diff --git a/poetry.lock b/poetry.lock index 588283c..e616760 100644 --- a/poetry.lock +++ b/poetry.lock @@ -142,7 +142,7 @@ werkzeug = "^3.0.0" type = "git" url = "https://github.com/nyjc-computing/campus.git" reference = "weekly" -resolved_reference = "9e37b852958b295480fd1239904fb0a18d7b653c" +resolved_reference = "ff98c44a7c6a1bdd4f7dabcaea46ca254108f6ee" [[package]] name = "certifi" diff --git a/tests/unit/test_oauth_token_contract.py b/tests/unit/test_oauth_token_contract.py index 86fd31f..bd71696 100644 --- a/tests/unit/test_oauth_token_contract.py +++ b/tests/unit/test_oauth_token_contract.py @@ -14,9 +14,12 @@ from_resource still accepts legacy `scopes` lists; - PATCH /credentials/... bodies are validated server-side via OAuthToken.from_resource() (campus #656), which maps the RFC 6749 - `scope` string to `scopes`, accepts legacy `expiry_seconds`, and bags - unknown provider keys into provider_fields; User.update() sends the - full to_resource() output. + `scope` string to `scopes` and bags unknown provider keys into + provider_fields; User.update() sends the full to_resource() output; +- the legacy `expiry_seconds` alias is fully removed (campus #659, + #648 checklist item 2): the constructor rejects the kwarg and + payloads whose only expiry information is `expiry_seconds` fail + validation — `expires_in` is the only accepted form. """ import os @@ -169,5 +172,25 @@ def test_scope_only_payload_passes_server_validation(self): self.assertEqual(validated.scope, "campus.profile") +class TestExpirySecondsAliasRemoved(unittest.TestCase): + """The legacy `expiry_seconds` alias is gone (campus #659, closing + #648 checklist item 2). The client has no call sites; these pins + guard against it creeping back in either direction.""" + + def test_constructor_rejects_expiry_seconds_kwarg(self): + with self.assertRaises(TypeError): + campus.model.OAuthToken(id="tok-1", expiry_seconds=60) + + def test_payload_with_only_expiry_seconds_fails_validation(self): + """Mirrors the server-side validation: a payload whose only + expiry information is the removed legacy key cannot construct, + so the server answers 422 VALIDATION_FAILED.""" + with self.assertRaises(ValueError): + campus.model.OAuthToken.from_resource({ + "access_token": "tok-2", + "expiry_seconds": 60, + }) + + if __name__ == "__main__": unittest.main()