Quarkus接口添加认证后测试不通过,如何处理授权部分?
接口加认证后测试用例的修复方案
给你几个可行的修复方向,结合你的测试代码逐一说明:
1. Mock认证组件,跳过真实认证逻辑
如果你的认证是通过自定义服务或者Spring Security核心组件实现的,直接在测试里Mock这些组件,让认证逻辑直接返回“通过”状态,不用走真实校验流程。
修改后的测试代码示例:
// 假设用的是Spring Security,Mock AuthenticationManager或自定义AuthService @MockBean private AuthenticationManager authenticationManager; @Test public void testInvalidLimitExceptionMapping() { String errorMessage = "Invalid offset or limit values."; String json = mapErrorToJson(errorMessage); // Mock认证通过逻辑 Mockito.when(authenticationManager.authenticate(any(Authentication.class))) .thenReturn(new UsernamePasswordAuthenticationToken("testUser", null, Collections.emptyList())); Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString())) .thenThrow(new InvalidParameterException(errorMessage)); given() .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03") .then() .statusCode(400) .body(is(json)); }
2. 在请求中携带合法的测试用认证凭证
如果不想Mock组件,直接给请求加符合要求的认证头,比如JWT Token或Basic Auth信息:
情况1:JWT认证
@Test public void testInvalidLimitExceptionMapping() { String errorMessage = "Invalid offset or limit values."; String json = mapErrorToJson(errorMessage); Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString())) .thenThrow(new InvalidParameterException(errorMessage)); // 使用预先生成的测试用合法JWT Token String testToken = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."; given() .header("Authorization", "Bearer " + testToken) // 添加认证头 .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03") .then() .statusCode(400) .body(is(json)); }
情况2:Basic认证
@Test public void testInvalidLimitExceptionMapping() { String errorMessage = "Invalid offset or limit values."; String json = mapErrorToJson(errorMessage); Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString())) .thenThrow(new InvalidParameterException(errorMessage)); given() .auth().preemptive().basic("testUsername", "testPassword") // 添加Basic认证 .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03") .then() .statusCode(400) .body(is(json)); }
3. 测试环境临时绕过该接口的认证
如果是Spring项目,可以用测试注解或临时配置,让测试时的这个接口不需要认证:
方法A:用@WithMockUser注解
// 在测试方法或类上添加注解,模拟已登录用户 @WithMockUser(username = "testUser", roles = {"USER"}) @Test public void testInvalidLimitExceptionMapping() { String errorMessage = "Invalid offset or limit values."; String json = mapErrorToJson(errorMessage); Mockito.when(orderService.getOrders(anyInt(), anyInt(), anyString())) .thenThrow(new InvalidParameterException(errorMessage)); given() .when().get("/v1/orders?offset=5&limit=10&date=2023-04-03") .then() .statusCode(400) .body(is(json)); }
方法B:临时修改Security配置
在测试类里添加测试专用的SecurityFilterChain,让/v1/orders接口跳过认证:
@Configuration public class TestSecurityConfig { @Bean public SecurityFilterChain testSecurityFilterChain(HttpSecurity http) throws Exception { http.authorizeHttpRequests(auth -> auth .requestMatchers("/v1/orders").permitAll() // 允许该接口无需认证 .anyRequest().authenticated() ); return http.build(); } }
然后在测试类上引入这个配置:
@Import(TestSecurityConfig.class) public class OrderControllerTest { // 你的测试代码... }
内容的提问来源于stack exchange,提问作者grigor martirosyan
相关产品推荐
相关产品推荐

