mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-07 05:46:27 +00:00
feat(security): full OAuth 2.1 / OpenID Connect server and OIDC relying-party client
Authorization server: consent and scopes, OIDC (nonce, auth_time, acr, sid, at_hash, signed userinfo, RP-initiated and back-channel logout), managed refresh tokens with rotation and reuse detection, RFC 9068 JWT access tokens, DPoP, PAR, device grant, token exchange, private_key_jwt, RFC 7591/7592 registration, RFC 9207 iss, signing keyring with rotation. State is DB-backed through a new lookup.OAuthGrantStore (procedure and direct backends, four dialect DDLs, conformance cases). Client side: WithOIDC discovery, PKCE, nonce, id_token validation, OAuth2LogoutURL. PeekRefresh now returns already rotated tokens so RotateRefresh can detect reuse. Docs: OAUTH2_SERVER.md, oauth2_full_example.go, breaking_changes.md step 8.
This commit is contained in:
@@ -154,3 +154,27 @@ func TestConformanceMSSQLContainer(t *testing.T) {
|
||||
}
|
||||
runOnServer(t, "sqlserver", dsn("cf_direct"), "mssql", lookup.Config{}, true)
|
||||
}
|
||||
|
||||
// TestContainerLifecycle checks the start/stop plumbing the container tests rely on: the
|
||||
// container comes up and accepts connections, and after stop it is gone (it runs with --rm).
|
||||
func TestContainerLifecycle(t *testing.T) {
|
||||
rt := containerRuntime(t)
|
||||
port := startContainer(t, rt, "docker.io/library/postgres:16-alpine", "5432", map[string]string{"POSTGRES_PASSWORD": containerPassword})
|
||||
waitReady(t, "pgx", fmt.Sprintf("postgres://postgres:%s@127.0.0.1:%s/postgres?sslmode=disable", containerPassword, port), 90*time.Second)
|
||||
|
||||
listed := func() string {
|
||||
return run(t, 30*time.Second, rt, "ps", "-q", "--filter", "ancestor=docker.io/library/postgres:16-alpine")
|
||||
}
|
||||
id := listed()
|
||||
if id == "" {
|
||||
t.Fatal("container is not running after start")
|
||||
}
|
||||
run(t, time.Minute, rt, "stop", "-t", "2", id)
|
||||
deadline := time.Now().Add(30 * time.Second)
|
||||
for listed() != "" {
|
||||
if time.Now().After(deadline) {
|
||||
t.Fatal("container still present after stop")
|
||||
}
|
||||
time.Sleep(500 * time.Millisecond)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user