Files
Flash5/flash-extensions/flash-ext-security-test/docs
Zakaria El OrcheandClaude Opus 5 f28fc43150 feat(ext-security): add an OAuth 2.1 authorization server
flash-ext-security-oauth-server issues RFC 9068 access tokens (code + PKCE S256,
CIMD and DCR clients, RFC 8707 resources, rotating refresh tokens) for resources on
the application's own origin. Around it: SecurityExtension resolves a configured
origin instead of X-Forwarded-* headers, mechanisms expose schemes() and a route can
be restricted to some of them, McpConfig.mechanisms(...) uses that, OIDC bearers must
be typed at+jwt, and PublicUrl guards outbound fetches against internal addresses.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-22 11:39:09 +00:00
..

flash-ext-security-test

Test-scope utilities for applications on flash-ext-security-core.

FlashTest app = FlashTest.of(flash -> flash.apply(new MyApp()).install(new TestSecurity()));

app.request().with(TestSecurity.as(() -> "alice")).get("/me");                 // any principal
app.request().with(TestSecurity.as(new OidcPrincipal(...))).get("/projects");   // a mechanism's own type

OAuthTestClient drives an application's own authorization server (flash-ext-security-oauth-server) the way an MCP client does — discovery, registration, PKCE, consent, exchange — signing in as any principal:

OAuthTestClient.Tokens tokens = OAuthTestClient.register(app).authorize(() -> "alice");
app.request().with(tokens.bearer()).post("/mcp");

TestSecurity.as(principal) hands the principal to the application by reference — FlashTest serves it in the same JVM — so tests exercise the real UserResolver, RoleResolver and policies with no identity provider running. Tests of the flows themselves use the mechanism's own kit: FakeOidcProvider and OidcTokens in this module for OIDC, a real POST for form login.