#![cfg(feature = "testing")]
use std::collections::HashMap;
use std::sync::atomic::Ordering;
use oauth_resource_server::{OAuthValidator, testing};
#[test]
fn an_environment_proxy_never_carries_a_loopback_fetch() {
let runtime = tokio::runtime::Builder::new_current_thread()
.enable_all()
.build()
.unwrap();
let proxy = runtime.block_on(testing::spawn_http_server(
HashMap::from([
(
"http://localhost:9/jwks".to_string(),
("200 OK", testing::jwks_body()),
),
(
"http://jwks.example.test/jwks".to_string(),
("200 OK", testing::jwks_body()),
),
]),
None,
));
unsafe {
for var in [
"NO_PROXY",
"no_proxy",
"ALL_PROXY",
"all_proxy",
"HTTPS_PROXY",
"https_proxy",
"http_proxy",
"REQUEST_METHOD",
] {
std::env::remove_var(var);
}
std::env::set_var("HTTP_PROXY", &proxy.base);
}
runtime.block_on(async {
let v = OAuthValidator::new(&testing::resolved_config("http://localhost:9/jwks")).unwrap();
assert!(v.refresh_now().await.is_err());
assert_eq!(proxy.hits.load(Ordering::SeqCst), 0);
let mut cfg = testing::resolved_config("http://jwks.example.test/jwks");
cfg.allow_insecure_http = true;
let v = OAuthValidator::new(&cfg).unwrap();
assert_eq!(v.refresh_now().await.unwrap(), 1);
assert_eq!(proxy.hits.load(Ordering::SeqCst), 1);
let plain = reqwest::Client::new()
.get("http://jwks.example.test/jwks")
.send()
.await
.unwrap();
assert!(plain.status().is_success());
assert_eq!(proxy.hits.load(Ordering::SeqCst), 2);
});
}