Files
keycloak-pattern/e2e/pattern2.mjs
T

58 lines
2.0 KiB
JavaScript

import assert from "node:assert/strict";
import { chromium } from "playwright-core";
const password = process.env.E2E_PASSWORD;
assert.ok(password, "E2E_PASSWORD must be set");
const browser = await chromium.launch({
executablePath: process.env.CHROME_BIN ?? "/usr/bin/google-chrome",
headless: true,
args: ["--no-sandbox"],
});
try {
const context = await browser.newContext();
const page = await context.newPage();
await page.goto("http://localhost:8082");
await page.locator("#login").click();
await page.waitForURL(/localhost:8080/u);
await page.locator("#username").fill(
process.env.E2E_USERNAME ?? "regular-user",
);
await page.locator("#password").fill(password);
await page.locator("#kc-login").click();
await page.waitForURL("http://localhost:8082/");
const boundaryResponsePromise = page.waitForResponse((response) =>
response.url().endsWith("/token/boundary"),
);
await page.locator("#inspect").click();
const boundaryResponse = await boundaryResponsePromise;
assert.equal(boundaryResponse.status(), 200);
const boundary = await boundaryResponse.json();
assert.equal(boundary.accessTokenStored, true);
assert.equal(boundary.refreshTokenStored, true);
assert.equal(boundary.browserReceivesRefreshToken, false);
assert.equal(JSON.stringify(boundary).includes("refresh_token"), false);
const cookies = await context.cookies("http://localhost:8082/");
const sessionCookie = cookies.find((cookie) => cookie.name === "AP2_SESSION");
assert.ok(sessionCookie);
assert.equal(sessionCookie.httpOnly, true);
assert.equal(sessionCookie.sameSite, "Lax");
const storage = await page.evaluate(() => ({
localStorage: Object.values(localStorage),
sessionStorage: Object.values(sessionStorage),
}));
assert.equal(JSON.stringify(storage).includes("refresh_token"), false);
console.log(
"pattern2 confidential client verified: server code exchange, server access/refresh custody, HttpOnly session",
);
} finally {
await browser.close();
}