fix(02-03): capture OAuth code from JSON redirect URLs

Consent returns the callback URL in JSON, so replay can fill {{oauth:code}} from $.data.redirect_to before the token request.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 13:38:54 +02:00
parent 22f02eed59
commit 8881df9f7a
2 changed files with 35 additions and 0 deletions

View File

@@ -79,6 +79,26 @@ func TestCaptureAndPlaceholderResolution(t *testing.T) {
if !strings.Contains(string(escaped.Response.Body), "{{oauth:redirect}}") {
t.Fatalf("php-escaped redirect not placeholder: %s", escaped.Response.Body)
}
codeStep := Step{
ID: "consent-code",
Response: Response{
Body: Body(`{"data":{"redirect_to":"http://127.0.0.1:8424/oauth/callback?code=oauthCodeFromJSON"}}`),
},
Capture: []CaptureRule{{
From: "response.json.query",
Path: "$.data.redirect_to",
Name: "code",
As: "oauth:code",
Category: "oauth_code",
}},
}
if err := CaptureStep(store, &codeStep); err != nil {
t.Fatal(err)
}
gotCode, ok := store.Get("oauth:code")
if !ok || gotCode != "oauthCodeFromJSON" {
t.Fatalf("json.query code: ok=%v val=%q", ok, gotCode)
}
step2 := Step{
ID: "pkce",