語言

TestTokenCreator 類別

定義

一個負責建立用於單元測試實作的測試標記的類別,依據 Microsoft。IdentityModel 代幣驗證。

public class TestTokenCreator
type TestTokenCreator = class
Public Class TestTokenCreator
繼承
TestTokenCreator

範例

以下舉例說明如何利用一個通用的測試框架 Xunit 來利用這個類別。 不過,核心概念仍適用於使用任何框架進行單元測試。

範例中想像一個類別 ClassWithMicrosoftIdentityModelDependency,該類別會暴露 ValidateToken,一個呼叫 Microsoft 的方法。IdentityModel 函式庫和 GetTokenValidationParameters 用來檢索TokenValidationParameters被測試程式碼,實際上是用到。 請注意,使用實 TokenValidationParameters 數很重要,因為這樣可以讓單元測試實際確認驗證是否有漏洞(例如某些重要的驗證被停用、 ValidateAudience等等 ValidateIssuer)。

在以下程式碼範例中,generateTokenToTest 應該是這個類別的方法之一。

internal void AssertValidationException(Func{string} generateTokenToTest, Type innerExceptionType, string innerExceptionMessagePart)
{
    try
    {
        ClassWithMicrosoftIdentityModelDependency.ValidateToken(
            generateTokenToTest,
            ClassWithMicrosoftIdentityModelDependency.GetTokenValidationParameters());

        if (innerExceptionType != null || innerExceptionType != null)
            throw new TestException(
                string.Format(
                    "Expected an exception of type '{0}' containing '{1}' in the message.",
                    innerExceptionType,
                    innerExceptionMessagePart));
    }
    catch (Exception e)
    {
        Assert.Equal(typeof(SampleTestTokenValidationException), e.GetType());
        Assert.Equal(innerExceptionType, e.InnerException.GetType());

        if (!string.IsNullOrEmpty(innerExceptionMessagePart))
        {
            Assert.Contains(innerExceptionMessagePart, e.InnerException.Message);
        }
    }
}

[Fact]
public void TokenWithoutSignature()
{
    var testTokenCreator = new TestTokenCreator();
    AssertValidationException(
        testTokenCreator.CreateTokenWithNoSignature,
        typeof(ArgumentException),
        "IDX14111");
}

備註

Microsoft。IdentityModel.SampleTests.SampleTokenValidationClassTests 包含範例,說明此類別如何用來驗證依賴 Microsoft 的簡單憑證驗證類別。IdentityModel 的憑證驗證方法。

建構函式

名稱 Description
TestTokenCreator()

一個負責建立用於單元測試實作的測試標記的類別,依據 Microsoft。IdentityModel 代幣驗證。

屬性

名稱 Description
Audience

在創建的代幣上標記或設定受眾。

Issuer

取得或設定發行者在所建立的代幣上蓋章。

SigningCredentials

取得或設定用於簽署所建立令牌的 SigningCredentials。

方法

名稱 Description
CreateClaimsSetWithInstanceOverrides()

根據實例值建立預設的理賠集合。

CreateDefaultValidToken()

根據類別的 Issuer和 AudienceSigningCredentials 值,建立一個預設有效的測試標記。

CreateExpiredToken()

建立一個已過期的測試 JWS 令牌。

CreateJsonPayload(IDictionary<String,Object>)

根據理賠通過 IDictionary<TKey,TValue>建立 JSON 有效載荷。

CreateNotYetValidToken()

建立一個尚未有效的測試 JWS 令牌。

CreateToken(Dictionary<String,Object>)

根據傳遞 Dictionary<TKey,TValue>的 建立一個標記。

CreateToken(SecurityTokenDescriptor)

根據傳遞 SecurityTokenDescriptor的 建立一個標記。

CreateTokenDescriptorWithInstanceOverrides()

根據實例值建立預設 SecurityTokenDescriptor 值。

CreateTokenWithBadAudience()

建立一個測試 JWS 令牌,對象與設定的實例值不符。

CreateTokenWithBadIssuer()

建立一個測試 JWS 令牌,發行者與設定的實例值不符。

CreateTokenWithBadSignatureKey()

建立一個測試 JWS 令牌,並用與設定值不符的金鑰簽署。

CreateTokenWithFutureIssuedAt()

建立一個測試 JWS 代幣,未來會發行。

CreateTokenWithInvalidSignature()

建立一個帶有與有效載荷不符的簽章的測試憑證。

CreateTokenWithMissingAudience()

建立一個測試 JWS 代幣,但缺少一個受眾(AUD)聲明。

CreateTokenWithMissingExpires()

建立一個測試 JWS 令牌,但缺少一個到期時間(exp)聲明。

CreateTokenWithMissingIssuedAt()

建立一個測試 JWS 令牌,缺少一個 IssuedAt(iat)申訴。

CreateTokenWithMissingIssuer()

建立一個測試 JWS 代幣,並缺少一個發行人(ISS)索賠。

CreateTokenWithMissingKey()

建立一個測試 JWS 標記,沒有簽署金鑰(例如 alg=none,無簽名)。

CreateTokenWithMissingNotBefore()

建立一個測試 JWS 令牌,缺少一個缺少 NotBefore (nbf) 聲明。

CreateTokenWithNoSignature()

建立一個測試 JWS 令牌,但沒有任何簽名。

適用於