Repository navigation
Expand file tree
/
Copy pathfederate_test.go
More file actions
139 lines (114 loc) · 4.11 KB
/
Copy pathfederate_test.go
File metadata and controls
139 lines (114 loc) · 4.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
package beyond
import (
"io"
"net/http"
"net/http/httptest"
"net/url"
"testing"
"github.com/presbrey/beyond/internal/authn"
"github.com/stretchr/testify/assert"
)
var (
federateServer = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
switch r.URL.Path {
case "/next":
token := r.URL.Query().Get("token")
if token == "" {
w.WriteHeader(551)
return
}
// Make request to testMux directly
request := httptest.NewRequest("GET", "/federate/verify?token="+token, nil)
request.Host = *host
recorder := httptest.NewRecorder()
testMux.ServeHTTP(recorder, request)
resp := recorder.Result()
body, _ := io.ReadAll(resp.Body)
w.WriteHeader(resp.StatusCode)
w.Write(body)
return
default:
return
}
}))
)
func TestFederateSetup(t *testing.T) {
assert.NoError(t, authn.FederateSetup())
// Test that setup works without keys
*authn.FederateAccessKey = "9zcNzr9ObeWnNExMXYbeXxy9CxMMz6FS6ZhSfYRwzXHTNa3ZJo7uFQ2qsWZ5u1Id"
*authn.FederateSecretKey = "S6ZhSfYRwzXHTNa3ZJo7uFQ2qsWZ5u1Id9zcNzr9ObeWnNExMXYbeXxy9CxMMz6F"
assert.NoError(t, authn.FederateSetup())
// Test that setup works with keys
}
func TestFederateHandler(t *testing.T) {
// Test federate endpoint without next parameter
request := httptest.NewRequest("GET", "/federate", nil)
request.Host = *host
w := httptest.NewRecorder()
testMux.ServeHTTP(w, request)
resp := w.Result()
body, _ := io.ReadAll(resp.Body)
assert.Equal(t, 403, resp.StatusCode)
assert.Equal(t, "securecookie: the value is not valid\n", string(body))
// Test federate endpoint with encoded next parameter (no auth)
nextURL := federateServer.URL + "/next?token="
next, err := authn.EncodeFederateNext(nextURL)
assert.NoError(t, err)
request = httptest.NewRequest("GET", "/federate?next="+url.QueryEscape(next), nil)
request.Host = *host
w = httptest.NewRecorder()
testMux.ServeHTTP(w, request)
resp = w.Result()
body, _ = io.ReadAll(resp.Body)
assert.Equal(t, *fouroOneCode, resp.StatusCode)
assert.Contains(t, string(body), "/launch?next=https")
// Test federate endpoint with auth cookie - should redirect to federate server
request = httptest.NewRequest("GET", "/federate?next="+url.QueryEscape(next), nil)
request.Host = *host
session := authn.NewSession(*authn.CookieName)
session.Values["user"] = "cloud@user.com"
recorder := httptest.NewRecorder()
err = authn.GetStore().Save(recorder, session)
assert.NoError(t, err)
cookie := recorder.Header().Get("Set-Cookie")
request.Header.Set("Cookie", cookie)
w = httptest.NewRecorder()
testMux.ServeHTTP(w, request)
resp = w.Result()
body, _ = io.ReadAll(resp.Body)
// The federate handler redirects to the federate server, so we expect a 302
assert.Equal(t, 302, resp.StatusCode)
assert.Contains(t, string(body), "Found")
// Test with invalid next parameter
request = httptest.NewRequest("GET", "/federate?next=invalid", nil)
request.Host = *host
request.Header.Set("Cookie", cookie)
w = httptest.NewRecorder()
testMux.ServeHTTP(w, request)
resp = w.Result()
body, _ = io.ReadAll(resp.Body)
assert.Equal(t, 403, resp.StatusCode)
assert.Contains(t, string(body), "securecookie")
}
func TestFederateVerify500(t *testing.T) {
// Save current keys
oldAccessKey := *authn.FederateAccessKey
oldSecretKey := *authn.FederateSecretKey
// Clear keys to force error
*authn.FederateAccessKey = ""
*authn.FederateSecretKey = ""
// Re-setup with no keys (should create store with no codecs for this test)
// Note: This test may not work as expected if other tests have already set up federation
// In a full test run, federation may already be configured
req := httptest.NewRequest("GET", "http://"+*host+"/federate/verify?", nil)
w := httptest.NewRecorder()
testMux.ServeHTTP(w, req)
resp := w.Result()
_, _ = io.ReadAll(resp.Body)
// Restore keys
*authn.FederateAccessKey = oldAccessKey
*authn.FederateSecretKey = oldSecretKey
// If federation was already set up by previous tests, this might not be 500
// Just check that we get an error response (4xx or 5xx)
assert.True(t, resp.StatusCode >= 400, "Expected error status code, got %d", resp.StatusCode)
}