mirror of
https://github.com/BookStackApp/BookStack.git
synced 2025-04-10 17:01:42 +08:00
OIDC: Added extra userinfo content-type normalisation and test
During review of #5337
This commit is contained in:
parent
17f7afe12d
commit
bc1f1d92e5
@ -11,7 +11,9 @@ class OidcUserinfoResponse implements ProvidesClaims
|
|||||||
|
|
||||||
public function __construct(ResponseInterface $response, string $issuer, array $keys)
|
public function __construct(ResponseInterface $response, string $issuer, array $keys)
|
||||||
{
|
{
|
||||||
$contentType = explode(';', $response->getHeader('Content-Type')[0], 2)[0];
|
$contentTypeHeaderValue = $response->getHeader('Content-Type')[0] ?? '';
|
||||||
|
$contentType = strtolower(trim(explode(';', $contentTypeHeaderValue, 2)[0]));
|
||||||
|
|
||||||
if ($contentType === 'application/json') {
|
if ($contentType === 'application/json') {
|
||||||
$this->claims = json_decode($response->getBody()->getContents(), true);
|
$this->claims = json_decode($response->getBody()->getContents(), true);
|
||||||
}
|
}
|
||||||
|
@ -787,6 +787,20 @@ class OidcTest extends TestCase
|
|||||||
$this->assertTrue($user->hasRole($roleA->id));
|
$this->assertTrue($user->hasRole($roleA->id));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function test_userinfo_endpoint_response_with_complex_json_content_type_handled()
|
||||||
|
{
|
||||||
|
$userinfoResponseData = [
|
||||||
|
'sub' => OidcJwtHelper::defaultPayload()['sub'],
|
||||||
|
'name' => 'Barry',
|
||||||
|
];
|
||||||
|
$userinfoResponse = new Response(200, ['Content-Type' => 'Application/Json ; charset=utf-8'], json_encode($userinfoResponseData));
|
||||||
|
$resp = $this->runLogin(['name' => null], [$userinfoResponse]);
|
||||||
|
$resp->assertRedirect('/');
|
||||||
|
|
||||||
|
$user = User::where('email', OidcJwtHelper::defaultPayload()['email'])->first();
|
||||||
|
$this->assertEquals('Barry', $user->name);
|
||||||
|
}
|
||||||
|
|
||||||
public function test_userinfo_endpoint_jwks_response_handled()
|
public function test_userinfo_endpoint_jwks_response_handled()
|
||||||
{
|
{
|
||||||
$userinfoResponseData = OidcJwtHelper::idToken(['name' => 'Barry Jwks']);
|
$userinfoResponseData = OidcJwtHelper::idToken(['name' => 'Barry Jwks']);
|
||||||
|
Loading…
x
Reference in New Issue
Block a user