haydn-j-evans commented on code in PR #17389:
URL: https://github.com/apache/iceberg/pull/17389#discussion_r4116553865
##########
core/src/test/java/org/apache/iceberg/rest/auth/TestOAuth2Util.java:
##########
@@ -253,6 +258,98 @@ private static void
assertRefreshIncludesOptionalOAuthParams(long expiresAtMilli
}
}
+ @Test
+ void fromTokenFileReadsInitialToken(@TempDir Path tempDir) throws
IOException {
+ String token = tokenWithExp(7200);
+ Path tokenFile = tempDir.resolve("token");
+ Files.writeString(tokenFile, token);
+
+ AuthSession parent = new AuthSession(Map.of(),
AuthConfig.builder().build());
+ AuthSession session = AuthSession.fromTokenFile(null,
tokenFile.toString(), 300_000L, parent);
+
+ assertThat(session.token()).isEqualTo(token);
+
assertThat(session.expiresAtMillis()).isEqualTo(TimeUnit.SECONDS.toMillis(7200));
+ assertThat(session.headers()).containsEntry("Authorization", "Bearer " +
token);
+ }
+
+ @Test
+ void fromTokenFileTrimsWhitespace(@TempDir Path tempDir) throws IOException {
+ String token = tokenWithExp(7200);
+ Path tokenFile = tempDir.resolve("token");
+ Files.writeString(tokenFile, token + "\n");
+
+ AuthSession parent = new AuthSession(Map.of(),
AuthConfig.builder().build());
+ AuthSession session = AuthSession.fromTokenFile(null,
tokenFile.toString(), 300_000L, parent);
+
+ assertThat(session.token()).isEqualTo(token);
+ }
+
+ @Test
+ void fromTokenFileMissingFileThrows(@TempDir Path tempDir) {
+ Path missing = tempDir.resolve("does-not-exist");
+ AuthSession parent = new AuthSession(Map.of(),
AuthConfig.builder().build());
+
+ assertThatThrownBy(() -> AuthSession.fromTokenFile(null,
missing.toString(), 300_000L, parent))
+ .isInstanceOf(UncheckedIOException.class)
+ .hasMessageContaining("Failed to read token file: " + missing);
+ }
+
+ @Test
+ void refreshFromFilePicksUpRotatedToken(@TempDir Path tempDir) throws
IOException {
+ String initialToken = tokenWithExp(7200);
+ Path tokenFile = tempDir.resolve("token");
+ Files.writeString(tokenFile, initialToken);
+
+ AuthSession parent = new AuthSession(Map.of(),
AuthConfig.builder().build());
+ AuthSession session = AuthSession.fromTokenFile(null,
tokenFile.toString(), 300_000L, parent);
+
+ String rotatedToken = tokenWithExp(500);
+ Files.writeString(tokenFile, rotatedToken);
+
+ Long newExpiresAtMillis = session.refreshFromFile();
+
+ assertThat(newExpiresAtMillis).isEqualTo(TimeUnit.SECONDS.toMillis(500));
+ assertThat(session.token()).isEqualTo(rotatedToken);
+
assertThat(session.expiresAtMillis()).isEqualTo(TimeUnit.SECONDS.toMillis(500));
+ assertThat(session.headers()).containsEntry("Authorization", "Bearer " +
rotatedToken);
+ }
+
+ @Test
+ void refreshFromFileOpaqueTokenFallsBackToDefaultExpiry(@TempDir Path
tempDir)
+ throws IOException {
+ Path tokenFile = tempDir.resolve("token");
+ Files.writeString(tokenFile, "opaque-token");
+
+ AuthSession parent = new AuthSession(Map.of(),
AuthConfig.builder().build());
+ AuthSession session = AuthSession.fromTokenFile(null,
tokenFile.toString(), 300_000L, parent);
+
+ long before = System.currentTimeMillis();
+ Long expiresAtMillis = session.refreshFromFile();
+ long after = System.currentTimeMillis();
+
+ assertThat(expiresAtMillis)
+ .isBetween(
+ before + OAuth2Properties.TOKEN_EXPIRES_IN_MS_DEFAULT,
+ after + OAuth2Properties.TOKEN_EXPIRES_IN_MS_DEFAULT);
+ }
+
+ @Test
+ void refreshFromFileTransientFailureKeepsStaleToken(@TempDir Path tempDir)
throws IOException {
+ String token = tokenWithExp(7200);
+ Path tokenFile = tempDir.resolve("token");
+ Files.writeString(tokenFile, token);
+
+ AuthSession parent = new AuthSession(Map.of(),
AuthConfig.builder().build());
+ AuthSession session = AuthSession.fromTokenFile(null,
tokenFile.toString(), 300_000L, parent);
+
+ Files.delete(tokenFile);
+
+ Long result = session.refreshFromFile();
+
+ assertThat(result).isNull();
+ assertThat(session.token()).isEqualTo(token);
+ }
+
Review Comment:
added a test and made sure it failed against the previous commit.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]