|
2 | 2 | import io
|
3 | 3 | import json
|
4 | 4 | import jwt
|
| 5 | +import time |
| 6 | +from jwt.exceptions import InvalidAudienceError, ExpiredSignatureError |
5 | 7 | from unittest.mock import patch
|
6 | 8 | from lambdas.lambda_authorizer import lambda_authorizer
|
7 | 9 | from cryptography.hazmat.primitives.asymmetric import rsa
|
@@ -53,3 +55,42 @@ def test_validate_token():
|
53 | 55 | payload = lambda_authorizer.validate_token(mock_jwt_token)
|
54 | 56 |
|
55 | 57 | assert payload == mock_payload
|
| 58 | + |
| 59 | + # Verifying for invalid audience error |
| 60 | + mock_payload = {"name": "Test name", "aud": "Random test audience"} |
| 61 | + |
| 62 | + # Encode the payload using the private key generated above while sharing the public key info as a header |
| 63 | + mock_jwt_token = jwt.encode( |
| 64 | + payload=mock_payload, |
| 65 | + algorithm="RS256", |
| 66 | + key=private_key_pem, |
| 67 | + headers={"kid": public_key_jwk["kid"]}, |
| 68 | + ) |
| 69 | + mock_keys_from_well_known_jwks = io.BytesIO(json.dumps({"keys": keys}).encode()) |
| 70 | + |
| 71 | + with patch.object( |
| 72 | + lambda_authorizer, "urlopen", return_value=mock_keys_from_well_known_jwks |
| 73 | + ): |
| 74 | + with pytest.raises(InvalidAudienceError): |
| 75 | + payload = lambda_authorizer.validate_token(mock_jwt_token) |
| 76 | + |
| 77 | + # Verifying for a payload with a expiration less than the current time |
| 78 | + mock_payload = { |
| 79 | + "name": "Test name", |
| 80 | + "aud": "Valid test audience", |
| 81 | + "exp": int(time.time()) - 1, |
| 82 | + } |
| 83 | + # Encode the payload using the private key generated above while sharing the public key info as a header |
| 84 | + mock_jwt_token = jwt.encode( |
| 85 | + payload=mock_payload, |
| 86 | + algorithm="RS256", |
| 87 | + key=private_key_pem, |
| 88 | + headers={"kid": public_key_jwk["kid"]}, |
| 89 | + ) |
| 90 | + mock_keys_from_well_known_jwks = io.BytesIO(json.dumps({"keys": keys}).encode()) |
| 91 | + |
| 92 | + with patch.object( |
| 93 | + lambda_authorizer, "urlopen", return_value=mock_keys_from_well_known_jwks |
| 94 | + ): |
| 95 | + with pytest.raises(ExpiredSignatureError): |
| 96 | + payload = lambda_authorizer.validate_token(mock_jwt_token) |
0 commit comments