diff --git a/.rubocop.yml b/.rubocop.yml index 8093a01d..db444b2b 100644 --- a/.rubocop.yml +++ b/.rubocop.yml @@ -25,3 +25,19 @@ Gemspec/DevelopmentDependencies: Naming/PredicateMethod: Enabled: false + +Style/MethodCallWithArgsParentheses: + Enabled: true + Exclude: + - "*.gemspec" + AllowedMethods: + - raise + - fail + - yield + - to + - not_to + - to_not + - describe + - context + - it + - specify diff --git a/lib/jwt/jwa/hmac.rb b/lib/jwt/jwa/hmac.rb index 75f2ebe6..f620373f 100644 --- a/lib/jwt/jwa/hmac.rb +++ b/lib/jwt/jwa/hmac.rb @@ -69,7 +69,7 @@ def fixed_length_secure_compare(a, b) def fixed_length_secure_compare(a, b) raise ArgumentError, "string length mismatch." unless a.bytesize == b.bytesize - l = a.unpack "C#{a.bytesize}" + l = a.unpack("C#{a.bytesize}") res = 0 b.each_byte { |byte| res |= byte ^ l.shift } diff --git a/lib/jwt/jwk/ec.rb b/lib/jwt/jwk/ec.rb index e240aa04..7a7761c5 100644 --- a/lib/jwt/jwk/ec.rb +++ b/lib/jwt/jwk/ec.rb @@ -54,7 +54,7 @@ def members def export(options = {}) exported = parameters.clone - exported.reject! { |k, _| EC_PRIVATE_KEY_ELEMENTS.include? k } unless private? && options[:include_private] == true + exported.reject! { |k, _| EC_PRIVATE_KEY_ELEMENTS.include?(k) } unless private? && options[:include_private] == true exported end diff --git a/lib/jwt/jwk/hmac.rb b/lib/jwt/jwk/hmac.rb index 6813367a..5fefac5f 100644 --- a/lib/jwt/jwk/hmac.rb +++ b/lib/jwt/jwk/hmac.rb @@ -47,7 +47,7 @@ def signing_key # See https://tools.ietf.org/html/rfc7517#appendix-A.3 def export(options = {}) exported = parameters.clone - exported.reject! { |k, _| HMAC_PRIVATE_KEY_ELEMENTS.include? k } unless private? && options[:include_private] == true + exported.reject! { |k, _| HMAC_PRIVATE_KEY_ELEMENTS.include?(k) } unless private? && options[:include_private] == true exported end diff --git a/lib/jwt/jwk/rsa.rb b/lib/jwt/jwk/rsa.rb index 2a28e0f7..e0ea2c5c 100644 --- a/lib/jwt/jwk/rsa.rb +++ b/lib/jwt/jwk/rsa.rb @@ -50,7 +50,7 @@ def verify_key def export(options = {}) exported = parameters.clone - exported.reject! { |k, _| RSA_PRIVATE_KEY_ELEMENTS.include? k } unless private? && options[:include_private] == true + exported.reject! { |k, _| RSA_PRIVATE_KEY_ELEMENTS.include?(k) } unless private? && options[:include_private] == true exported end diff --git a/spec/integration/readme_examples_spec.rb b/spec/integration/readme_examples_spec.rb index a354f199..d4313c48 100644 --- a/spec/integration/readme_examples_spec.rb +++ b/spec/integration/readme_examples_spec.rb @@ -7,64 +7,49 @@ let(:payload) { { data: 'test' } } it 'NONE' do - token = JWT.encode payload, nil, 'none' - decoded_token = JWT.decode token, nil, false - - expect(token).to eq 'eyJhbGciOiJub25lIn0.eyJkYXRhIjoidGVzdCJ9.' - expect(decoded_token).to eq [ - { 'data' => 'test' }, - { 'alg' => 'none' } - ] + token = JWT.encode(payload, nil, 'none') + decoded_token = JWT.decode(token, nil, false) + + expect(token).to eq('eyJhbGciOiJub25lIn0.eyJkYXRhIjoidGVzdCJ9.') + expect(decoded_token).to eq([{ 'data' => 'test' }, { 'alg' => 'none' }]) end it 'decodes with HMAC algorithm with secret key' do - token = JWT.encode payload, 'my$ecretK3y', 'HS256' - decoded_token = JWT.decode token, 'my$ecretK3y', false - - expect(token).to eq 'eyJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoidGVzdCJ9.pNIWIL34Jo13LViZAJACzK6Yf0qnvT_BuwOxiMCPE-Y' - expect(decoded_token).to eq [ - { 'data' => 'test' }, - { 'alg' => 'HS256' } - ] + token = JWT.encode(payload, 'my$ecretK3y', 'HS256') + decoded_token = JWT.decode(token, 'my$ecretK3y', false) + + expect(token).to eq('eyJhbGciOiJIUzI1NiJ9.eyJkYXRhIjoidGVzdCJ9.pNIWIL34Jo13LViZAJACzK6Yf0qnvT_BuwOxiMCPE-Y') + expect(decoded_token).to eq([{ 'data' => 'test' }, { 'alg' => 'HS256' }]) end it 'RSA' do - rsa_private = OpenSSL::PKey::RSA.generate 2048 + rsa_private = OpenSSL::PKey::RSA.generate(2048) rsa_public = rsa_private.public_key - token = JWT.encode payload, rsa_private, 'RS256' - decoded_token = JWT.decode token, rsa_public, true, algorithm: 'RS256' + token = JWT.encode(payload, rsa_private, 'RS256') + decoded_token = JWT.decode(token, rsa_public, true, algorithm: 'RS256') - expect(decoded_token).to eq [ - { 'data' => 'test' }, - { 'alg' => 'RS256' } - ] + expect(decoded_token).to eq([{ 'data' => 'test' }, { 'alg' => 'RS256' }]) end it 'ECDSA' do ecdsa_key = OpenSSL::PKey::EC.generate('prime256v1') - token = JWT.encode payload, ecdsa_key, 'ES256' - decoded_token = JWT.decode token, ecdsa_key, true, algorithm: 'ES256' + token = JWT.encode(payload, ecdsa_key, 'ES256') + decoded_token = JWT.decode(token, ecdsa_key, true, algorithm: 'ES256') - expect(decoded_token).to eq [ - { 'data' => 'test' }, - { 'alg' => 'ES256' } - ] + expect(decoded_token).to eq([{ 'data' => 'test' }, { 'alg' => 'ES256' }]) end if Gem::Version.new(OpenSSL::VERSION) >= Gem::Version.new('2.1') it 'RSASSA-PSS' do - rsa_private = OpenSSL::PKey::RSA.generate 2048 + rsa_private = OpenSSL::PKey::RSA.generate(2048) rsa_public = rsa_private.public_key - token = JWT.encode payload, rsa_private, 'PS256' - decoded_token = JWT.decode token, rsa_public, true, algorithm: 'PS256' + token = JWT.encode(payload, rsa_private, 'PS256') + decoded_token = JWT.decode(token, rsa_public, true, algorithm: 'PS256') - expect(decoded_token).to eq [ - { 'data' => 'test' }, - { 'alg' => 'PS256' } - ] + expect(decoded_token).to eq([{ 'data' => 'test' }, { 'alg' => 'PS256' }]) end end end @@ -77,10 +62,10 @@ exp = Time.now.to_i + (4 * 3600) exp_payload = { data: 'data', exp: exp } - token = JWT.encode exp_payload, hmac_secret, 'HS256' + token = JWT.encode(exp_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, algorithm: 'HS256') end.not_to raise_error end @@ -90,10 +75,10 @@ exp_payload = { data: 'data', exp: exp } - token = JWT.encode exp_payload, hmac_secret, 'HS256' + token = JWT.encode(exp_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, leeway: leeway, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, leeway: leeway, algorithm: 'HS256') end.not_to raise_error end end @@ -102,10 +87,10 @@ it 'without leeway' do nbf = Time.now.to_i - 3600 nbf_payload = { data: 'data', nbf: nbf } - token = JWT.encode nbf_payload, hmac_secret, 'HS256' + token = JWT.encode(nbf_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, algorithm: 'HS256') end.not_to raise_error end @@ -113,10 +98,10 @@ nbf = Time.now.to_i + 10 leeway = 30 nbf_payload = { data: 'data', nbf: nbf } - token = JWT.encode nbf_payload, hmac_secret, 'HS256' + token = JWT.encode(nbf_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, leeway: leeway, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, leeway: leeway, algorithm: 'HS256') end.not_to raise_error end end @@ -125,10 +110,10 @@ iss = 'My Awesome Company Inc. or https://my.awesome.website/' iss_payload = { data: 'data', iss: iss } - token = JWT.encode iss_payload, hmac_secret, 'HS256' + token = JWT.encode(iss_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, iss: iss, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, iss: iss, algorithm: 'HS256') end.not_to raise_error end @@ -137,10 +122,10 @@ aud = %w[Young Old] aud_payload = { data: 'data', aud: aud } - token = JWT.encode aud_payload, hmac_secret, 'HS256' + token = JWT.encode(aud_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, aud: %w[Old Young], verify_aud: true, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, aud: %w[Old Young], verify_aud: true, algorithm: 'HS256') end.not_to raise_error end @@ -148,10 +133,10 @@ aud = 'Kids' aud_payload = { data: 'data', aud: aud } - token = JWT.encode aud_payload, hmac_secret, 'HS256' + token = JWT.encode(aud_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, aud: 'Kids', verify_aud: true, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, aud: 'Kids', verify_aud: true, algorithm: 'HS256') end.not_to raise_error end end @@ -163,10 +148,10 @@ jti = Digest::MD5.hexdigest(jti_raw) jti_payload = { data: 'data', iat: iat, jti: jti } - token = JWT.encode jti_payload, hmac_secret, 'HS256' + token = JWT.encode(jti_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, verify_jti: true, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, verify_jti: true, algorithm: 'HS256') end.not_to raise_error end @@ -175,10 +160,10 @@ iat = Time.now.to_i iat_payload = { data: 'data', iat: iat } - token = JWT.encode iat_payload, hmac_secret, 'HS256' + token = JWT.encode(iat_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, verify_iat: true, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, verify_iat: true, algorithm: 'HS256') end.not_to raise_error end @@ -186,10 +171,10 @@ iat = Time.now.to_i - 7 iat_payload = { data: 'data', iat: iat, leeway: 10 } - token = JWT.encode iat_payload, hmac_secret, 'HS256' + token = JWT.encode(iat_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, verify_iat: true, algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, verify_iat: true, algorithm: 'HS256') end.not_to raise_error end end @@ -198,10 +183,10 @@ it 'with custom field' do payload = { data: 'test' } - token = JWT.encode payload, nil, 'none', typ: 'JWT' - _, header = JWT.decode token, nil, false + token = JWT.encode(payload, nil, 'none', typ: 'JWT') + _, header = JWT.decode(token, nil, false) - expect(header['typ']).to eq 'JWT' + expect(header['typ']).to eq('JWT') end end @@ -209,32 +194,32 @@ sub = 'Subject' sub_payload = { data: 'data', sub: sub } - token = JWT.encode sub_payload, hmac_secret, 'HS256' + token = JWT.encode(sub_payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, { sub: sub, verify_sub: true, algorithm: 'HS256' } + JWT.decode(token, hmac_secret, true, { sub: sub, verify_sub: true, algorithm: 'HS256' }) end.not_to raise_error expect do - JWT.decode token, hmac_secret, true, { sub: 'sub', verify_sub: true, algorithm: 'HS256' } + JWT.decode(token, hmac_secret, true, { sub: 'sub', verify_sub: true, algorithm: 'HS256' }) end.to raise_error(JWT::InvalidSubError) expect do - JWT.decode token, hmac_secret, true, { 'sub' => 'sub', verify_sub: true, algorithm: 