ServerBagTest.php 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180
  1. <?php
  2. /*
  3. * This file is part of the Symfony package.
  4. *
  5. * (c) Fabien Potencier <fabien@symfony.com>
  6. *
  7. * For the full copyright and license information, please view the LICENSE
  8. * file that was distributed with this source code.
  9. */
  10. namespace Symfony\Component\HttpFoundation\Tests;
  11. use PHPUnit\Framework\TestCase;
  12. use Symfony\Component\HttpFoundation\ServerBag;
  13. /**
  14. * ServerBagTest.
  15. *
  16. * @author Bulat Shakirzyanov <mallluhuct@gmail.com>
  17. */
  18. class ServerBagTest extends TestCase
  19. {
  20. public function testShouldExtractHeadersFromServerArray()
  21. {
  22. $server = [
  23. 'SOME_SERVER_VARIABLE' => 'value',
  24. 'SOME_SERVER_VARIABLE2' => 'value',
  25. 'ROOT' => 'value',
  26. 'HTTP_CONTENT_TYPE' => 'text/html',
  27. 'HTTP_CONTENT_LENGTH' => '0',
  28. 'HTTP_ETAG' => 'asdf',
  29. 'PHP_AUTH_USER' => 'foo',
  30. 'PHP_AUTH_PW' => 'bar',
  31. ];
  32. $bag = new ServerBag($server);
  33. $this->assertEquals([
  34. 'CONTENT_TYPE' => 'text/html',
  35. 'CONTENT_LENGTH' => '0',
  36. 'ETAG' => 'asdf',
  37. 'AUTHORIZATION' => 'Basic '.base64_encode('foo:bar'),
  38. 'PHP_AUTH_USER' => 'foo',
  39. 'PHP_AUTH_PW' => 'bar',
  40. ], $bag->getHeaders());
  41. }
  42. public function testHttpPasswordIsOptional()
  43. {
  44. $bag = new ServerBag(['PHP_AUTH_USER' => 'foo']);
  45. $this->assertEquals([
  46. 'AUTHORIZATION' => 'Basic '.base64_encode('foo:'),
  47. 'PHP_AUTH_USER' => 'foo',
  48. 'PHP_AUTH_PW' => '',
  49. ], $bag->getHeaders());
  50. }
  51. public function testHttpPasswordIsOptionalWhenPassedWithHttpPrefix()
  52. {
  53. $bag = new ServerBag(['HTTP_PHP_AUTH_USER' => 'foo']);
  54. $this->assertEquals([
  55. 'AUTHORIZATION' => 'Basic '.base64_encode('foo:'),
  56. 'PHP_AUTH_USER' => 'foo',
  57. ], $bag->getHeaders());
  58. }
  59. public function testHttpBasicAuthWithPhpCgi()
  60. {
  61. $bag = new ServerBag(['HTTP_AUTHORIZATION' => 'Basic '.base64_encode('foo:bar')]);
  62. $this->assertEquals([
  63. 'AUTHORIZATION' => 'Basic '.base64_encode('foo:bar'),
  64. 'PHP_AUTH_USER' => 'foo',
  65. 'PHP_AUTH_PW' => 'bar',
  66. ], $bag->getHeaders());
  67. }
  68. public function testHttpBasicAuthWithPhpCgiBogus()
  69. {
  70. $bag = new ServerBag(['HTTP_AUTHORIZATION' => 'Basic_'.base64_encode('foo:bar')]);
  71. // Username and passwords should not be set as the header is bogus
  72. $headers = $bag->getHeaders();
  73. $this->assertArrayNotHasKey('PHP_AUTH_USER', $headers);
  74. $this->assertArrayNotHasKey('PHP_AUTH_PW', $headers);
  75. }
  76. public function testHttpBasicAuthWithPhpCgiRedirect()
  77. {
  78. $bag = new ServerBag(['REDIRECT_HTTP_AUTHORIZATION' => 'Basic '.base64_encode('username:pass:word')]);
  79. $this->assertEquals([
  80. 'AUTHORIZATION' => 'Basic '.base64_encode('username:pass:word'),
