diff --git a/src/OpenIddict/OpenIddictProvider.Authentication.cs b/src/OpenIddict/OpenIddictProvider.Authentication.cs index d4772f84..8cea3b45 100644 --- a/src/OpenIddict/OpenIddictProvider.Authentication.cs +++ b/src/OpenIddict/OpenIddictProvider.Authentication.cs @@ -40,7 +40,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.RequestNotSupported, - description: "The request parameter is not supported."); + description: "The 'request' parameter is not supported."); return; } @@ -53,7 +53,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.RequestUriNotSupported, - description: "The request_uri parameter is not supported."); + description: "The 'request_uri' parameter is not supported."); return; } @@ -70,7 +70,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The request_id parameter is not supported."); + description: "The 'request_id' parameter is not supported."); return; } @@ -87,7 +87,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Invalid request: timeout expired."); + description: "The specified 'request_id' parameter is invalid."); return; } @@ -126,7 +126,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedResponseType, - description: "The specified response_type parameter is not supported."); + description: "The specified 'response_type' parameter is not supported."); return; } @@ -140,7 +140,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedResponseType, - description: "The specified response_type parameter is not allowed."); + description: "The specified 'response_type' parameter is not allowed."); return; } @@ -152,7 +152,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedResponseType, - description: "The specified response_type parameter is not allowed."); + description: "The specified 'response_type' parameter is not allowed."); return; } @@ -166,7 +166,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedResponseType, - description: "The specified response_type parameter is not allowed."); + description: "The specified 'response_type' parameter is not allowed."); return; } @@ -194,7 +194,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The specified response_mode parameter is not supported."); + description: "The specified 'response_mode' parameter is not supported."); return; } @@ -207,7 +207,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The required redirect_uri parameter was missing."); + description: "The mandatory 'redirect_uri' parameter is missing."); return; } @@ -239,7 +239,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The specified code_challenge_method parameter is not allowed."); + description: "The specified 'code_challenge_method' parameter is not allowed."); return; } @@ -252,7 +252,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The specified response_type parameter is not allowed when using PKCE."); + description: "The specified 'response_type' parameter is not allowed when using PKCE."); return; } @@ -267,7 +267,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Application not found in the database: ensure that your client_id is correct."); + description: "The specified 'client_id' parameter is invalid."); return; } @@ -280,7 +280,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Invalid redirect_uri."); + description: "The specified 'redirect_uri' parameter is not valid for this client application."); return; } @@ -295,7 +295,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Confidential clients are not allowed to retrieve a token from the authorization endpoint."); + description: "The specified 'response_type' parameter is not valid for this client application."); return; } diff --git a/src/OpenIddict/OpenIddictProvider.Exchange.cs b/src/OpenIddict/OpenIddictProvider.Exchange.cs index f4b3caf6..de89cd01 100644 --- a/src/OpenIddict/OpenIddictProvider.Exchange.cs +++ b/src/OpenIddict/OpenIddictProvider.Exchange.cs @@ -34,7 +34,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedGrantType, - description: "The specified grant_type is not supported by this authorization server."); + description: "The specified 'grant_type' parameter is not supported."); return; } @@ -59,7 +59,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The mandatory 'redirect_uri' parameter was missing."); + description: "The mandatory 'redirect_uri' parameter is missing."); return; } @@ -74,7 +74,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The 'offline_access' scope is not allowed when using grant_type=client_credentials."); + description: "The 'offline_access' scope is not valid for the specified 'grant_type' parameter."); return; } @@ -87,7 +87,8 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Client applications must be authenticated to use the client credentials grant."); + description: "The 'client_id' and 'client_secret' parameters are " + + "required when using the client credentials grant."); return; } @@ -107,7 +108,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The mandatory 'client_id' parameter was missing."); + description: "The mandatory 'client_id' parameter is missing."); return; } @@ -129,7 +130,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Application not found in the database: ensure that your client_id is correct."); + description: "The specified 'client_id' parameter is invalid."); return; } @@ -144,12 +145,12 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnauthorizedClient, - description: "Public clients are not allowed to use the client credentials grant."); + description: "The specified 'grant_type' parameter is not valid for this client application."); return; } - // Reject tokens requests containing a client_secret when the client is a public application. + // Reject token requests containing a client_secret when the client is a public application. if (!string.IsNullOrEmpty(context.ClientSecret)) { logger.LogError("The token request was rejected because the public application '{ClientId}' " + @@ -157,7 +158,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Public clients are not allowed to send a client_secret."); + description: "The 'client_secret' parameter is not valid for this client application."); return; } @@ -181,7 +182,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Missing credentials: ensure that you specified a client_secret."); + description: "The 'client_secret' parameter required for this client application is missing."); return; } @@ -193,7 +194,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Invalid credentials: ensure that you specified a correct client_secret."); + description: "The specified client credentials are invalid."); return; } diff --git a/src/OpenIddict/OpenIddictProvider.Introspection.cs b/src/OpenIddict/OpenIddictProvider.Introspection.cs index 8ff1927e..0e57f23f 100644 --- a/src/OpenIddict/OpenIddictProvider.Introspection.cs +++ b/src/OpenIddict/OpenIddictProvider.Introspection.cs @@ -28,7 +28,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Introspection requests must use HTTP POST."); + description: "The specified HTTP method is not valid."); return Task.FromResult(0); } @@ -49,7 +49,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Clients must be authenticated to use the introspection endpoint."); + description: "The mandatory 'client_id' and/or 'client_secret' parameters are missing."); return; } @@ -63,7 +63,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Application not found in the database: ensure that your client_id is correct."); + description: "The specified 'client_id' parameter is invalid."); return; } @@ -76,7 +76,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Public applications are not allowed to use the introspection endpoint."); + description: "This client application is not allowed to use the introspection endpoint."); return; } @@ -89,7 +89,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Invalid credentials: ensure that you specified a correct client_secret."); + description: "The specified client credentials are invalid."); return; } diff --git a/src/OpenIddict/OpenIddictProvider.Revocation.cs b/src/OpenIddict/OpenIddictProvider.Revocation.cs index 0e3ed525..52883a23 100644 --- a/src/OpenIddict/OpenIddictProvider.Revocation.cs +++ b/src/OpenIddict/OpenIddictProvider.Revocation.cs @@ -35,8 +35,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedTokenType, - description: "Identity tokens cannot be revoked. When specifying a token_type_hint parameter, " + - "its value must be equal to 'access_token', 'authorization_code' or 'refresh_token'."); + description: "The specified 'token_type_hint' parameter is not supported."); return; } @@ -46,8 +45,7 @@ namespace OpenIddict { context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedTokenType, - description: "Access tokens cannot be revoked. When specifying a token_type_hint parameter, " + - "its value must be equal to 'authorization_code' or 'refresh_token'."); + description: "The specified 'token_type_hint' parameter is not supported."); return; } @@ -68,7 +66,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The mandatory 'client_id' parameter was missing."); + description: "The mandatory 'client_id' parameter is missing."); return; } @@ -90,7 +88,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Application not found in the database: ensure that your client_id is correct."); + description: "The specified 'client_id' parameter is invalid."); return; } @@ -98,7 +96,6 @@ namespace OpenIddict // Reject revocation requests containing a client_secret if the application is a public client. if (await applications.IsPublicAsync(application, context.HttpContext.RequestAborted)) { - // Reject tokens requests containing a client_secret when the client is a public application. if (!string.IsNullOrEmpty(context.ClientSecret)) { logger.LogError("The revocation request was rejected because the public application " + @@ -106,7 +103,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Public clients are not allowed to send a client_secret."); + description: "The 'client_secret' parameter is not valid for this client application."); return; } @@ -130,7 +127,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Missing credentials: ensure that you specified a client_secret."); + description: "The 'client_secret' parameter required for this client application is missing."); return; } @@ -142,7 +139,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidClient, - description: "Invalid credentials: ensure that you specified a correct client_secret."); + description: "The specified client credentials are invalid."); return; } @@ -167,7 +164,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedTokenType, - description: "Identity tokens cannot be revoked."); + description: "The specified token cannot be revoked."); return; } @@ -179,7 +176,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.UnsupportedTokenType, - description: "The specified access token cannot be revoked."); + description: "The specified token cannot be