App Passwords: Introduce introspection endpoint.

This introduces a new endpoint, `wp/v2/users/me/application-passwords/introspect`, that will return details about the App Password being used to authenticate the current request. This allows for an application to disambiguate between multiple installations of their application which would all share the same `app_id`.

Props xkon, peterwilsoncc, TimothyBlynJacobs.
Fixes #52275.


git-svn-id: https://develop.svn.wordpress.org/trunk@50065 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
Timothy Jacobs
2021-01-29 00:05:20 +00:00
parent 09a72ba49f
commit e290a9b557
7 changed files with 229 additions and 7 deletions
+7 -4
View File
@@ -38,13 +38,15 @@ class Tests_Auth extends WP_UnitTestCase {
$this->user = clone self::$_user;
wp_set_current_user( self::$user_id );
update_site_option( 'using_application_passwords', 1 );
unset( $_SERVER['PHP_AUTH_USER'], $_SERVER['PHP_AUTH_PW'], $GLOBALS['wp_rest_application_password_status'], $GLOBALS['wp_rest_application_password_uuid'] );
}
public function tearDown() {
parent::tearDown();
// Cleanup all the global state.
unset( $_SERVER['PHP_AUTH_USER'], $_SERVER['PHP_AUTH_PW'], $GLOBALS['wp_rest_application_password_status'] );
unset( $_SERVER['PHP_AUTH_USER'], $_SERVER['PHP_AUTH_PW'], $GLOBALS['wp_rest_application_password_status'], $GLOBALS['wp_rest_application_password_uuid'] );
}
function test_auth_cookie_valid() {
@@ -442,7 +444,7 @@ class Tests_Auth extends WP_UnitTestCase {
);
// Create a new app-only password.
list( $user_app_password ) = WP_Application_Passwords::create_new_application_password( $user_id, array( 'name' => 'phpunit' ) );
list( $user_app_password, $item ) = WP_Application_Passwords::create_new_application_password( $user_id, array( 'name' => 'phpunit' ) );
// Fake a REST API request.
add_filter( 'application_password_is_api_request', '__return_true' );
@@ -452,11 +454,11 @@ class Tests_Auth extends WP_UnitTestCase {
$_SERVER['PHP_AUTH_USER'] = 'http_auth_login';
$_SERVER['PHP_AUTH_PW'] = 'http_auth_pass';
$this->assertSame(
null,
$this->assertNull(
wp_validate_application_password( null ),
'Regular user account password should not be allowed for API authentication'
);
$this->assertNull( rest_get_authenticated_app_password() );
// Not try with an App password instead.
$_SERVER['PHP_AUTH_PW'] = $user_app_password;
@@ -466,6 +468,7 @@ class Tests_Auth extends WP_UnitTestCase {
wp_validate_application_password( null ),
'Application passwords should be allowed for API authentication'
);
$this->assertEquals( $item['uuid'], rest_get_authenticated_app_password() );
}
/**