From 604bed29306b72742688c2c8f1345ca5c26e070f Mon Sep 17 00:00:00 2001 From: Matt Jankowski Date: Tue, 27 Jan 2026 05:20:25 -0500 Subject: [PATCH] Convert `oauth/authorizations` spec controller->request (#37613) --- .../oauth/authorizations_controller_spec.rb | 76 ------------------ spec/requests/oauth/authorizations_spec.rb | 80 +++++++++++++++++++ 2 files changed, 80 insertions(+), 76 deletions(-) delete mode 100644 spec/controllers/oauth/authorizations_controller_spec.rb create mode 100644 spec/requests/oauth/authorizations_spec.rb diff --git a/spec/controllers/oauth/authorizations_controller_spec.rb b/spec/controllers/oauth/authorizations_controller_spec.rb deleted file mode 100644 index aa557b67d8..0000000000 --- a/spec/controllers/oauth/authorizations_controller_spec.rb +++ /dev/null @@ -1,76 +0,0 @@ -# frozen_string_literal: true - -require 'rails_helper' - -RSpec.describe OAuth::AuthorizationsController do - render_views - - let(:app) { Doorkeeper::Application.create!(name: 'test', redirect_uri: 'http://localhost/', scopes: 'read') } - - describe 'GET #new' do - subject do - get :new, params: { client_id: app.uid, response_type: 'code', redirect_uri: 'http://localhost/', scope: 'read' } - end - - context 'when signed in' do - let!(:user) { Fabricate(:user) } - - before do - sign_in user, scope: :user - end - - it 'returns http success and private cache control headers' do - subject - - expect(response) - .to have_http_status(200) - expect(response.headers['Cache-Control']) - .to include('private, no-store') - expect(response.parsed_body.at('body.modal-layout')) - .to be_present - expect(controller.stored_location_for(:user)) - .to eq authorize_path_for(app) - end - - context 'when app is already authorized' do - before do - Doorkeeper::AccessToken.find_or_create_for( - application: app, - resource_owner: user.id, - scopes: app.scopes, - expires_in: Doorkeeper.configuration.access_token_expires_in, - use_refresh_token: Doorkeeper.configuration.refresh_token_enabled? - ) - end - - it 'redirects to callback' do - subject - expect(response).to redirect_to(/\A#{app.redirect_uri}/) - end - - context 'with `force_login` param true' do - subject do - get :new, params: { client_id: app.uid, response_type: 'code', redirect_uri: 'http://localhost/', scope: 'read', force_login: 'true' } - end - - it { is_expected.to have_http_status(:success) } - end - end - end - - context 'when not signed in' do - it 'redirects' do - subject - - expect(response) - .to redirect_to '/auth/sign_in' - expect(controller.stored_location_for(:user)) - .to eq authorize_path_for(app) - end - end - - def authorize_path_for(app) - "/oauth/authorize?client_id=#{app.uid}&redirect_uri=http%3A%2F%2Flocalhost%2F&response_type=code&scope=read" - end - end -end diff --git a/spec/requests/oauth/authorizations_spec.rb b/spec/requests/oauth/authorizations_spec.rb new file mode 100644 index 0000000000..f17b58a002 --- /dev/null +++ b/spec/requests/oauth/authorizations_spec.rb @@ -0,0 +1,80 @@ +# frozen_string_literal: true + +require 'rails_helper' + +RSpec.describe 'OAuth Authorizations' do + let(:application) { Fabricate :application, name: 'test', redirect_uri: 'http://localhost/', scopes: 'read' } + let(:params) { { client_id: application.uid, response_type: 'code', redirect_uri: 'http://localhost/', scope: 'read' } } + + describe 'GET #new' do + subject { get oauth_authorization_path(params) } + + context 'when signed in' do + let(:user) { Fabricate(:user) } + + before { sign_in user } + + it 'returns http success and private cache control headers' do + subject + + expect(response) + .to have_http_status(:success) + expect(response.headers['Cache-Control']) + .to include('private, no-store') + expect(response.parsed_body.at('body.modal-layout')) + .to be_present + expect(controller.stored_location_for(:user)) + .to eq authorize_path_for(application) + end + + context 'when app is already authorized' do + before do + Doorkeeper::AccessToken.find_or_create_for( + application: application, + resource_owner: user.id, + scopes: application.scopes, + expires_in: Doorkeeper.configuration.access_token_expires_in, + use_refresh_token: Doorkeeper.configuration.refresh_token_enabled? + ) + end + + it 'redirects to callback' do + subject + + expect(response) + .to redirect_to(/\A#{application.redirect_uri}/) + end + + context 'with `force_login` param true' do + subject do + get oauth_authorization_path(params.merge(force_login: 'true')) + end + + it 'renders new page with success status' do + subject + + expect(response) + .to have_http_status(:success) + expect(response.parsed_body.title) + .to match(I18n.t('doorkeeper.authorizations.new.title')) + end + end + end + end + + context 'when not signed in' do + it 'redirects' do + subject + + expect(response) + .to redirect_to(new_user_session_path) + expect(controller.stored_location_for(:user)) + .to eq authorize_path_for(application) + end + end + + def authorize_path_for(application) + "/oauth/authorize?client_id=#{application.uid}&redirect_uri=http%3A%2F%2Flocalhost%2F&response_type=code&scope=read" + end + end +end