Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,9 @@
"testFile": "cross-env JEST_TESTS=1 jest --config=jest.config.js --verbose --runInBand --bail=1 --no-cache ",
"test:pdf-annotations:harness:install": "playwright install chromium",
"test:pdf-annotations:harness": "playwright test --config=projects/pdf-annotations/harness/playwright.config.ts",
"start:opds-pkce-test-server": "node projects/opds-pkce-test-server/server.mjs",
"test:opds-pkce-test-server": "node --test projects/opds-pkce-test-server/server.test.mjs",
"test:opds-pkce": "cross-env JEST_TESTS=1 jest --config=jest.config.js --verbose --runInBand --bail=1 --no-cache test/main/network/opdsPkce.test.ts",
"_NOT_NEEDED_postinstall_ReactARIAComponents": "node ./scripts/adobe-spectrum-react-aria-components-patch.js",
"_NOT_NEEDED_postinstall": "npm run pinCompromisedColorPackage && npm run electron-build",
"_NOT_NEEDED_pinCompromisedColorPackage": "(npm ls colors || echo \"NPM LS?\") && rimraf node_modules/electron-rebuild/node_modules/colors && rimraf node_modules/dir-compare/node_modules/colors",
Expand Down
38 changes: 38 additions & 0 deletions projects/opds-pkce-test-server/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# OPDS Authorization Code with PKCE test server

This dependency-free loopback server exercises the flow proposed in
[opds-community/drafts#100](https://github.com/opds-community/drafts/issues/100).
It is for local development only and does not authenticate real users.

Run it from the repository root:

```powershell
npm run start:opds-pkce-test-server
```

Then add this protected catalog to Thorium:

```text
http://127.0.0.1:49152/opds/v2/catalog
```

The authentication document contains only the proposed flow type and its
required `authenticate` and `refresh` links. The server expects the shared OPDS
client ID `http://opds-spec.org/auth/client`, the callback `opds://authorize/`,
and PKCE `S256`. The `refresh` link targets `/token`, which handles both the
authorization-code exchange and refresh-token grant.

Because this local server uses plain HTTP, only development and CI builds of
Thorium accept its loopback endpoints. Production builds require HTTPS.

Use a different port with an optional argument:

```powershell
node projects\opds-pkce-test-server\server.mjs 49153
```

Run its tests with:

```powershell
npm run test:opds-pkce-test-server
```
Loading
Loading