summaryrefslogtreecommitdiff
path: root/tests/unit/test_httpapi_vyos.py
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-03 16:44:59 +1000
committeromnom62 <omnom62@outlook.com>2026-10-03 16:44:59 +1000
commite562acc5a2ac5efc16e1a9d623ca962225ee31f7 (patch)
treea8d2366e0833cf4d8824ffe1ccaf2e35da033e2a /tests/unit/test_httpapi_vyos.py
parent6e9fe2c879895ade7c66b4ee199b0bac36f2b2e6 (diff)
downloadrest.vyos-t8989_auth_methods_rework.tar.gz
rest.vyos-t8989_auth_methods_rework.zip
https: T8989: auth_methods AI comments fixedt8989_auth_methods_rework
Diffstat (limited to 'tests/unit/test_httpapi_vyos.py')
-rw-r--r--tests/unit/test_httpapi_vyos.py24
1 files changed, 22 insertions, 2 deletions
diff --git a/tests/unit/test_httpapi_vyos.py b/tests/unit/test_httpapi_vyos.py
index 9b0116b..4541c46 100644
--- a/tests/unit/test_httpapi_vyos.py
+++ b/tests/unit/test_httpapi_vyos.py
@@ -1,8 +1,8 @@
# -*- coding: utf-8 -*-
"""Unit tests for plugins/httpapi/vyos.py
-Tests cover all three auth methods (key, header, bearer) and token
-caching behaviour. The Ansible connection layer is mocked so no
+Tests cover all five auth methods (key, header, bearer, mTLS, and OIDC)
+and token caching behaviour. The Ansible connection layer is mocked so no
real device is needed.
"""
from __future__ import absolute_import, division, print_function
@@ -375,6 +375,26 @@ class TestSendRequestOidcMethod(unittest.TestCase):
plugin.send_request("/retrieve", op="showConfig", path=[])
self.assertIn("OIDC token fetch failed", str(ctx.exception))
+ def test_oidc_passes_configured_timeout(self):
+ """An unavailable or stalled IdP must not hang the task
+ indefinitely -- the timeout is passed through explicitly
+ rather than relying on open_url's own default."""
+ plugin = self._plugin()
+ plugin.get_option = {
+ "auth_method": "oidc",
+ "oidc_token_url": "http://idp/token",
+ "oidc_client_id": "vyos-api",
+ "oidc_client_secret": "secret",
+ "oidc_timeout": 5,
+ }.get
+ with patch("ansible_collections.vyos.rest.plugins.httpapi.vyos.open_url") as mock_open_url:
+ mock_resp = MagicMock()
+ mock_resp.read.return_value = self._idp_response()
+ mock_open_url.return_value = mock_resp
+ plugin.connection.send.return_value = self._retrieve_response()
+ plugin.send_request("/retrieve", op="showConfig", path=[])
+ self.assertEqual(mock_open_url.call_args[1]["timeout"], 5)
+
def test_oidc_raises_when_access_token_missing(self):
plugin = self._plugin()
with patch("ansible_collections.vyos.rest.plugins.httpapi.vyos.open_url") as mock_open_url: