-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathoauth_test.go
More file actions
162 lines (134 loc) 路 3.88 KB
/
Copy pathoauth_test.go
File metadata and controls
162 lines (134 loc) 路 3.88 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
package bskyoauth
import (
"crypto/ecdsa"
"crypto/elliptic"
"crypto/rand"
"testing"
"time"
"github.com/shindakun/bskyoauth/internal/oauth"
)
func TestOAuthStateStoreExpiration(t *testing.T) {
// Create a store with short TTL for testing
store := oauth.NewStateStore(100 * time.Millisecond)
defer store.Stop()
// Generate test key
key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
if err != nil {
t.Fatalf("Failed to generate key: %v", err)
}
// Store a state
testState := &oauth.State{
CodeVerifier: "test-verifier",
DPoPKey: key,
ExpectedIssuer: "https://bsky.social",
}
store.Set("test-state", testState)
// Should be retrievable immediately
retrieved, exists := store.Get("test-state")
if !exists {
t.Fatal("State should exist immediately after setting")
}
if retrieved.CodeVerifier != "test-verifier" {
t.Errorf("Expected verifier 'test-verifier', got '%s'", retrieved.CodeVerifier)
}
// Wait for expiration
time.Sleep(150 * time.Millisecond)
// Should be expired now
_, exists = store.Get("test-state")
if exists {
t.Error("State should be expired after TTL")
}
}
func TestOAuthStateStoreCleanup(t *testing.T) {
// Create a store with short TTL and short cleanup interval for testing
store := oauth.NewStateStoreWithInterval(50*time.Millisecond, 100*time.Millisecond)
defer store.Stop()
// Generate test key
key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
if err != nil {
t.Fatalf("Failed to generate key: %v", err)
}
// Store multiple states
for i := 0; i < 10; i++ {
testState := &oauth.State{
CodeVerifier: "test-verifier",
DPoPKey: key,
ExpectedIssuer: "https://bsky.social",
}
store.Set(string(rune(i)), testState)
}
// Verify all states exist by trying to retrieve them
for i := 0; i < 10; i++ {
if _, exists := store.Get(string(rune(i))); !exists {
t.Errorf("State %d should exist", i)
}
}
// Wait for expiration and at least one cleanup cycle
time.Sleep(200 * time.Millisecond)
// Verify states have been cleaned up
for i := 0; i < 10; i++ {
if _, exists := store.Get(string(rune(i))); exists {
t.Errorf("State %d should be cleaned up", i)
}
}
}
func TestOAuthStateStoreDelete(t *testing.T) {
store := oauth.NewStateStore(1 * time.Minute)
defer store.Stop()
// Generate test key
key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
if err != nil {
t.Fatalf("Failed to generate key: %v", err)
}
// Store a state
testState := &oauth.State{
CodeVerifier: "test-verifier",
DPoPKey: key,
ExpectedIssuer: "https://bsky.social",
}
store.Set("test-state", testState)
// Verify it exists
_, exists := store.Get("test-state")
if !exists {
t.Fatal("State should exist after setting")
}
// Delete it
store.Delete("test-state")
// Verify it's gone
_, exists = store.Get("test-state")
if exists {
t.Error("State should not exist after deletion")
}
}
func TestOAuthStateStoreStop(t *testing.T) {
store := oauth.NewStateStore(1 * time.Minute)
// Stop the store - should be safe to call
store.Stop()
// Calling stop again should also be safe (no panic)
store.Stop()
// Test passes if no panic occurs
}
func TestIssuerValidation(t *testing.T) {
store := oauth.NewStateStore(1 * time.Minute)
defer store.Stop()
// Generate test key
key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
if err != nil {
t.Fatalf("Failed to generate key: %v", err)
}
// Store a state with expected issuer
testState := &oauth.State{
CodeVerifier: "test-verifier",
DPoPKey: key,
ExpectedIssuer: "https://bsky.social",
}
store.Set("test-state", testState)
// Retrieve and verify expected issuer is stored
retrieved, exists := store.Get("test-state")
if !exists {
t.Fatal("State should exist")
}
if retrieved.ExpectedIssuer != "https://bsky.social" {
t.Errorf("Expected issuer 'https://bsky.social', got '%s'", retrieved.ExpectedIssuer)
}
}