Laravel Passport-功能测试返回未经授权的401

时间:2020-03-25 16:15:13

标签: laravel phpunit guzzle laravel-passport

我正在尝试测试登录端点,其中成功的响应将返回access_token等。

我正在使用RefreshDatabase,所以我更改了控制器上的登录方法,以通过client_secret调用来检索DB。我使用dd()进行了测试,可以确认在终端中运行的每个phpunit上的client_secret都发生了变化。凭据正确无误,API端点有效-只是在通过测试运行时无效。例如,我在mysql服务器上设置了护照表,运行Postman时可以成功登录。只有在尝试运行测试时,我才会收到401错误。

这是我的AuthTest

<?php

namespace Tests\Feature;

use Illuminate\Foundation\Testing\RefreshDatabase;
use Illuminate\Foundation\Testing\WithFaker;
use Tests\TestCase;

class AuthTest extends TestCase
{
    use RefreshDatabase;



    /**
     * @test
     */
    public function a_user_receives_an_access_token()
    {

         \Artisan::call('passport:install');

        $user = factory('App\User')->create();

        $response = $this->json('POST', '/api/login', [
            'username' => $user->email,
            'password' => 'password'
        ]);



        $response
            ->assertJson([
                'access_token' => true
            ]);


    }
}

routes / api.php

Route::post('login', 'AuthController@login');

AuthController @ login:

    public function login(Request $request) {
        $http = new \GuzzleHttp\Client;

        try {
            $response = $http->post(config('services.passport.login_endpoint'), [
                'form_params' => [
                    'grant_type' => 'password',
                    'client_id' =>  '2', //config('services.passport.client_id')
                    'client_secret' => DB::table('oauth_clients')->where('id', 2)->pluck('secret')[0], //config('services.passport.client_secret'),
                    'username' => $request->username,
                    'password' => $request->password
                ]
            ]);

            return $response->getBody();

        } catch (\GuzzleHttp\Exception\BadResponseException $e) {



            if ($e->getCode() == 400 || $e->getCode() == 401) {
                return response()
                ->json([
                    'status' => $e->getCode(),
                    'message' => 'Your email and/or password are incorrect',
                    'expanded' => $e->getMessage()
                ]);
            }

            return response()
                ->json([
                    'status' => $e->getCode(),
                    'message' => $e->getMessage()
                ]);
        }

    }

我看了看这个问题和答案:How to test authentication via API with Laravel Passport?

我无法使用以下内容

public function setUp() {
    parent::setUp();
    \Artisan::call('migrate',['-vvv' => true]);
    \Artisan::call('passport:install',['-vvv' => true]);
    \Artisan::call('db:seed',['-vvv' => true]);
}

这会导致错误:

PHP Fatal error: Declaration of Tests\Feature\AuthTest::setUp() must be compatible with Illuminate\Foundation\Testing\TestCase::setUp()

编辑:我刚刚添加

    public function setUp() :void {
        parent::setUp();
        \Artisan::call('migrate',['-vvv' => true]);
        \Artisan::call('passport:install',['-vvv' => true]);
        \Artisan::call('db:seed',['-vvv' => true]);
    }

但问题仍然存在

再次编辑:

如果我直接测试oauth路由,则它会通过

    public function testOauthLogin() {
        $oauth_client_id = 2;
        $oauth_client = OAuthClient::findOrFail($oauth_client_id);

        $user = factory('App\User')->create();

        $body = [
            'username' => $user->email,
            'password' => 'password',
            'client_id' => $oauth_client_id,
            'client_secret' => $oauth_client->secret,
            'grant_type' => 'password',
            'scope' => '*'
        ];
        $this->json('POST','/oauth/token',$body,['Accept' => 'application/json'])
            ->assertStatus(200)
            ->assertJsonStructure(['token_type','expires_in','access_token','refresh_token']);
    }

但是我使用口吃的自定义端点失败。我不知道为什么

再次编辑:

我认为问题出在Guzzle,但我不确定。我找到了我想做的另一种实现,如下:

 public function login(Request $request) {
        $request->request->add([
            'username' => $request->username,
            'password' => $request->password,
            'grant_type' => 'password',
            'client_id' => $this->client->id,
            'client_secret' => $this->client->secret,
            'scope' => '*'
        ]);

        $response = Route::dispatch(Request::create(
            'oauth/token',
            'POST'
        ));


    }

以上工作。

0 个答案:

没有答案