  81. 'PHP_AUTH_USER' => 'username',
  82. 'PHP_AUTH_PW' => 'pass:word',
  83. ], $bag->getHeaders());
  84. }
  85. public function testHttpBasicAuthWithPhpCgiEmptyPassword()
  86. {
  87. $bag = new ServerBag(['HTTP_AUTHORIZATION' => 'Basic '.base64_encode('foo:')]);
  88. $this->assertEquals([
  89. 'AUTHORIZATION' => 'Basic '.base64_encode('foo:'),
  90. 'PHP_AUTH_USER' => 'foo',
  91. 'PHP_AUTH_PW' => '',
  92. ], $bag->getHeaders());
  93. }
  94. public function testHttpDigestAuthWithPhpCgi()
  95. {
  96. $digest = 'Digest username="foo", realm="acme", nonce="'.md5('secret').'", uri="/protected, qop="auth"';
  97. $bag = new ServerBag(['HTTP_AUTHORIZATION' => $digest]);
  98. $this->assertEquals([
  99. 'AUTHORIZATION' => $digest,
  100. 'PHP_AUTH_DIGEST' => $digest,
  101. ], $bag->getHeaders());
  102. }
  103. public function testHttpDigestAuthWithPhpCgiBogus()
  104. {
  105. $digest = 'Digest_username="foo", realm="acme", nonce="'.md5('secret').'", uri="/protected, qop="auth"';
  106. $bag = new ServerBag(['HTTP_AUTHORIZATION' => $digest]);
  107. // Username and passwords should not be set as the header is bogus
  108. $headers = $bag->getHeaders();
  109. $this->assertArrayNotHasKey('PHP_AUTH_USER', $headers);
  110. $this->assertArrayNotHasKey('PHP_AUTH_PW', $headers);
  111. }
  112. public function testHttpDigestAuthWithPhpCgiRedirect()
  113. {
  114. $digest = 'Digest username="foo", realm="acme", nonce="'.md5('secret').'", uri="/protected, qop="auth"';
  115. $bag = new ServerBag(['REDIRECT_HTTP_AUTHORIZATION' => $digest]);
  116. $this->assertEquals([
  117. 'AUTHORIZATION' => $digest,
  118. 'PHP_AUTH_DIGEST' => $digest,
  119. ], $bag->getHeaders());
  120. }
  121. public function testOAuthBearerAuth()
  122. {
  123. $headerContent = 'Bearer L-yLEOr9zhmUYRkzN1jwwxwQ-PBNiKDc8dgfB4hTfvo';
  124. $bag = new ServerBag(['HTTP_AUTHORIZATION' => $headerContent]);
  125. $this->assertEquals([
  126. 'AUTHORIZATION' => $headerContent,
  127. ], $bag->getHeaders());
  128. }
  129. public function testOAuthBearerAuthWithRedirect()
  130. {
  131. $headerContent = 'Bearer L-yLEOr9zhmUYRkzN1jwwxwQ-PBNiKDc8dgfB4hTfvo';
  132. $bag = new ServerBag(['REDIRECT_HTTP_AUTHORIZATION' => $headerContent]);
  133. $this->assertEquals([
  134. 'AUTHORIZATION' => $headerContent,
  135. ], $bag->getHeaders());
  136. }
  137. /**
  138. * @see https://github.com/symfony/symfony/issues/17345
  139. */
  140. public function testItDoesNotOverwriteTheAuthorizationHeaderIfItIsAlreadySet()
  141. {
  142. $headerContent = 'Bearer L-yLEOr9zhmUYRkzN1jwwxwQ-PBNiKDc8dgfB4hTfvo';
  143. $bag = new ServerBag(['PHP_AUTH_USER' => 'foo', 'HTTP_AUTHORIZATION' => $headerContent]);
  144. $this->assertEquals([
  145. 'AUTHORIZATION' => $headerContent,
  146. 'PHP_AUTH_USER' => 'foo',
  147. 'PHP_AUTH_PW' => '',
  148. ], $bag->getHeaders());
  149. }
  150. }