ServiceProvider.GetRequiredService<ApplicationDbContext>();
|
||||
TestingUser = dbContext.Users.FirstOrDefault(u => u.UserName == testingUserName);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue