Files
shelfmark/tests/core/test_proxy_headers.py
T
Guflly 3c51b7cfaa Fix OIDC redirects on custom ports (#1180)
Fixes #1175

Preserves the forwarded host and port when Shelfmark builds OIDC
callback URLs. The reverse-proxy examples now retain custom ports as
well.

Tests:
- `uv run pytest -n 0 -q tests/core/test_proxy_headers.py
tests/core/test_oidc_routes.py`
- `uv run ruff check shelfmark/main.py tests/core/test_proxy_headers.py`
- `uv run ruff format --check shelfmark/main.py
tests/core/test_proxy_headers.py`
2026-08-11 01:05:23 -04:00

47 lines
1.2 KiB
Python

import importlib
from unittest.mock import Mock, patch
import pytest
@pytest.fixture(scope="module")
def main_module():
with patch("shelfmark.download.orchestrator.start"):
import shelfmark.main as main
importlib.reload(main)
return main
@pytest.mark.parametrize(
"headers",
[
{
"X-Forwarded-Proto": "https",
"X-Forwarded-Host": "library.example.com:12345",
},
{
"X-Forwarded-Proto": "https",
"X-Forwarded-Host": "library.example.com",
"X-Forwarded-Port": "12345",
},
],
)
def test_oidc_redirect_uses_forwarded_external_port(main_module, headers):
oidc_client = Mock()
oidc_client.authorize_redirect.return_value = ("", 302)
with patch(
"shelfmark.core.oidc_routes._get_oidc_client",
return_value=(oidc_client, {}),
):
response = main_module.app.test_client().get(
"/api/auth/oidc/login",
headers=headers,
)
assert response.status_code == 302
oidc_client.authorize_redirect.assert_called_once_with(
"https://library.example.com:12345/api/auth/oidc/callback"
)