commit c2b2391bec10c9fc6090da32f49d797195af1fc2
parent 9f243046efb7ffc3bf7b0690632434645effac81
Author: Christian Grothoff <christian@grothoff.org>
Date: Thu, 24 Sep 2026 00:24:56 +0200
testing: check that a code with a forged OAuth2 state is refused
Issue: https://bugs.taler.net/n/11740
Signed-off-by: Christian Grothoff <christian@grothoff.org>
Diffstat:
1 file changed, 8 insertions(+), 0 deletions(-)
diff --git a/src/testing/test_kyc_api.c b/src/testing/test_kyc_api.c
@@ -161,6 +161,14 @@ run (void *cls,
"get-kyc-info-withdraw",
0,
MHD_HTTP_OK),
+ /* A code sent along with just the account instead of the state
+ the exchange issued must not complete the process. */
+ TALER_TESTING_cmd_proof_kyc_oauth2 (
+ "proof-kyc-withdraw-oauth2-forged",
+ "withdraw-coin-1-lacking-kyc",
+ "test-oauth2",
+ "pass",
+ MHD_HTTP_FORBIDDEN),
TALER_TESTING_cmd_proof_kyc_oauth2 (
"proof-kyc-withdraw-oauth2",
"start-kyc-process-withdraw",