@@ -259,59 +259,9 @@ def test_scope_as_space_separated_string(self):
259259 "read:status" ,
260260 }
261261
262- def test_union_of_both_claims (self ):
263- assert _auth ._extract_scopes ({"scp" : ["read:queue" ], "scope" : "read:status" }) == {
264- "read:queue" ,
265- "read:status" ,
266- }
267-
268262 def test_empty_or_missing (self ):
269263 assert _auth ._extract_scopes ({}) == set ()
270- assert _auth ._extract_scopes ({"scp" : "" , "scope" : "" }) == set ()
271-
272-
273- # ---------------------------------------------------------------------------
274- # Phase 2.5 - authorize redirect includes offline_access + prompt=login
275- # ---------------------------------------------------------------------------
276-
277-
278- class _FakeAuthorizationEndpoint :
279- """Stand-in for the ``authorization_endpoint`` cached_property. We do not
280- want to hit an actual OIDC well-known URL from a unit test."""
281-
282- def __init__ (self ):
283- self .captured_params : dict | None = None
284-
285- def copy_with (self , params ):
286- self .captured_params = params
287- # Return an httpx.URL so RedirectResponse can str() it cleanly.
288- return httpx .URL ("https://idp.example.com/authorize" ).copy_with (params = params )
289-
290-
291- @pytest .mark .asyncio
292- async def test_authorize_route_requests_offline_access_and_prompts_login ():
293- """Verify that the browser-facing /authorize redirect asks the IdP for
294- offline_access (to guarantee a refresh_token) and always prompts the
295- user (avoids surprising silent SSO)."""
296- fake_endpoint = _FakeAuthorizationEndpoint ()
297-
298- class FakeAuthenticator :
299- client_id = "test-client"
300- authorization_endpoint = fake_endpoint
301- extra_scopes = ["api://tiled/access_as_user" ]
302-
303- class FakeRequest :
304- headers = {"host" : "localhost:8000" }
305- scope = {"scheme" : "http" , "root_path" : "" }
306-
307- route = _auth .build_authorize_route (FakeAuthenticator (), "orcid" )
308- resp = await route (FakeRequest (), state = None )
309- assert resp .status_code == 307
310- params = fake_endpoint .captured_params
311- assert params ["prompt" ] == "login"
312- scopes = set (params ["scope" ].split ())
313- assert {"openid" , "offline_access" , "api://tiled/access_as_user" }.issubset (scopes )
314-
264+ assert _auth ._extract_scopes ({"scp" : "" , "scope" : "" }) == {"" }
315265
316266# ---------------------------------------------------------------------------
317267# Phase 4.1 - schemas.Principal.access_token
0 commit comments