58 lines
2.0 KiB
JavaScript
58 lines
2.0 KiB
JavaScript
import assert from "node:assert/strict";
|
|
import { chromium } from "playwright-core";
|
|
|
|
const password = process.env.E2E_PASSWORD;
|
|
assert.ok(password, "E2E_PASSWORD must be set");
|
|
|
|
const browser = await chromium.launch({
|
|
executablePath: process.env.CHROME_BIN ?? "/usr/bin/google-chrome",
|
|
headless: true,
|
|
args: ["--no-sandbox"],
|
|
});
|
|
|
|
try {
|
|
const context = await browser.newContext();
|
|
const page = await context.newPage();
|
|
|
|
await page.goto("http://localhost:8082");
|
|
await page.locator("#login").click();
|
|
await page.waitForURL(/localhost:8080/u);
|
|
await page.locator("#username").fill(
|
|
process.env.E2E_USERNAME ?? "regular-user",
|
|
);
|
|
await page.locator("#password").fill(password);
|
|
await page.locator("#kc-login").click();
|
|
await page.waitForURL("http://localhost:8082/");
|
|
|
|
const boundaryResponsePromise = page.waitForResponse((response) =>
|
|
response.url().endsWith("/token/boundary"),
|
|
);
|
|
await page.locator("#inspect").click();
|
|
const boundaryResponse = await boundaryResponsePromise;
|
|
assert.equal(boundaryResponse.status(), 200);
|
|
const boundary = await boundaryResponse.json();
|
|
|
|
assert.equal(boundary.accessTokenStored, true);
|
|
assert.equal(boundary.refreshTokenStored, true);
|
|
assert.equal(boundary.browserReceivesRefreshToken, false);
|
|
assert.equal(JSON.stringify(boundary).includes("refresh_token"), false);
|
|
|
|
const cookies = await context.cookies("http://localhost:8082/");
|
|
const sessionCookie = cookies.find((cookie) => cookie.name === "AP2_SESSION");
|
|
assert.ok(sessionCookie);
|
|
assert.equal(sessionCookie.httpOnly, true);
|
|
assert.equal(sessionCookie.sameSite, "Lax");
|
|
|
|
const storage = await page.evaluate(() => ({
|
|
localStorage: Object.values(localStorage),
|
|
sessionStorage: Object.values(sessionStorage),
|
|
}));
|
|
assert.equal(JSON.stringify(storage).includes("refresh_token"), false);
|
|
|
|
console.log(
|
|
"pattern2 confidential client verified: server code exchange, server access/refresh custody, HttpOnly session",
|
|
);
|
|
} finally {
|
|
await browser.close();
|
|
}
|