add credential absence assertions to test_pkce_token_exchange_basic_auth

Verify that client_id and client_secret are NOT double-sent in the POST
body when Basic Auth is used (include_client_id=False with client_secret).
Catches regressions where credentials leak into both Auth header and body.
This commit is contained in:
Ishaan Jaffer 2026-03-06 14:48:23 -08:00
parent 0c60c0f892
commit 427d013d8c

View file

@ -3423,6 +3423,10 @@ class TestPKCEFunctionality:
assert isinstance(kwargs["auth"], httpx.BasicAuth)
# Verify code_verifier is in the POST body (essential PKCE field)
assert kwargs.get("data", {}).get("code_verifier") == "verifier_abc"
# Verify credentials are NOT double-sent in the POST body when using Basic Auth
post_data = kwargs.get("data", {})
assert "client_secret" not in post_data, "client_secret must not appear in POST body when using Basic Auth"
assert "client_id" not in post_data, "client_id must not appear in POST body when using Basic Auth (include_client_id=False)"
return mock_response
# Use separate mock clients for token exchange and userinfo —