diff options
context:
space:
mode:
Diffstat (limited to 'tests/extensions/test-auth.lua')
-rw-r--r--tests/extensions/test-auth.lua93
1 file changed, 31 insertions, 62 deletions
diff --git a/tests/extensions/test-auth.lua b/tests/extensions/test-auth.lua
index 359f52e..e9fed78 100644
--- a/tests/extensions/test-auth.lua
+++ b/tests/extensions/test-auth.lua
@@ -79,16 +79,14 @@ local userset = repo_userset("secret-repo")
h.check("a protected repository lists its users",
userset ~= nil and userset.alice and userset.bob)
h.equals("an unlisted repository is public", repo_userset("unlisted"), nil)
-h.equals("the repository name matches case exactly",
- repo_userset("Secret-Repo"), nil)
+h.equals("the repository name matches case exactly", repo_userset("Secret-Repo"), nil)
local empty = repo_userset("empty-repo")
h.check("a protected repository with no members denies as an empty set",
empty ~= nil and next(empty) == nil)
if variant == "file" then
h.redirect_file("/etc/cgit-auth/users", "auth-users-missing")
- h.equals("a missing users file turns every login down",
- account_hash("alice"), nil)
+ h.equals("a missing users file turns every login down", account_hash("alice"), nil)
h.redirect_file("/etc/cgit-auth/users", "auth-users")
end
@@ -106,13 +104,10 @@ h.equals("a value is decoded", params.x, "A")
h.equals("a cookie is found among others",
get_cookie("foo=1; cgitauth=abc; bar=2", "cgitauth"), "abc")
-h.equals("a lone cookie is found", get_cookie("cgitauth=abc", "cgitauth"),
- "abc")
+h.equals("a lone cookie is found", get_cookie("cgitauth=abc", "cgitauth"), "abc")
h.equals("no header yields no cookie", get_cookie(nil, "cgitauth"), nil)
-h.equals("a longer name does not match",
- get_cookie("xcgitauth=z", "cgitauth"), nil)
-h.equals("a magic character in the name is taken literally",
- get_cookie("a-b=z", "a-b"), "z")
+h.equals("a longer name does not match", get_cookie("xcgitauth=z", "cgitauth"), nil)
+h.equals("a magic character in the name is taken literally", get_cookie("a-b=z", "a-b"), "z")
h.check("equal strings compare equal", constant_equals("abc", "abc"))
h.check("differing strings do not", not constant_equals("abc", "abd"))
@@ -124,53 +119,42 @@ h.check("a scheme relative target is not", not is_safe_redirect("//evil"))
h.check("a backslash variant is not", not is_safe_redirect("/\\evil"))
h.check("a missing target is not", not is_safe_redirect(nil))
-h.equals("control characters are stripped from header values",
- strip_controls("a\r\nb"), "ab")
+h.equals("control characters are stripped from header values", strip_controls("a\r\nb"), "ab")
-- Signing and verification.
local now = os.time()
local cookie = secure_value("username", "alice", now + 3600)
-h.equals("a signed value verifies and comes back",
- validate_value("username", cookie), "alice")
+h.equals("a signed value verifies and comes back", validate_value("username", cookie), "alice")
cookie = secure_value("username", "a|b", now + 3600)
-h.equals("a value holding the separator survives the round trip",
- validate_value("username", cookie), "a|b")
+h.equals("a value holding the separator survives the round trip", validate_value("username", cookie), "a|b")
cookie = secure_value("username", "a\nb", now + 3600)
h.equals("a signed control character is still rejected on the way out",
validate_value("username", cookie), nil)
cookie = secure_value("redirect", "/repo/?a=b", 0)
-h.equals("an expiration of zero never expires",
- validate_value("redirect", cookie), "/repo/?a=b")
+h.equals("an expiration of zero never expires", validate_value("redirect", cookie), "/repo/?a=b")
cookie = secure_value("username", "alice", now - 10)
-h.equals("an expired value is rejected",
- validate_value("username", cookie), nil)
+h.equals("an expired value is rejected", validate_value("username", cookie), nil)
cookie = secure_value("username", "alice", now + 3600)
-local flipped = cookie:sub(1, -2) ..
- (cookie:sub(-1) == "0" and "1" or "0")
-h.equals("a tampered signature is rejected",
- validate_value("username", flipped), nil)
+local flipped = cookie:sub(1, -2) .. (cookie:sub(-1) == "0" and "1" or "0")
+h.equals("a tampered signature is rejected", validate_value("username", flipped), nil)
-h.equals("a value signed for one field does not serve another",
- validate_value("redirect", cookie), nil)
+h.equals("a value signed for one field does not serve another", validate_value("redirect", cookie), nil)
h.equals("no cookie does not verify", validate_value("username", nil), nil)
-h.equals("a tiny cookie does not verify", validate_value("username", "ab"),
- nil)
-h.equals("a leading separator does not verify",
- validate_value("username", "|x|1|s|sig"), nil)
+h.equals("a tiny cookie does not verify", validate_value("username", "ab"), nil)
+h.equals("a leading separator does not verify", validate_value("username", "|x|1|s|sig"), nil)
h.equals("an unsigned cookie does not verify",
validate_value("username", "username|alice|123|salt"), nil)
h.equals("an exponent spelling of the expiry does not verify",
validate_value("username", "username|alice|1e9|salt|beef"), nil)
-h.equals("an empty value signs to nothing", secure_value("username", "", 1),
- "")
+h.equals("an empty value signs to nothing", secure_value("username", "", 1), "")
-- The headers the filter writes itself.
