Private/Runtime/Tests/Get-OpenApiAuthorization.Tests.ps1

BeforeAll {
    $env:TCS_CONFIG_ROOT = Join-Path -Path $TestDrive -ChildPath 'config'
    $env:TCS_SKIP_UPDATE_CHECK = '1'
    $env:TCS_TELEMETRY_OPTOUT = '1'
    $ModuleRoot = Split-Path -Path (Split-Path -Path (Split-Path -Path $PSScriptRoot -Parent) -Parent) -Parent
    Import-Module -Name (Join-Path -Path $ModuleRoot -ChildPath 'tcs.openapi.psd1') -Force
    # Windows PowerShell 5.1 does not load System.Net.Http by default
    Add-Type -AssemblyName 'System.Net.Http'
}

AfterAll {
    Remove-Module -Name tcs.openapi -Force -ErrorAction SilentlyContinue
}

Describe 'Get-OpenApiAuthorization' {
    BeforeAll {
        InModuleScope -ModuleName tcs.openapi {
            $script:testClient = New-Object System.Net.Http.HttpClient
        }
    }

    AfterAll {
        InModuleScope -ModuleName tcs.openapi {
            $script:testClient.Dispose()
        }
    }

    It 'returns header, query and cookie credentials for the selected schemes' {
        InModuleScope -ModuleName tcs.openapi {
            $key = (New-Object -TypeName System.Net.NetworkCredential -ArgumentList '', 'k 1').SecurePassword
            $context = New-OpenApiContext -Service 'S' -BaseUri 'https://a' -ApiKey $key
            $schemes = @{
                h = @{ Type = 'apiKey'; In = 'header'; ParameterName = 'X-Key' }
                q = @{ Type = 'apiKey'; In = 'query'; ParameterName = 'key' }
                c = @{ Type = 'apiKey'; In = 'cookie'; ParameterName = 'sid' }
            }
            $operation = @{ Security = @(@{ h = @(); q = @(); c = @() }); SecuritySchemes = $schemes }
            $auth = Get-OpenApiAuthorization -Operation $operation -Context $context -Client $script:testClient
            $auth.Header['X-Key'] | Should -Be 'k 1'
            $auth.Query | Should -Be @('key=k%201')
            $auth.Cookie | Should -Be @('sid=k%201')
            $auth.SensitiveName | Should -Contain 'X-Key'
            $auth.UsesOAuth | Should -BeFalse
        }
    }

    It 'falls back to the context bearer token or credential without security metadata' {
        InModuleScope -ModuleName tcs.openapi {
            $token = (New-Object -TypeName System.Net.NetworkCredential -ArgumentList '', 't').SecurePassword
            $auth = Get-OpenApiAuthorization -Operation @{ OperationId = 'x' } -Context (New-OpenApiContext -Service 'S' -BaseUri 'https://a' -BearerToken $token) -Client $script:testClient
            $auth.Header['Authorization'] | Should -Be 'Bearer t'
            $credential = New-Object System.Management.Automation.PSCredential -ArgumentList 'u', $token
            $auth = Get-OpenApiAuthorization -Operation @{ OperationId = 'x' } -Context (New-OpenApiContext -Service 'S' -BaseUri 'https://a' -Credential $credential) -Client $script:testClient
            $auth.Header['Authorization'] | Should -Be ('Basic ' + [Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes('u:t')))
        }
    }

    It 'fetches an OAuth2 token for an oauth2 scheme' {
        InModuleScope -ModuleName tcs.openapi {
            Mock -CommandName Get-OpenApiOAuthToken -MockWith { (New-Object -TypeName System.Net.NetworkCredential -ArgumentList '', "fetched-$Force").SecurePassword }
            $secret = (New-Object -TypeName System.Net.NetworkCredential -ArgumentList '', 's').SecurePassword
            $context = New-OpenApiContext -Service 'S' -BaseUri 'https://a' -ClientId 'id' -ClientSecret $secret -TokenUri 'https://t/token'
            $operation = @{ Security = @(@{ o = @('read') }); SecuritySchemes = @{ o = @{ Type = 'oauth2' } } }
            $auth = Get-OpenApiAuthorization -Operation $operation -Context $context -Client $script:testClient -ForceRefresh
            $auth.Header['Authorization'] | Should -Be 'Bearer fetched-True'
            $auth.UsesOAuth | Should -BeTrue
            Should -Invoke -CommandName Get-OpenApiOAuthToken -Times 1 -ParameterFilter { $TokenUri -eq 'https://t/token' -and ($Scope -join ',') -eq 'read' }
        }
    }

    It 'returns no credentials for Security = []' {
        InModuleScope -ModuleName tcs.openapi {
            $token = (New-Object -TypeName System.Net.NetworkCredential -ArgumentList '', 't').SecurePassword
            $auth = Get-OpenApiAuthorization -Operation @{ Security = @() } -Context (New-OpenApiContext -Service 'S' -BaseUri 'https://a' -BearerToken $token) -Client $script:testClient
            $auth.Header.Count | Should -Be 0
            $auth.Query.Count | Should -Be 0
        }
    }
}