public class HttpBasicAuthenticationFilterTestCase extends AbstractMuleTestCase
{
public void testAuthenticationHeaderFailure() throws Exception
{
MuleEvent oldEvent = RequestContext.getEvent();
MuleEvent event = this.getTestEvent("a");
MuleMessage message = event.getMessage();
message.setProperty(HttpConstants.HEADER_AUTHORIZATION, "Basic a", PropertyScope.INBOUND);
RequestContext.setEvent(event);
HttpBasicAuthenticationFilter filter = new HttpBasicAuthenticationFilter();
SecurityManager manager = mock(SecurityManager.class);
filter.setSecurityManager(manager);
doThrow(new UnauthorisedException(null, (MuleEvent) null)).when(manager).authenticate(
(Authentication) anyObject());
try
{
filter.authenticateInbound(event);
fail("An UnauthorisedException should be thrown");
}
catch (UnauthorisedException e)
{
assertNotNull(event.getMessage().getProperty("WWW-Authenticate"));
assertEquals("Basic realm=", event.getMessage().getProperty("WWW-Authenticate"));
verify(manager);
}
RequestContext.setEvent(oldEvent);
}