;; webid-oidc, implementation of the Solid specification ;; Copyright (C) 2020, 2021 Vivien Kraus ;; This program is free software: you can redistribute it and/or modify ;; it under the terms of the GNU Affero General Public License as ;; published by the Free Software Foundation, either version 3 of the ;; License, or (at your option) any later version. ;; This program is distributed in the hope that it will be useful, ;; but WITHOUT ANY WARRANTY; without even the implied warranty of ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the ;; GNU Affero General Public License for more details. ;; You should have received a copy of the GNU Affero General Public License ;; along with this program. If not, see . (use-modules (webid-oidc dpop-proof) (webid-oidc jti) (webid-oidc jwk) (webid-oidc testing) (webid-oidc errors) (web uri) (srfi srfi-19) (web response)) (with-test-environment "dpop-proof-iat-too-late" (lambda () (define jwk (generate-key #:n-size 2048)) (define cnf (jkt jwk)) (define blacklist (make-jti-list)) (define proof (issue-dpop-proof jwk #:alg 'RS256 #:htm 'GET #:htu (string->uri "https://example.com/res#frag") #:iat (time-utc->date (make-time time-utc 0 0)))) (with-exception-handler (lambda (error) (unless ((record-predicate &dpop-too-old) ((record-accessor &cannot-decode-dpop-proof 'cause) error)) (raise-exception error))) (lambda () (dpop-proof-decode (time-utc->date (make-time time-utc 0 600)) blacklist 'GET (string->uri "https://example.com/res?query") proof cnf) (exit 2)) #:unwind? #t #:unwind-for-type &cannot-decode-dpop-proof)))