revoked."); return; } diff --git a/src/OpenIddict/OpenIddictProvider.Session.cs b/src/OpenIddict/OpenIddictProvider.Session.cs index 06889d89..83f56e47 100644 --- a/src/OpenIddict/OpenIddictProvider.Session.cs +++ b/src/OpenIddict/OpenIddictProvider.Session.cs @@ -43,7 +43,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "The request_id parameter is not supported."); + description: "The 'request_id' parameter is not supported."); return; } @@ -60,7 +60,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Invalid request: timeout expired."); + description: "The specified 'request_id' parameter is invalid."); return; } @@ -121,7 +121,7 @@ namespace OpenIddict context.Reject( error: OpenIdConnectConstants.Errors.InvalidRequest, - description: "Invalid post_logout_redirect_uri."); + description: "The specified 'post_logout_redirect_uri' parameter is not valid."); return; } diff --git a/test/OpenIddict.Tests/OpenIddictProviderTests.Authentication.cs b/test/OpenIddict.Tests/OpenIddictProviderTests.Authentication.cs index 99dc5dfc..3eaab432 100644 --- a/test/OpenIddict.Tests/OpenIddictProviderTests.Authentication.cs +++ b/test/OpenIddict.Tests/OpenIddictProviderTests.Authentication.cs @@ -45,7 +45,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.RequestNotSupported, response.Error); - Assert.Equal("The request parameter is not supported.", response.ErrorDescription); + Assert.Equal("The 'request' parameter is not supported.", response.ErrorDescription); } [Fact] @@ -68,7 +68,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.RequestUriNotSupported, response.Error); - Assert.Equal("The request_uri parameter is not supported.", response.ErrorDescription); + Assert.Equal("The 'request_uri' parameter is not supported.", response.ErrorDescription); } [Fact] @@ -87,7 +87,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The request_id parameter is not supported.", response.ErrorDescription); + Assert.Equal("The 'request_id' parameter is not supported.", response.ErrorDescription); } [Fact] @@ -111,7 +111,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Invalid request: timeout expired.", response.ErrorDescription); + Assert.Equal("The specified 'request_id' parameter is invalid.", response.ErrorDescription); } [Fact] @@ -132,7 +132,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.UnsupportedResponseType, response.Error); - Assert.Equal("The specified response_type parameter is not supported.", response.ErrorDescription); + Assert.Equal("The specified 'response_type' parameter is not supported.", response.ErrorDescription); } [Theory] @@ -168,7 +168,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.UnsupportedResponseType, response.Error); - Assert.Equal("The specified response_type parameter is not allowed.", response.ErrorDescription); + Assert.Equal("The specified 'response_type' parameter is not allowed.", response.ErrorDescription); } [Fact] @@ -215,7 +215,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The specified response_mode parameter is not supported.", response.ErrorDescription); + Assert.Equal("The specified 'response_mode' parameter is not supported.", response.ErrorDescription); } [Fact] @@ -236,7 +236,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The required redirect_uri parameter was missing.", response.ErrorDescription); + Assert.Equal("The mandatory 'redirect_uri' parameter is missing.", response.ErrorDescription); } [Fact] @@ -282,7 +282,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The specified code_challenge_method parameter is not allowed.", response.ErrorDescription); + Assert.Equal("The specified 'code_challenge_method' parameter is not allowed.", response.ErrorDescription); } [Theory] @@ -309,7 +309,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The specified response_type parameter is not allowed when using PKCE.", response.ErrorDescription); + Assert.Equal("The specified 'response_type' parameter is not allowed when using PKCE.", response.ErrorDescription); } [Fact] @@ -339,7 +339,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Application not found in the database: ensure that your client_id is correct.", response.ErrorDescription); + Assert.Equal("The specified 'client_id' parameter is invalid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); } @@ -376,7 +376,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Invalid redirect_uri.", response.ErrorDescription); + Assert.Equal("The specified 'redirect_uri' parameter is not valid for this client application.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.ValidateRedirectUriAsync(application, "http://www.fabrikam.com/path", It.IsAny()), Times.Once()); @@ -424,7 +424,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Confidential clients are not allowed to retrieve a token from the authorization endpoint.", response.ErrorDescription); + Assert.Equal("The specified 'response_type' parameter is not valid for this client application.