mirror of
https://github.com/gosticks/wordpress-develop.git
synced 2026-10-06 23:58:03 +00:00
App Passwords: Introduce introspection endpoint.
This introduces a new endpoint, `wp/v2/users/me/application-passwords/introspect`, that will return details about the App Password being used to authenticate the current request. This allows for an application to disambiguate between multiple installations of their application which would all share the same `app_id`. Props xkon, peterwilsoncc, TimothyBlynJacobs. Fixes #52275. git-svn-id: https://develop.svn.wordpress.org/trunk@50065 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
@@ -38,13 +38,15 @@ class Tests_Auth extends WP_UnitTestCase {
|
||||
$this->user = clone self::$_user;
|
||||
wp_set_current_user( self::$user_id );
|
||||
update_site_option( 'using_application_passwords', 1 );
|
||||
|
||||
unset( $_SERVER['PHP_AUTH_USER'], $_SERVER['PHP_AUTH_PW'], $GLOBALS['wp_rest_application_password_status'], $GLOBALS['wp_rest_application_password_uuid'] );
|
||||
}
|
||||
|
||||
public function tearDown() {
|
||||
parent::tearDown();
|
||||
|
||||
// Cleanup all the global state.
|
||||
unset( $_SERVER['PHP_AUTH_USER'], $_SERVER['PHP_AUTH_PW'], $GLOBALS['wp_rest_application_password_status'] );
|
||||
unset( $_SERVER['PHP_AUTH_USER'], $_SERVER['PHP_AUTH_PW'], $GLOBALS['wp_rest_application_password_status'], $GLOBALS['wp_rest_application_password_uuid'] );
|
||||
}
|
||||
|
||||
function test_auth_cookie_valid() {
|
||||
@@ -442,7 +444,7 @@ class Tests_Auth extends WP_UnitTestCase {
|
||||
);
|
||||
|
||||
// Create a new app-only password.
|
||||
list( $user_app_password ) = WP_Application_Passwords::create_new_application_password( $user_id, array( 'name' => 'phpunit' ) );
|
||||
list( $user_app_password, $item ) = WP_Application_Passwords::create_new_application_password( $user_id, array( 'name' => 'phpunit' ) );
|
||||
|
||||
// Fake a REST API request.
|
||||
add_filter( 'application_password_is_api_request', '__return_true' );
|
||||
@@ -452,11 +454,11 @@ class Tests_Auth extends WP_UnitTestCase {
|
||||
$_SERVER['PHP_AUTH_USER'] = 'http_auth_login';
|
||||
$_SERVER['PHP_AUTH_PW'] = 'http_auth_pass';
|
||||
|
||||
$this->assertSame(
|
||||
null,
|
||||
$this->assertNull(
|
||||
wp_validate_application_password( null ),
|
||||
'Regular user account password should not be allowed for API authentication'
|
||||
);
|
||||
$this->assertNull( rest_get_authenticated_app_password() );
|
||||
|
||||
// Not try with an App password instead.
|
||||
$_SERVER['PHP_AUTH_PW'] = $user_app_password;
|
||||
@@ -466,6 +468,7 @@ class Tests_Auth extends WP_UnitTestCase {
|
||||
wp_validate_application_password( null ),
|
||||
'Application passwords should be allowed for API authentication'
|
||||
);
|
||||
$this->assertEquals( $item['uuid'], rest_get_authenticated_app_password() );
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user