Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 47 additions & 0 deletions src/main/java/com/box/sdk/BoxAPIConnection.java
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ public class BoxAPIConnection {

private static final String AUTHORIZATION_URL = "https://account.box.com/api/oauth2/authorize";
private static final String TOKEN_URL_STRING = "https://api.box.com/oauth2/token";
private static final String REVOKE_URL_STRING = "https://api.box.com/oauth2/revoke";
private static final String DEFAULT_BASE_URL = "https://api.box.com/2.0/";
private static final String DEFAULT_BASE_UPLOAD_URL = "https://upload.box.com/api/2.0/";

Expand All @@ -52,6 +53,7 @@ public class BoxAPIConnection {
private String accessToken;
private String refreshToken;
private String tokenURL;
private String revokeURL;
private String baseURL;
private String baseUploadURL;
private boolean autoRefresh;
Expand Down Expand Up @@ -80,6 +82,7 @@ public BoxAPIConnection(String clientID, String clientSecret, String accessToken
this.accessToken = accessToken;
this.refreshToken = refreshToken;
this.tokenURL = TOKEN_URL_STRING;
this.revokeURL = REVOKE_URL_STRING;
this.baseURL = DEFAULT_BASE_URL;
this.baseUploadURL = DEFAULT_BASE_UPLOAD_URL;
this.autoRefresh = true;
Expand Down Expand Up @@ -247,6 +250,22 @@ public void setTokenURL(String tokenURL) {
this.tokenURL = tokenURL;
}

/**
* Set the URL used for token revocation.
* @param url The url to use.
*/
public void setRevokeURL(String url) {
this.revokeURL = url;
}

/**
* Returns the URL used for token revocation.
* @return The url used for token revocation.
*/
public String getRevokeURL() {
return this.revokeURL;
}

/**
* Gets the base URL that's used when sending requests to the Box API. The default value is
* "https://api.box.com/2.0/".
Expand Down Expand Up @@ -667,6 +686,34 @@ public ScopedToken getLowerScopedToken(List<String> scopes, String resource) {
return token;
}

/**
* Revokes the tokens associated with this API connection. This results in the connection no
* longer being able to make API calls until a fresh authorization is made by calling authenticate()
*/
public void revokeToken() {

URL url = null;
try {
url = new URL(this.revokeURL);
} catch (MalformedURLException e) {
assert false : "An invalid refresh URL indicates a bug in the SDK.";
throw new RuntimeException("An invalid refresh URL indicates a bug in the SDK.", e);
}

String urlParameters = String.format("token=%s&client_id=%s&client_secret=%s",
this.accessToken, this.clientID, this.clientSecret);

BoxAPIRequest request = new BoxAPIRequest(this, url, "POST");
request.shouldAuthenticate(false);
request.setBody(urlParameters);

try {
request.send();
} catch (BoxAPIException e) {
throw e;
}
}

/**
* Saves the state of this connection to a string so that it can be persisted and restored at a later time.
*
Expand Down
56 changes: 56 additions & 0 deletions src/test/java/com/box/sdk/BoxAPIConnectionTest.java
Original file line number Diff line number Diff line change
Expand Up @@ -21,12 +21,28 @@
import static org.mockito.Mockito.when;

import org.junit.Assert;
import org.junit.Rule;
import org.junit.Test;
import org.junit.experimental.categories.Category;


import com.eclipsesource.json.JsonObject;

import com.github.tomakehurst.wiremock.client.WireMock;
import static com.github.tomakehurst.wiremock.client.WireMock.aResponse;
import static com.github.tomakehurst.wiremock.client.WireMock.post;
import static com.github.tomakehurst.wiremock.client.WireMock.stubFor;
import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo;
import com.github.tomakehurst.wiremock.junit.WireMockRule;

public class BoxAPIConnectionTest {

/**
* Wiremock
*/
@Rule
public final WireMockRule wireMockRule = new WireMockRule(53620);

@Test
@Category(UnitTest.class)
public void canRefreshWhenGivenRefreshToken() {
Expand Down Expand Up @@ -248,6 +264,46 @@ public void successfullySavesAndRestoresConnection() {
TestConfig.setRefreshToken(restoredAPI.getRefreshToken());
}

@Test
@Category(IntegrationTest.class)
public void revokeToken() {

String accessToken = TestConfig.getAccessToken();
String clientID = TestConfig.getClientID();
String clientSecret = TestConfig.getClientSecret();
BoxAPIConnection api = new BoxAPIConnection(clientID, clientSecret, accessToken, "");

BoxFolder.getRootFolder(api);

api.revokeToken();

try {
BoxFolder.getRootFolder(api);
} catch (BoxAPIException ex) {
assertEquals(401, ex.getResponseCode());
}
}

@Test
@Category(UnitTest.class)
public void revokeTokenCallsCorrectEndpoint() {

String accessToken = "fakeAccessToken";
String clientID = "fakeID";
String clientSecret = "fakeSecret";

BoxAPIConnection api = new BoxAPIConnection(clientID, clientSecret, accessToken, "");
api.setRevokeURL("http://localhost:53620/oauth2/revoke");

stubFor(post(urlPathEqualTo("/oauth2/revoke"))
.withRequestBody(WireMock.equalTo("token=fakeAccessToken&client_id=fakeID&client_secret=fakeSecret"))
.willReturn(aResponse()
.withHeader("Content-Type", "application/json")
.withBody("")));

api.revokeToken();
}

@Test
@Category(IntegrationTestJWT.class)
public void developerEditionAppAuthWorks() throws IOException {
Expand Down