Hello. Is my reading of the docs (<here>) correct ...
# pactflow
j
Hello. Is my reading of the docs (here) correct that in BDCT there's no way of writing a consumer contract which specifies an oauth2 scope used in a theoretical token as part of it's
given
which is validated against the security schema of a providers oas contract?
m
It won’t check the token/scopes, but you can write tests that have OAuth2 on them. Here is an example repo if it helps: https://github.com/pactflow/bdct-oas-examples/tree/main/examples/security
Basically, the OAuth info is not checked as part of the test
j
Thanks, @Matt (pactflow.io / pact-js / pact-go). Are there plans or desire to expand on OAuth checking? Since scopes are often defined in the oas, it might be a nice extra layer to be able to check the correctness of requested scopes in a hypothetical oauth token.
m
I remember thinking about it a while back and it either being difficult or not possible. How would you check the scopes?
Specifically, how would you know what scopes the consumer has on their token from a Pact file? You would presumably need to encode the JWT in the pact file and then unpack it?
If you had thoughts on how to do it, you could have a crack at adding it here: https://github.com/pactflow/swagger-mock-validator
j
I had not gotten even nearly that far 🙂. I'll have a look in the repo - my instinct was not to encode a JWT but some other oauth specific custom matching rule on the request which provides instruction on what scopes would be in the JWT.
😆 1