'HS256' } + JWT.decode(token, hmac_secret, true, { 'sub' => 'sub', verify_sub: true, algorithm: 'HS256' }) end.not_to raise_error end it 'required_claims' do payload = { data: 'test' } - token = JWT.encode payload, hmac_secret, 'HS256' + token = JWT.encode(payload, hmac_secret, 'HS256') expect do - JWT.decode token, hmac_secret, true, required_claims: ['exp'], algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, required_claims: ['exp'], algorithm: 'HS256') end.to raise_error(JWT::MissingRequiredClaim) expect do - JWT.decode token, hmac_secret, true, required_claims: ['data'], algorithm: 'HS256' + JWT.decode(token, hmac_secret, true, required_claims: ['data'], algorithm: 'HS256') end.not_to raise_error end @@ -244,7 +229,7 @@ secrets = { issuers.first => hmac_secret, issuers.last => 'hmac_secret2' } - token = JWT.encode iss_payload, hmac_secret, 'HS256' + token = JWT.encode(iss_payload, hmac_secret, 'HS256') expect do # Add iss to the validation to check if the token has been manipulated diff --git a/spec/jwt/claims/audience_spec.rb b/spec/jwt/claims/audience_spec.rb index a7406ef0..73159055 100644 --- a/spec/jwt/claims/audience_spec.rb +++ b/spec/jwt/claims/audience_spec.rb @@ -16,7 +16,7 @@ it 'raises JWT::InvalidAudError' do expect do subject - end.to raise_error JWT::InvalidAudError + end.to raise_error(JWT::InvalidAudError) end end @@ -27,7 +27,7 @@ it 'raises JWT::InvalidAudError' do expect do subject - end.to raise_error JWT::InvalidAudError + end.to raise_error(JWT::InvalidAudError) end end diff --git a/spec/jwt/claims/not_before_spec.rb b/spec/jwt/claims/not_before_spec.rb index 29677401..6d179e37 100644 --- a/spec/jwt/claims/not_before_spec.rb +++ b/spec/jwt/claims/not_before_spec.rb @@ -6,7 +6,7 @@ describe '#verify!' do context 'when nbf is in the future' do it 'raises JWT::ImmatureSignature' do - expect { described_class.new(leeway: 0).verify!(context: SpecSupport::Token.new(payload: payload)) }.to raise_error JWT::ImmatureSignature + expect { described_class.new(leeway: 0).verify!(context: SpecSupport::Token.new(payload: payload)) }.to raise_error(JWT::ImmatureSignature) end end diff --git a/spec/jwt/claims/numeric_spec.rb b/spec/jwt/claims/numeric_spec.rb index e2f25467..3c0536b7 100644 --- a/spec/jwt/claims/numeric_spec.rb +++ b/spec/jwt/claims/numeric_spec.rb @@ -30,14 +30,14 @@ let(:claims) { { claim => '1' } } it 'raises error' do - expect { subject }.to raise_error JWT::InvalidPayload + expect { subject }.to raise_error(JWT::InvalidPayload) end context 'and key is a string' do let(:claims) { { claim.to_s => '1' } } it 'raises error' do - expect { subject }.to raise_error JWT::InvalidPayload + expect { subject }.to raise_error(JWT::InvalidPayload) end end end @@ -46,7 +46,7 @@ let(:claims) { { claim => Time.now } } it 'raises error' do - expect { subject }.to raise_error JWT::InvalidPayload + expect { subject }.to raise_error(JWT::InvalidPayload) end end @@ -54,7 +54,7 @@ let(:claims) { { claim => '1' } } it 'raises error' do - expect { subject }.to raise_error JWT::InvalidPayload + expect { subject }.to raise_error(JWT::InvalidPayload) end end end diff --git a/spec/jwt/claims/required_spec.rb b/spec/jwt/claims/required_spec.rb index e2c5d7a4..75793ee2 100644 --- a/spec/jwt/claims/required_spec.rb +++ b/spec/jwt/claims/required_spec.rb @@ -8,7 +8,7 @@ context 'when payload is missing the required claim' do let(:required_claims) { ['exp'] } it 'raises JWT::MissingRequiredClaim' do - expect { verify! }.to raise_error JWT::MissingRequiredClaim, 'Missing required claim exp' + expect { verify! }.to raise_error(JWT::MissingRequiredClaim, 'Missing required claim exp') end end diff --git a/spec/jwt/concurrent_encode_decode_spec.rb b/spec/jwt/concurrent_encode_decode_spec.rb index 07809aa1..a9f9df5c 100644 --- a/spec/jwt/concurrent_encode_decode_spec.rb +++ b/spec/jwt/concurrent_encode_decode_spec.rb @@ -17,8 +17,8 @@ token = JWT.encode(input_payload, curve, 'ES256', input_header) output_payload, output_header = JWT.decode(token, public_key, true, { algorithm: 'ES256', verify_expiration: true }) - expect(output_payload).to eq input_payload - expect(output_header).to eq input_header + expect(output_payload).to eq(input_payload) + expect(output_header).to eq(input_header) end end end diff --git a/spec/jwt/jwa/ecdsa_spec.rb b/spec/jwt/jwa/ecdsa_spec.rb index 5d1e9497..3da70361 100644 --- a/spec/jwt/jwa/ecdsa_spec.rb +++ b/spec/jwt/jwa/ecdsa_spec.rb @@ -40,11 +40,11 @@ describe '#verify' do context 'when the verification key is valid' do it 'returns true for a valid signature' do - expect(instance.verify(data: data, signature: signature, verification_key: ecdsa_key)).to be true + expect(instance.verify(data: data, signature: signature, verification_key: ecdsa_key)).to be(true) end it 'returns false for an invalid signature' do - expect(instance.verify(data: data, signature: 'invalid_signature', verification_key: ecdsa_key)).to be false + expect(instance.verify(data: data, signature: 'invalid_signature', verification_key: ecdsa_key)).to be(false) end end diff --git a/spec/jwt/jwa/none_spec.rb b/spec/jwt/jwa/none_spec.rb index ca5a1094..1338e146 100644 --- a/spec/jwt/jwa/none_spec.rb +++ b/spec/jwt/jwa/none_spec.rb @@ -11,7 +11,7 @@ describe '#verify' do it 'returns true' do - expect(subject.verify('data', 'signature', 'key')).to be true + expect(subject.verify('data', 'signature', 'key')).to be(true) end end end diff --git a/spec/jwt/jwk/ec_spec.rb b/spec/jwt/jwk/ec_spec.rb index 77bb77f4..301f3b61 100644 --- a/spec/jwt/jwk/ec_spec.rb +++ b/spec/jwt/jwk/ec_spec.rb @@ -9,16 +9,16 @@ context 'when a keypair with both keys given' do let(:keypair) { ec_key } it 'creates an instance of the class' do - expect(subject).to be_a described_class - expect(subject.private?).to eq true + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(true) end end context 'when a keypair with only public key is given' do let(:keypair) { test_pkey('ec256-public.pem') } it 'creates an instance of the class' do - expect(subject).to be_a described_class - expect(subject.private?).to eq false + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(false) end end @@ -60,7 +60,7 @@ context 'when keypair with private key is exported' do let(:keypair) { ec_key } it 'returns a hash with the both parts of the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :kid, :x, :y) # Exported keys do not currently include private key info, @@ -73,7 +73,7 @@ context 'when keypair with public key is exported' do let(:keypair) { test_pkey('ec256-public.pem') } it 'returns a hash with the public parts of the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :kid, :x, :y) # Don't include private `d` if not explicitly requested. @@ -83,7 +83,7 @@ context 'when a custom "kid" is provided' do let(:kid) { 'custom_key_identifier' } it 'exports it' do - expect(subject[:kid]).to eq 'custom_key_identifier' + expect(subject[:kid]).to eq('custom_key_identifier') end end end @@ -92,7 +92,7 @@ subject { described_class.new(keypair).export(include_private: true) } let(:keypair) { ec_key } it 'returns a hash with the both parts of the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :kid, :x, :y) # `d` is the private part. @@ -194,8 +194,8 @@ let(:params) { exported_key } it 'returns a private key' do - expect(subject.private?).to eq true - expect(subject).to be_a described_class + expect(subject.private?).to eq(true) + expect(subject).to be_a(described_class) # Regular export returns only the non-private parts. public_only = exported_key.reject { |k, _v| k == :d } @@ -221,8 +221,8 @@ let(:params) { exported_key } it 'returns a hash with the public parts of the key' do - expect(subject).to be_a described_class - expect(subject.private?).to eq false + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(false) expect(subject.export).to eq(exported_key) end end diff --git a/spec/jwt/jwk/hmac_spec.rb b/spec/jwt/jwk/hmac_spec.rb index 18c6efab..51aeaa8a 100644 --- a/spec/jwt/jwk/hmac_spec.rb +++ b/spec/jwt/jwk/hmac_spec.rb @@ -8,8 +8,8 @@ describe '.new' do context 'when a secret key given' do it 'creates an instance of the class' do - expect(jwk).to be_a described_class - expect(jwk.private?).to eq true + expect(jwk).to be_a(described_class) + expect(jwk.private?).to eq(true) end end @@ -34,7 +34,7 @@ let(:key) { hmac_key } subject { described_class.new(key, kid).export } it 'returns a hash with the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :kid) end end @@ -43,7 +43,7 @@ let(:key) { hmac_key } subject { described_class.new(key, kid).export(include_private: true) } it 'returns a hash with the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :kid, :k) end end @@ -58,7 +58,7 @@ let(:params) { exported_key } it 'returns a key' do - expect(subject).to be_a described_class + expect(subject).to be_a(described_class) expect(subject.export(include_private: true)).to eq(exported_key) end @@ -102,64 +102,64 @@ describe '#==' do it 'is equal to itself' do other = jwk - expect(jwk == other).to eq true + expect(jwk == other).to eq(true) end it 'is equal to a clone of itself' do other = jwk.clone - expect(jwk == other).to eq true + expect(jwk == other).to eq(true) end it 'is not equal to nil' do other = nil - expect(jwk == other).to eq false + expect(jwk == other).to eq(false) end it 'is not equal to boolean true' do other = true - expect(jwk == other).to eq false + expect(jwk == other).to eq(false) end it 'is not equal to a non-key' do other = Object.new - expect(jwk == other).to eq false + expect(jwk == other).to eq(false) end it 'is not equal to a different key' do other = described_class.new('other-key') - expect(jwk == other).to eq false + expect(jwk == other).to eq(false) end end describe '#<=>' do it 'is equal to itself' do other = jwk - expect(jwk <=> other).to eq 0 + expect(jwk <=> other).to eq(0) end it 'is equal to a clone of itself' do other = jwk.clone - expect(jwk <=> other).to eq 0 + expect(jwk <=> other).to eq(0) end it 'is not comparable to nil' do other = nil - expect(jwk <=> other).to eq nil + expect(jwk <=> other).to eq(nil) end it 'is not comparable to boolean true' do other = true - expect(jwk <=> other).to eq nil + expect(jwk <=> other).to eq(nil) end it 'is not comparable to a non-key' do other = Object.new - expect(jwk <=> other).to eq nil + expect(jwk <=> other).to eq(nil) end it 'is not equal to a different key' do other = described_class.new('other-key') - expect(jwk <=> other).not_to eq 0 + expect(jwk <=> other).not_to eq(0) end end end diff --git a/spec/jwt/jwk/rsa_spec.rb b/spec/jwt/jwk/rsa_spec.rb index a9690222..7fc4ba2e 100644 --- a/spec/jwt/jwk/rsa_spec.rb +++ b/spec/jwt/jwk/rsa_spec.rb @@ -9,16 +9,16 @@ context 'when a keypair with both keys given' do let(:keypair) { rsa_key } it 'creates an instance of the class' do - expect(subject).to be_a described_class - expect(subject.private?).to eq true + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(true) end end context 'when a keypair with only public key is given' do let(:keypair) { rsa_key.public_key } it 'creates an instance of the class' do - expect(subject).to be_a described_class - expect(subject.private?).to eq false + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(false) end end end @@ -37,7 +37,7 @@ context 'when keypair with private key is exported' do let(:keypair) { rsa_key } it 'returns a hash with the public parts of the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :n, :e, :kid) expect(subject).not_to include(:d, :p, :dp, :dq, :qi) end @@ -46,7 +46,7 @@ context 'when keypair with public key is exported' do let(:keypair) { rsa_key.public_key } it 'returns a hash with the public parts of the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :n, :e, :kid) expect(subject).not_to include(:d, :p, :dp, :dq, :qi) end @@ -63,7 +63,7 @@ subject { described_class.new(keypair).export(include_private: true) } let(:keypair) { rsa_key } it 'returns a hash with the public AND private parts of the key' do - expect(subject).to be_a Hash + expect(subject).to be_a(Hash) expect(subject).to include(:kty, :n, :e, :kid, :d, :p, :q, :dp, :dq, :qi) end end @@ -158,8 +158,8 @@ context 'when keypair is imported with symbol keys' do let(:params) { { kty: 'RSA', e: exported_key[:e], n: exported_key[:n] } } it 'returns a hash with the public parts of the key' do - expect(subject).to be_a described_class - expect(subject.private?).to eq false + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(false) expect(subject.export).to eq(exported_key) end end @@ -167,8 +167,8 @@ context 'when keypair is imported with string keys from JSON' do let(:params) { { 'kty' => 'RSA', 'e' => exported_key[:e], 'n' => exported_key[:n] } } it 'returns a hash with the public parts of the key' do - expect(subject).to be_a described_class - expect(subject.private?).to eq false + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(false) expect(subject.export).to eq(exported_key) end end @@ -177,8 +177,8 @@ let(:exported_key) { described_class.new(rsa_key).export(include_private: true) } let(:params) { exported_key } it 'creates a complete keypair' do - expect(subject).to be_a described_class - expect(subject.private?).to eq true + expect(subject).to be_a(described_class) + expect(subject.private?).to eq(true) end end diff --git a/spec/jwt/jwk/set_spec.rb b/spec/jwt/jwk/set_spec.rb index 9c0adf11..3575b82b 100644 --- a/spec/jwt/jwk/set_spec.rb +++ b/spec/jwt/jwk/set_spec.rb @@ -8,7 +8,7 @@ context 'can create a set' do it 'from a JWK' do - jwk = JWT::JWK.new 'testkey' + jwk = JWT::JWK.new('testkey') expect(described_class.new(jwk).keys).to eql([jwk]) end @@ -25,7 +25,7 @@ end it 'from an array of keys' do - jwk = JWT::JWK.new 'testkey' + jwk = JWT::JWK.new('testkey') expect(described_class.new([jwk]).keys).to eql([jwk]) end diff --git a/spec/jwt/jwk_spec.rb b/spec/jwt/jwk_spec.rb index 135910f2..3442dff2 100644 --- a/spec/jwt/jwk_spec.rb +++ b/spec/jwt/jwk_spec.rb @@ -12,7 +12,7 @@ subject { described_class.import(params) } it 'creates a ::JWT::JWK::RSA instance' do - expect(subject).to be_a JWT::JWK::RSA + expect(subject).to be_a(JWT::JWK::RSA) expect(subject.export).to eq(exported_key) end @@ -26,7 +26,7 @@ context 'parsed from JSON' do let(:params) { exported_key } it 'creates a ::JWT::JWK::RSA instance from JSON parsed JWK' do - expect(subject).to be_a JWT::JWK::RSA + expect(subject).to be_a(JWT::JWK::RSA) expect(subject.export).to eq(exported_key) end end @@ -60,17 +60,17 @@ context 'when RSA key is given' do let(:keypair) { rsa_key } - it { is_expected.to be_a JWT::JWK::RSA } + it { is_expected.to be_a(JWT::JWK::RSA) } end context 'when secret key is given' do let(:keypair) { 'secret-key' } - it { is_expected.to be_a JWT::JWK::HMAC } + it { is_expected.to be_a(JWT::JWK::HMAC) } end context 'when EC key is given' do let(:keypair) { ec_key } - it { is_expected.to be_a JWT::JWK::EC } + it { is_expected.to be_a(JWT::JWK::EC) } end context 'when kid is given' do diff --git a/spec/jwt/jwt_spec.rb b/spec/jwt/jwt_spec.rb index 69d4a02b..fe20c77a 100644 --- a/spec/jwt/jwt_spec.rb +++ b/spec/jwt/jwt_spec.rb @@ -11,17 +11,17 @@ let(:encoded_token) { 'eyJhbGciOiJub25lIn0.eyJ1c2VyX2lkIjoic29tZUB1c2VyLnRsZCJ9.' } it 'should generate a valid token' do - token = JWT.encode payload, nil, alg + token = JWT.encode(payload, nil, alg) - expect(token).to eq encoded_token + expect(token).to eq(encoded_token) end context 'decoding without verification' do it 'should decode a valid token' do - jwt_payload, header = JWT.decode encoded_token, nil, false + jwt_payload, header = JWT.decode(encoded_token, nil, false) - expect(header['alg']).to eq alg - expect(jwt_payload).to eq payload + expect(header['alg']).to eq(alg) + expect(jwt_payload).to eq(payload) end end @@ -29,18 +29,18 @@ context 'without specifying the none algorithm' do it 'should fail to decode the token' do expect do - JWT.decode encoded_token, nil, true - end.to raise_error JWT::IncorrectAlgorithm + JWT.decode(encoded_token, nil, true) + end.to raise_error(JWT::IncorrectAlgorithm) end end context 'specifying the none algorithm' do context 'when the claims are valid' do it 'should decode the token' do - jwt_payload, header = JWT.decode encoded_token, nil, true, { algorithms: 'none' } + jwt_payload, header = JWT.decode(encoded_token, nil, true, { algorithms: 'none' }) - expect(header['alg']).to eq 'none' - expect(jwt_payload).to eq payload + expect(header['alg']).to eq('none') + expect(jwt_payload).to eq(payload) end end @@ -48,8 +48,8 @@ let(:encoded_token) { JWT.encode({ exp: 0 }, nil, 'none') } it 'should fail to decode the token' do expect do - JWT.decode encoded_token, nil, true - end.to raise_error JWT::IncorrectAlgorithm + JWT.decode(encoded_token, nil, true) + end.to raise_error(JWT::IncorrectAlgorithm) end end end @@ -63,27 +63,27 @@ }.each do |alg, encoded_token| context "alg: #{alg}" do it 'should generate a valid token' do - token = JWT.encode payload, secret, alg + token = JWT.encode(payload, secret, alg) - expect(token).to eq encoded_token + expect(token).to eq(encoded_token) end it 'should decode a valid token' do - jwt_payload, header = JWT.decode encoded_token, secret, true, algorithm: alg + jwt_payload, header = JWT.decode(encoded_token, secret, true, algorithm: alg) - expect(header['alg']).to eq alg - expect(jwt_payload).to eq payload + expect(header['alg']).to eq(alg) + expect(jwt_payload).to eq(payload) end it 'wrong secret should raise JWT::VerificationError' do expect do - JWT.decode encoded_token, 'wrong_secret', true, algorithm: alg - end.to raise_error JWT::VerificationError + JWT.decode(encoded_token, 'wrong_secret', true, algorithm: alg) + end.to raise_error(JWT::VerificationError) end it 'wrong secret and verify = false should not raise an error' do expect do - JWT.decode encoded_token, 'wrong_secret', false + JWT.decode(encoded_token, 'wrong_secret', false) end.not_to raise_error end end @@ -96,38 +96,38 @@ }.each do |alg, encoded_token| context "alg: #{alg}" do it 'should generate a valid token' do - token = JWT.encode payload, rsa_private, alg + token = JWT.encode(payload, rsa_private, alg) - expect(token).to eq encoded_token + expect(token).to eq(encoded_token) end it 'should decode a valid token' do - jwt_payload, header = JWT.decode encoded_token, rsa_public, true, algorithm: alg + jwt_payload, header = JWT.decode(encoded_token, rsa_public, true, algorithm: alg) - expect(header['alg']).to eq alg - expect(jwt_payload).to eq payload + expect(header['alg']).to eq(alg) + expect(jwt_payload).to eq(payload) end it 'should decode a valid token using algorithm hash string key' do - jwt_payload, header = JWT.decode encoded_token, rsa_public, true, 'algorithm' => alg + jwt_payload, header = JWT.decode(encoded_token, rsa_public, true, 'algorithm' => alg) - expect(header['alg']).to eq alg - expect(jwt_payload).to eq payload + expect(header['alg']).to eq(alg) + expect(jwt_payload).to eq(payload) end it 'wrong key should raise JWT::VerificationError' do key = test_pkey('rsa-2048-wrong-public.pem') expect do - JWT.decode encoded_token, key, true, algorithm: alg - end.to raise_error JWT::VerificationError + JWT.decode(encoded_token, key, true, algorithm: alg) + end.to raise_error(JWT::VerificationError) end it 'wrong key and verify = false should not raise an error' do key = test_pkey('rsa-2048-wrong-public.pem') expect do - JWT.decode encoded_token, key, false + JWT.decode(encoded_token, key, false) end.not_to raise_error end end @@ -149,21 +149,21 @@ end it 'should decode a valid token' do - jwt_payload, header = JWT.decode encoded_token, public_key, true, algorithm: alg + jwt_payload, header = JWT.decode(encoded_token, public_key, true, algorithm: alg) - expect(header['alg']).to eq alg - expect(jwt_payload).to eq payload + expect(header['alg']).to eq(alg) + expect(jwt_payload).to eq(payload) end it 'wrong key should raise JWT::VerificationError' do expect do - JWT.decode encoded_token, wrong_key, true, algorithm: alg - end.to raise_error JWT::VerificationError + JWT.decode(encoded_token, wrong_key, true, algorithm: alg) + end.to raise_error(JWT::VerificationError) end it 'wrong key and verify = false should not raise an error' do expect do - JWT.decode encoded_token, wrong_key, false + JWT.decode(encoded_token, wrong_key, false) end.not_to raise_error end end @@ -195,25 +195,25 @@ salt_length: :auto, mgf1_hash: translated_alg ) - expect(valid_signature).to be true + expect(valid_signature).to be(true) end it 'should decode a valid token' do - jwt_payload, header = JWT.decode encoded_token, rsa_public, true, algorithm: alg + jwt_payload, header = JWT.decode(encoded_token, rsa_public, true, algorithm: alg) - expect(header['alg']).to eq alg - expect(jwt_payload).to eq payload + expect(header['alg']).to eq(alg) + expect(jwt_payload).to eq(payload) end it 'wrong key should raise JWT::VerificationError' do expect do - JWT.decode encoded_token, wrong_key, true, algorithm: alg - end.to raise_error JWT::VerificationError + JWT.decode(encoded_token, wrong_key, true, algorithm: alg) + end.to raise_error(JWT::VerificationError) end it 'wrong key and verify = false should not raise an error' do expect do - JWT.decode encoded_token, wrong_key, false + JWT.decode(encoded_token, wrong_key, false) end.not_to raise_error end end @@ -222,8 +222,8 @@ context 'Invalid' do it 'invalid algorithm should raise EncodeError' do expect do - JWT.encode payload, 'secret', 'HS255' - end.to raise_error JWT::EncodeError + JWT.encode(payload, 'secret', 'HS255') + end.to raise_error(JWT::EncodeError) end it 'raises "No verification key available" error' do @@ -235,17 +235,17 @@ key = OpenSSL::PKey::EC.generate('secp256k1') expect do - JWT.encode payload, key, 'ES256' - end.to raise_error JWT::EncodeError, 'payload algorithm is ES256 but ES256K signing key was provided' + JWT.encode(payload, key, 'ES256') + end.to raise_error(JWT::EncodeError, 'payload algorithm is ES256 but ES256K signing key was provided') end it 'ECDSA curve_name mismatch should raise JWT::IncorrectAlgorithm when decoding' do key = OpenSSL::PKey::EC.generate('secp256k1') - token = JWT.encode payload, test_pkey('ec256-private.pem'), 'ES256' + token = JWT.encode(payload, test_pkey('ec256-private.pem'), 'ES256') expect do - JWT.decode token, key, true, algorithm: 'ES256' - end.to raise_error JWT::IncorrectAlgorithm, 'payload algorithm is ES256 but ES256K verification key was provided' + JWT.decode(token, key, true, algorithm: 'ES256') + end.to raise_error(JWT::IncorrectAlgorithm, 'payload algorithm is ES256 but ES256K verification key was provided') end end @@ -292,7 +292,7 @@ secrets = { iss => ['hmac_secret2', secret] } - token = JWT.encode iss_payload, secret, 'HS256' + token = JWT.encode(iss_payload, secret, 'HS256') expect do JWT.decode(token, nil, true, { iss: iss, verify_iss: true, algorithm: 'HS256' }) do |_headers, payload| @@ -307,7 +307,7 @@ secrets = { iss => secret } - token = JWT.encode iss_payload, secret, 'HS256' + token = JWT.encode(iss_payload, secret, 'HS256') expect do JWT.decode(token, nil, true, { iss: iss, verify_iss: true, algorithm: 'HS256' }) do |_headers, payload| @@ -322,7 +322,7 @@ secrets = { iss => ['hmac_secret2', secret] } - token = JWT.encode iss_payload, secret, 'HS256' + token = JWT.encode(iss_payload, secret, 'HS256') expect do JWT.decode(token, nil, true, { iss: iss, verify_iss: true, algorithm: 'HS256' }) do |_headers, payload| @@ -337,7 +337,7 @@ secrets = { issuers.first => secret, issuers.last => 'hmac_secret2' } - token = JWT.encode iss_payload, secret, 'HS256' + token = JWT.encode(iss_payload, secret, 'HS256') expect do JWT.decode(token, nil, true, { iss: issuers, verify_iss: true, algorithm: 'HS256' }) do |_headers, payload| @@ -352,7 +352,7 @@ secrets = { issuers.first => [secret, 'hmac_secret1'], issuers.last => 'hmac_secret2' } - token = JWT.encode iss_payload, secret, 'HS256' + token = JWT.encode(iss_payload, secret, 'HS256') expect do JWT.decode(token, nil, true, { iss: issuers, verify_iss: true, algorithm: 'HS256' }) do |_headers, payload| @@ -364,31 +364,31 @@ context 'algorithm' do it 'should raise JWT::IncorrectAlgorithm on mismatch' do - token = JWT.encode payload, secret, 'HS256' + token = JWT.encode(payload, secret, 'HS256') expect do - JWT.decode token, secret, true, algorithm: 'HS384' - end.to raise_error JWT::IncorrectAlgorithm + JWT.decode(token, secret, true, algorithm: 'HS384') + end.to raise_error(JWT::IncorrectAlgorithm) expect do - JWT.decode token, secret, true, algorithm: 'HS256' + JWT.decode(token, secret, true, algorithm: 'HS256') end.not_to raise_error end it 'should raise JWT::IncorrectAlgorithm on mismatch prior to kid public key network call' do - token = JWT.encode payload, rsa_private, 'RS256' + token = JWT.encode(payload, rsa_private, 'RS256') expect do JWT.decode(token, nil, true, { algorithms: ['RS384'] }) do |_, _| # unsuccessful keyfinder public key network call here end - end.to raise_error JWT::IncorrectAlgorithm + end.to raise_error(JWT::IncorrectAlgorithm) expect do JWT.decode(token, nil, true, { 'algorithms' => ['RS384'] }) do |_, _| # unsuccessful keyfinder public key network call here end - end.to raise_error JWT::IncorrectAlgorithm + end.to raise_error(JWT::IncorrectAlgorithm) end it 'raises error when keyfinder does not find anything' do @@ -398,68 +398,68 @@ JWT.decode(token, nil, true, algorithm: 'HS256') do nil end - end.to raise_error JWT::SignatureError, 'No verification key available' + end.to raise_error(JWT::SignatureError, 'No verification key available') end it 'should raise JWT::IncorrectAlgorithm when algorithms array does not contain algorithm' do - token = JWT.encode payload, secret, 'HS512' + token = JWT.encode(payload, secret, 'HS512') expect do - JWT.decode token, secret, true, algorithms: ['HS384'] - end.to raise_error JWT::IncorrectAlgorithm + JWT.decode(token, secret, true, algorithms: ['HS384']) + end.to raise_error(JWT::IncorrectAlgorithm) expect do - JWT.decode token, secret, true, 'algorithms' => ['HS384'] - end.to raise_error JWT::IncorrectAlgorithm + JWT.decode(token, secret, true, 'algorithms' => ['HS384']) + end.to raise_error(JWT::IncorrectAlgorithm) expect do - JWT.decode token, secret, true, algorithms: %w[HS512 HS384] + JWT.decode(token, secret, true, algorithms: %w[HS512 HS384]) end.not_to raise_error expect do - JWT.decode token, secret, true, 'algorithms' => %w[HS512 HS384] + JWT.decode(token, secret, true, 'algorithms' => %w[HS512 HS384]) end.not_to raise_error end context 'no algorithm provided' do it 'should use the default decode algorithm' do - token = JWT.encode payload, rsa_public.to_s + token = JWT.encode(payload, rsa_public.to_s) - jwt_payload, header = JWT.decode token, rsa_public.to_s + jwt_payload, header = JWT.decode(token, rsa_public.to_s) - expect(header['alg']).to eq 'HS256' - expect(jwt_payload).to eq payload + expect(header['alg']).to eq('HS256') + expect(jwt_payload).to eq(payload) end end context 'token is missing algorithm' do it 'should raise JWT::IncorrectAlgorithm' do expect do - JWT.decode 'e30K.e30K.e30K' - end.to raise_error JWT::IncorrectAlgorithm + JWT.decode('e30K.e30K.e30K') + end.to raise_error(JWT::IncorrectAlgorithm) end context 'invalid header format' do it 'should raise JWT::MalformedTokenError' do expect do - JWT.decode 'W10.e30K.e30K' - end.to raise_error JWT::MalformedTokenError + JWT.decode('W10.e30K.e30K') + end.to raise_error(JWT::MalformedTokenError) end end context 'invalid 2-segment header format' do it 'should raise JWT::MalformedTokenError' do expect do - JWT.decode 'WyJIUzI1NiJd.e30K' - end.to raise_error JWT::MalformedTokenError, 'Not enough or too many segments' + JWT.decode('WyJIUzI1NiJd.e30K') + end.to raise_error(JWT::MalformedTokenError, 'Not enough or too many segments') end end context '2-segment token' do it 'should raise JWT::IncorrectAlgorithm' do expect do - JWT.decode 'e30K.e30K.' - end.to raise_error JWT::IncorrectAlgorithm + JWT.decode('e30K.e30K.') + end.to raise_error(JWT::IncorrectAlgorithm) end end end @@ -470,12 +470,12 @@ let(:token) do iss_payload = payload.merge(iss: iss) - JWT.encode iss_payload, secret + JWT.encode(iss_payload, secret) end it 'if verify_iss is set to false (default option) should not raise JWT::InvalidIssuerError' do expect do - JWT.decode token, secret, true, iss: iss, algorithm: 'HS256' + JWT.decode(token, secret, true, iss: iss, algorithm: 'HS256') end.not_to raise_error end @@ -566,7 +566,7 @@ it 'should encode string payloads' do expect do - JWT.encode 'Hello World', 'secret' + JWT.encode('Hello World', 'secret') end.not_to raise_error end @@ -577,7 +577,7 @@ end it 'should generate the same token' do - expect(JWT.encode('Hello World', 'secret', 'HS256', { alg: 'HS256' })).to eq JWT.encode('Hello World', 'secret', 'HS256') + expect(JWT.encode('Hello World', 'secret', 'HS256', { alg: 'HS256' })).to eq(JWT.encode('Hello World', 'secret', 'HS256')) end end @@ -637,8 +637,8 @@ it 'calls X5cKeyFinder#from to verify the signature and return the payload' do jwt_payload, header = decoded_token - expect(header['alg']).to eq alg - expect(jwt_payload).to eq payload + expect(header['alg']).to eq(alg) + expect(jwt_payload).to eq(payload) end end diff --git a/spec/jwt/version_spec.rb b/spec/jwt/version_spec.rb index e7611c6e..147321c8 100644 --- a/spec/jwt/version_spec.rb +++ b/spec/jwt/version_spec.rb @@ -20,7 +20,7 @@ end it 'has a PRE version' do - expect(JWT::VERSION::PRE).to be_a(String).or be_nil + expect(JWT::VERSION::PRE).to be_a(String).or(be_nil) end it 'has a STRING version' do diff --git a/spec/spec_helper.rb b/spec/spec_helper.rb index c1992e73..de9527ab 100644 --- a/spec/spec_helper.rb +++ b/spec/spec_helper.rb @@ -12,7 +12,7 @@ puts "OpenSSL::OPENSSL_LIBRARY_VERSION: #{OpenSSL::OPENSSL_LIBRARY_VERSION}\n\n" RSpec.configure do |config| - config.expect_with :rspec do |c| + config.expect_with(:rspec) do |c| c.syntax = :expect end config.include(SpecSupport::TestKeys) @@ -23,6 +23,6 @@ end config.run_all_when_everything_filtered = true - config.filter_run :focus + config.filter_run(:focus) config.order = 'random' end