@@ -220,34 +204,27 @@ out, ret = run_action("authenticate-cookie", { repo = "secret-repo" })
h.equals("a protected repository turns a bare request away", ret, 0)
local session = secure_value("username", "Alice", now + 3600)
-out, ret = run_action("authenticate-cookie",
- { repo = "secret-repo", cookie = "cgitauth=" .. session })
+out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. session })
h.equals("a signed session for a member is let through", ret, 1)
-out, ret = run_action("authenticate-cookie",
- { repo = "empty-repo", cookie = "cgitauth=" .. session })
+out, ret = run_action("authenticate-cookie", { repo = "empty-repo", cookie = "cgitauth=" .. session })
h.equals("a memberless repository denies even a valid session", ret, 0)
local outsider = secure_value("username", "carol", now + 3600)
-out, ret = run_action("authenticate-cookie",
- { repo = "secret-repo", cookie = "cgitauth=" .. outsider })
+out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. outsider })
h.equals("a signed session for an outsider is turned away", ret, 0)
-local forged = session:sub(1, -2) ..
- (session:sub(-1) == "0" and "1" or "0")
-out, ret = run_action("authenticate-cookie",
- { repo = "secret-repo", cookie = "cgitauth=" .. forged })
+local forged = session:sub(1, -2) .. (session:sub(-1) == "0" and "1" or "0")
+out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. forged })
h.equals("a forged session is turned away", ret, 0)
out, ret = run_action("no-such-action", {})
h.equals("an unknown action denies rather than raising", ret, 0)
out, ret = run_action("body", { url = "/repo/log/?q=x" })
-h.contains("the login form posts to the login url", out,
- "<form method='post' action='/?p=login'>")
+h.contains("the login form posts to the login url", out, "<form method='post' action='/?p=login'>")
local token = out:match("name='redirect' value='([^']*)'")
-h.equals("the form carries a signed way back",
- token and validate_value("redirect", token), "/repo/log/?q=x")
+h.equals("the form carries a signed way back", token and validate_value("redirect", token), "/repo/log/?q=x")
out, ret = run_action("body", { url = "//evil.example/x" })
token = out:match("name='redirect' value='([^']*)'")
@@ -258,45 +235,37 @@ local way_back = secure_value("redirect", "/repo/", 0)
out, ret = run_action("authenticate-post", {
method = "POST",
- body = "username=Alice&password=" .. url_encode(password) ..
- "&redirect=" .. url_encode(way_back),
+ body = "username=Alice&password=" .. url_encode(password) .. "&redirect=" .. url_encode(way_back),
})
h.contains("a good login redirects back", out, "Status: 302")
h.contains("to where the form said", out, "Location: /repo/\n")
local granted = out:match("Set%-Cookie: cgitauth=([^;]*);")
-h.equals("and grants a session that verifies",
- granted and validate_value("username", granted), "Alice")
+h.equals("and grants a session that verifies", granted and validate_value("username", granted), "Alice")
out, ret = run_action("authenticate-post", {
method = "POST",
- body = "username=Alice&password=wrong&redirect=" ..
- url_encode(way_back),
+ body = "username=Alice&password=wrong&redirect=" .. url_encode(way_back),
})
h.contains("a bad password redirects the same way", out, "Status: 302")
-h.contains("but clears the session cookie", out,
- "Set-Cookie: cgitauth=; ")
+h.contains("but clears the session cookie", out, "Set-Cookie: cgitauth=; ")
out, ret = run_action("authenticate-post", {
method = "POST",
body = "username=nobody&password=x&redirect=" .. url_encode(way_back),
})
-h.contains("an unknown user is told nothing different", out,
- "Set-Cookie: cgitauth=; ")
+h.contains("an unknown user is told nothing different", out, "Set-Cookie: cgitauth=; ")
out, ret = run_action("authenticate-post", {
method = "POST",
body = "username=Alice&password=" .. url_encode(password),
})
-h.contains("a post without the signed token is not served", out,
- "Status: 404")
+h.contains("a post without the signed token is not served", out, "Status: 404")
local hijack = secure_value("redirect", "//evil.example/", 0)
out, ret = run_action("authenticate-post", {
method = "POST",
- body = "username=Alice&password=" .. url_encode(password) ..
- "&redirect=" .. url_encode(hijack),
+ body = "username=Alice&password=" .. url_encode(password) .. "&redirect=" .. url_encode(hijack),
})
-h.contains("even a signed unsafe destination is not followed", out,
- "Status: 404")
+h.contains("even a signed unsafe destination is not followed", out, "Status: 404")
h.finish()