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.ValidateRedirectUriAsync(application, "http://www.fabrikam.com/path", It.IsAny()), Times.Once()); diff --git a/test/OpenIddict.Tests/OpenIddictProviderTests.Exchange.cs b/test/OpenIddict.Tests/OpenIddictProviderTests.Exchange.cs index ac1313cc..cb6ca02d 100644 --- a/test/OpenIddict.Tests/OpenIddictProviderTests.Exchange.cs +++ b/test/OpenIddict.Tests/OpenIddictProviderTests.Exchange.cs @@ -52,7 +52,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.UnsupportedGrantType, response.Error); - Assert.Equal("The specified grant_type is not supported by this authorization server.", response.ErrorDescription); + Assert.Equal("The specified 'grant_type' parameter is not supported.", response.ErrorDescription); } [Fact] @@ -99,7 +99,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The mandatory 'redirect_uri' parameter was missing.", response.ErrorDescription); + Assert.Equal("The mandatory 'redirect_uri' parameter is missing.", response.ErrorDescription); } [Fact] @@ -119,7 +119,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The 'offline_access' scope is not allowed when using grant_type=client_credentials.", response.ErrorDescription); + Assert.Equal("The 'offline_access' scope is not valid for the specified 'grant_type' parameter.", response.ErrorDescription); } [Theory] @@ -142,7 +142,8 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Client applications must be authenticated to use the client credentials grant.", response.ErrorDescription); + Assert.Equal("The 'client_id' and 'client_secret' parameters are " + + "required when using the client credentials grant.", response.ErrorDescription); } [Fact] @@ -164,7 +165,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The mandatory 'client_id' parameter was missing.", response.ErrorDescription); + Assert.Equal("The mandatory 'client_id' parameter is missing.", response.ErrorDescription); } [Fact] @@ -195,7 +196,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Application not found in the database: ensure that your client_id is correct.", response.ErrorDescription); + Assert.Equal("The specified 'client_id' parameter is invalid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); } @@ -232,7 +233,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.UnauthorizedClient, response.Error); - Assert.Equal("Public clients are not allowed to use the client credentials grant.", response.ErrorDescription); + Assert.Equal("The specified 'grant_type' parameter is not valid for this client application.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -272,7 +273,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Public clients are not allowed to send a client_secret.", response.ErrorDescription); + Assert.Equal("The 'client_secret' parameter is not valid for this client application.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -312,7 +313,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Missing credentials: ensure that you specified a client_secret.", response.ErrorDescription); + Assert.Equal("The 'client_secret' parameter required for this client application is missing.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -352,7 +353,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Missing credentials: ensure that you specified a client_secret.", response.ErrorDescription); + Assert.Equal("The 'client_secret' parameter required for this client application is missing.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -395,7 +396,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Invalid credentials: ensure that you specified a correct client_secret.", response.ErrorDescription); + Assert.Equal("The specified client credentials are invalid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); diff --git a/test/OpenIddict.Tests/OpenIddictProviderTests.Introspection.cs b/test/OpenIddict.Tests/OpenIddictProviderTests.Introspection.cs index 77de1e21..900f4684 100644 --- a/test/OpenIddict.Tests/OpenIddictProviderTests.Introspection.cs +++ b/test/OpenIddict.Tests/OpenIddictProviderTests.Introspection.cs @@ -41,7 +41,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Introspection requests must use HTTP POST.", response.ErrorDescription); + Assert.Equal("The specified HTTP method is not valid.", response.ErrorDescription); } [Theory] @@ -64,7 +64,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Clients must be authenticated to use the introspection endpoint.", response.ErrorDescription); + Assert.Equal("The mandatory 'client_id' and/or 'client_secret' parameters are missing.", response.ErrorDescription); } [Fact] @@ -94,7 +94,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Application not found in the database: ensure that your client_id is correct.", response.ErrorDescription); + Assert.Equal("The specified 'client_id' parameter is invalid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); } @@ -131,7 +131,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Public applications are not allowed to use the introspection endpoint.", response.ErrorDescription); + Assert.Equal("This client application is not allowed to use the introspection endpoint.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -172,7 +172,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Invalid credentials: ensure that you specified a correct client_secret.", response.ErrorDescription); + Assert.Equal("The specified client credentials are invalid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); diff --git a/test/OpenIddict.Tests/OpenIddictProviderTests.Revocation.cs b/test/OpenIddict.Tests/OpenIddictProviderTests.Revocation.cs index 84846303..389d2159 100644 --- a/test/OpenIddict.Tests/OpenIddictProviderTests.Revocation.cs +++ b/test/OpenIddict.Tests/OpenIddictProviderTests.Revocation.cs @@ -27,30 +27,10 @@ namespace OpenIddict.Tests { public partial class OpenIddictProviderTests { - [Fact] - public async Task ValidateRevocationRequest_IdTokenTokenTokenHintIsRejected() - { - // Arrange - var server = CreateAuthorizationServer(); - - var client = new OpenIdConnectClient(server.CreateClient()); - - // Act - var response = await client.PostAsync(RevocationEndpoint, new OpenIdConnectRequest - { - Token = "SlAV32hkKG", - TokenTypeHint = OpenIdConnectConstants.TokenTypeHints.IdToken - }); - - // Assert - Assert.Equal(OpenIdConnectConstants.Errors.UnsupportedTokenType, response.Error); - Assert.Equal( - "Identity tokens cannot be revoked. When specifying a token_type_hint parameter, " + - "its value must be equal to 'access_token', 'authorization_code' or 'refresh_token'.", response.ErrorDescription); - } - - [Fact] - public async Task ValidateRevocationRequest_AccessTokenTokenTokenHintIsRejectedWhenReferenceTokensAreDisabled() + [Theory] + [InlineData(OpenIdConnectConstants.TokenTypeHints.AccessToken)] + [InlineData(OpenIdConnectConstants.TokenTypeHints.IdToken)] + public async Task ValidateRevocationRequest_UnsupportedTokenTypeHintIsRejected(string type) { // Arrange var server = CreateAuthorizationServer(); @@ -61,14 +41,12 @@ namespace OpenIddict.Tests var response = await client.PostAsync(RevocationEndpoint, new OpenIdConnectRequest { Token = "SlAV32hkKG", - TokenTypeHint = OpenIdConnectConstants.TokenTypeHints.AccessToken + TokenTypeHint = type }); // Assert Assert.Equal(OpenIdConnectConstants.Errors.UnsupportedTokenType, response.Error); - Assert.Equal( - "Access tokens cannot be revoked. When specifying a token_type_hint parameter, " + - "its value must be equal to 'authorization_code' or 'refresh_token'.", response.ErrorDescription); + Assert.Equal("The specified 'token_type_hint' parameter is not supported.", response.ErrorDescription); } [Fact] @@ -88,7 +66,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The mandatory 'client_id' parameter was missing.", response.ErrorDescription); + Assert.Equal("The mandatory 'client_id' parameter is missing.", response.ErrorDescription); } [Fact] @@ -118,7 +96,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Application not found in the database: ensure that your client_id is correct.", response.ErrorDescription); + Assert.Equal("The specified 'client_id' parameter is invalid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); } @@ -156,7 +134,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Public clients are not allowed to send a client_secret.", response.ErrorDescription); + Assert.Equal("The 'client_secret' parameter is not valid for this client application.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -195,7 +173,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Missing credentials: ensure that you specified a client_secret.", response.ErrorDescription); + Assert.Equal("The 'client_secret' parameter required for this client application is missing.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -234,7 +212,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Missing credentials: ensure that you specified a client_secret.", response.ErrorDescription); + Assert.Equal("The 'client_secret' parameter required for this client application is missing.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -276,7 +254,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidClient, response.Error); - Assert.Equal("Invalid credentials: ensure that you specified a correct client_secret.", response.ErrorDescription); + Assert.Equal("The specified client credentials are invalid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.Once()); Mock.Get(manager).Verify(mock => mock.GetClientTypeAsync(application, It.IsAny()), Times.Once()); @@ -315,7 +293,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.UnsupportedTokenType, response.Error); - Assert.Equal("The specified access token cannot be revoked.", response.ErrorDescription); + Assert.Equal("The specified token cannot be revoked.", response.ErrorDescription); format.Verify(mock => mock.Unprotect("SlAV32hkKG"), Times.Once()); } @@ -355,7 +333,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.UnsupportedTokenType, response.Error); - Assert.Equal("Identity tokens cannot be revoked.", response.ErrorDescription); + Assert.Equal("The specified token cannot be revoked.", response.ErrorDescription); handler.As() .Verify(mock => mock.CanReadToken("SlAV32hkKG"), Times.Once()); diff --git a/test/OpenIddict.Tests/OpenIddictProviderTests.Session.cs b/test/OpenIddict.Tests/OpenIddictProviderTests.Session.cs index 4b66a1dd..ff53564d 100644 --- a/test/OpenIddict.Tests/OpenIddictProviderTests.Session.cs +++ b/test/OpenIddict.Tests/OpenIddictProviderTests.Session.cs @@ -35,7 +35,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("The request_id parameter is not supported.", response.ErrorDescription); + Assert.Equal("The 'request_id' parameter is not supported.", response.ErrorDescription); } [Fact] @@ -59,7 +59,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Invalid request: timeout expired.", response.ErrorDescription); + Assert.Equal("The specified 'request_id' parameter is invalid.", response.ErrorDescription); } [Theory] @@ -110,7 +110,7 @@ namespace OpenIddict.Tests // Assert Assert.Equal(OpenIdConnectConstants.Errors.InvalidRequest, response.Error); - Assert.Equal("Invalid post_logout_redirect_uri.", response.ErrorDescription); + Assert.Equal("The specified 'post_logout_redirect_uri' parameter is not valid.", response.ErrorDescription); Mock.Get(manager).Verify(mock => mock.ValidatePostLogoutRedirectUriAsync("http://www.fabrikam.com/path", It.IsAny()), Times.Once()); }