summaryrefslogtreecommitdiff
path: root/lib/facebook-graph-sdk/tests/Helpers/FacebookSignedRequestFromInputHelperTest.php
diff options
context:
space:
mode:
Diffstat (limited to 'lib/facebook-graph-sdk/tests/Helpers/FacebookSignedRequestFromInputHelperTest.php')
-rw-r--r--lib/facebook-graph-sdk/tests/Helpers/FacebookSignedRequestFromInputHelperTest.php113
1 files changed, 113 insertions, 0 deletions
diff --git a/lib/facebook-graph-sdk/tests/Helpers/FacebookSignedRequestFromInputHelperTest.php b/lib/facebook-graph-sdk/tests/Helpers/FacebookSignedRequestFromInputHelperTest.php
new file mode 100644
index 0000000..d9bd803
--- /dev/null
+++ b/lib/facebook-graph-sdk/tests/Helpers/FacebookSignedRequestFromInputHelperTest.php
@@ -0,0 +1,113 @@
+<?php
+/**
+ * Copyright 2014 Facebook, Inc.
+ *
+ * You are hereby granted a non-exclusive, worldwide, royalty-free license to
+ * use, copy, modify, and distribute this software in source code or binary
+ * form for use in connection with the web services and APIs provided by
+ * Facebook.
+ *
+ * As with any software that integrates with the Facebook platform, your use
+ * of this software is subject to the Facebook Developer Principles and
+ * Policies [http://developers.facebook.com/policy/]. This copyright notice
+ * shall be included in all copies or substantial portions of the software.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+ * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+ * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
+ * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+ * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
+ * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
+ * DEALINGS IN THE SOFTWARE.
+ *
+ */
+namespace Facebook\Tests\Helpers;
+
+use Facebook\FacebookApp;
+use Facebook\FacebookClient;
+use Facebook\FacebookRequest;
+use Facebook\FacebookResponse;
+use Facebook\Helpers\FacebookSignedRequestFromInputHelper;
+
+class FooSignedRequestHelper extends FacebookSignedRequestFromInputHelper
+{
+ public function getRawSignedRequest()
+ {
+ return null;
+ }
+}
+
+class FooSignedRequestHelperFacebookClient extends FacebookClient
+{
+ public function sendRequest(FacebookRequest $request)
+ {
+ $params = $request->getParams();
+ $rawResponse = json_encode([
+ 'access_token' => 'foo_access_token_from:' . $params['code'],
+ ]);
+
+ return new FacebookResponse($request, $rawResponse, 200);
+ }
+}
+
+class FacebookSignedRequestFromInputHelperTest extends \PHPUnit_Framework_TestCase
+{
+ /**
+ * @var FooSignedRequestHelper
+ */
+ protected $helper;
+
+ public $rawSignedRequestAuthorizedWithAccessToken = 'vdZXlVEQ5NTRRTFvJ7Jeo_kP4SKnBDvbNP0fEYKS0Sg=.eyJvYXV0aF90b2tlbiI6ImZvb190b2tlbiIsImFsZ29yaXRobSI6IkhNQUMtU0hBMjU2IiwiaXNzdWVkX2F0IjoxNDAyNTUxMDMxLCJ1c2VyX2lkIjoiMTIzIn0=';
+ public $rawSignedRequestAuthorizedWithCode = 'oBtmZlsFguNQvGRETDYQQu1-PhwcArgbBBEK4urbpRA=.eyJjb2RlIjoiZm9vX2NvZGUiLCJhbGdvcml0aG0iOiJITUFDLVNIQTI1NiIsImlzc3VlZF9hdCI6MTQwNjMxMDc1MiwidXNlcl9pZCI6IjEyMyJ9';
+ public $rawSignedRequestUnauthorized = 'KPlyhz-whtYAhHWr15N5TkbS_avz-2rUJFpFkfXKC88=.eyJhbGdvcml0aG0iOiJITUFDLVNIQTI1NiIsImlzc3VlZF9hdCI6MTQwMjU1MTA4Nn0=';
+
+ public function setUp()
+ {
+ $app = new FacebookApp('123', 'foo_app_secret');
+ $this->helper = new FooSignedRequestHelper($app, new FooSignedRequestHelperFacebookClient());
+ }
+
+ public function testSignedRequestDataCanBeRetrievedFromPostData()
+ {
+ $_POST['signed_request'] = 'foo_signed_request';
+
+ $rawSignedRequest = $this->helper->getRawSignedRequestFromPost();
+
+ $this->assertEquals('foo_signed_request', $rawSignedRequest);
+ }
+
+ public function testSignedRequestDataCanBeRetrievedFromCookieData()
+ {
+ $_COOKIE['fbsr_123'] = 'foo_signed_request';
+
+ $rawSignedRequest = $this->helper->getRawSignedRequestFromCookie();
+
+ $this->assertEquals('foo_signed_request', $rawSignedRequest);
+ }
+
+ public function testAccessTokenWillBeNullWhenAUserHasNotYetAuthorizedTheApp()
+ {
+ $this->helper->instantiateSignedRequest($this->rawSignedRequestUnauthorized);
+ $accessToken = $this->helper->getAccessToken();
+
+ $this->assertNull($accessToken);
+ }
+
+ public function testAnAccessTokenCanBeInstantiatedWhenRedirectReturnsAnAccessToken()
+ {
+ $this->helper->instantiateSignedRequest($this->rawSignedRequestAuthorizedWithAccessToken);
+ $accessToken = $this->helper->getAccessToken();
+
+ $this->assertInstanceOf('Facebook\Authentication\AccessToken', $accessToken);
+ $this->assertEquals('foo_token', $accessToken->getValue());
+ }
+
+ public function testAnAccessTokenCanBeInstantiatedWhenRedirectReturnsACode()
+ {
+ $this->helper->instantiateSignedRequest($this->rawSignedRequestAuthorizedWithCode);
+ $accessToken = $this->helper->getAccessToken();
+
+ $this->assertInstanceOf('Facebook\Authentication\AccessToken', $accessToken);
+ $this->assertEquals('foo_access_token_from:foo_code', $accessToken->getValue());
+ }
+}