diff options
Diffstat (limited to 'tests/extensions/test-auth.lua')
| -rw-r--r-- | tests/extensions/test-auth.lua | 93 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 31 insertions, 62 deletions
diff --git a/tests/extensions/test-auth.lua b/tests/extensions/test-auth.lua index 359f52e..e9fed78 100644 --- a/tests/extensions/test-auth.lua +++ b/tests/extensions/test-auth.lua @@ -79,16 +79,14 @@ local userset = repo_userset("secret-repo") h.check("a protected repository lists its users", userset ~= nil and userset.alice and userset.bob) h.equals("an unlisted repository is public", repo_userset("unlisted"), nil) -h.equals("the repository name matches case exactly", - repo_userset("Secret-Repo"), nil) +h.equals("the repository name matches case exactly", repo_userset("Secret-Repo"), nil) local empty = repo_userset("empty-repo") h.check("a protected repository with no members denies as an empty set", empty ~= nil and next(empty) == nil) if variant == "file" then h.redirect_file("/etc/cgit-auth/users", "auth-users-missing") - h.equals("a missing users file turns every login down", - account_hash("alice"), nil) + h.equals("a missing users file turns every login down", account_hash("alice"), nil) h.redirect_file("/etc/cgit-auth/users", "auth-users") end @@ -106,13 +104,10 @@ h.equals("a value is decoded", params.x, "A") h.equals("a cookie is found among others", get_cookie("foo=1; cgitauth=abc; bar=2", "cgitauth"), "abc") -h.equals("a lone cookie is found", get_cookie("cgitauth=abc", "cgitauth"), - "abc") +h.equals("a lone cookie is found", get_cookie("cgitauth=abc", "cgitauth"), "abc") h.equals("no header yields no cookie", get_cookie(nil, "cgitauth"), nil) -h.equals("a longer name does not match", - get_cookie("xcgitauth=z", "cgitauth"), nil) -h.equals("a magic character in the name is taken literally", - get_cookie("a-b=z", "a-b"), "z") +h.equals("a longer name does not match", get_cookie("xcgitauth=z", "cgitauth"), nil) +h.equals("a magic character in the name is taken literally", get_cookie("a-b=z", "a-b"), "z") h.check("equal strings compare equal", constant_equals("abc", "abc")) h.check("differing strings do not", not constant_equals("abc", "abd")) @@ -124,53 +119,42 @@ h.check("a scheme relative target is not", not is_safe_redirect("//evil")) h.check("a backslash variant is not", not is_safe_redirect("/\\evil")) h.check("a missing target is not", not is_safe_redirect(nil)) -h.equals("control characters are stripped from header values", - strip_controls("a\r\nb"), "ab") +h.equals("control characters are stripped from header values", strip_controls("a\r\nb"), "ab") -- Signing and verification. local now = os.time() local cookie = secure_value("username", "alice", now + 3600) -h.equals("a signed value verifies and comes back", - validate_value("username", cookie), "alice") +h.equals("a signed value verifies and comes back", validate_value("username", cookie), "alice") cookie = secure_value("username", "a|b", now + 3600) -h.equals("a value holding the separator survives the round trip", - validate_value("username", cookie), "a|b") +h.equals("a value holding the separator survives the round trip", validate_value("username", cookie), "a|b") cookie = secure_value("username", "a\nb", now + 3600) h.equals("a signed control character is still rejected on the way out", validate_value("username", cookie), nil) cookie = secure_value("redirect", "/repo/?a=b", 0) -h.equals("an expiration of zero never expires", - validate_value("redirect", cookie), "/repo/?a=b") +h.equals("an expiration of zero never expires", validate_value("redirect", cookie), "/repo/?a=b") cookie = secure_value("username", "alice", now - 10) -h.equals("an expired value is rejected", - validate_value("username", cookie), nil) +h.equals("an expired value is rejected", validate_value("username", cookie), nil) cookie = secure_value("username", "alice", now + 3600) -local flipped = cookie:sub(1, -2) .. - (cookie:sub(-1) == "0" and "1" or "0") -h.equals("a tampered signature is rejected", - validate_value("username", flipped), nil) +local flipped = cookie:sub(1, -2) .. (cookie:sub(-1) == "0" and "1" or "0") +h.equals("a tampered signature is rejected", validate_value("username", flipped), nil) -h.equals("a value signed for one field does not serve another", - validate_value("redirect", cookie), nil) +h.equals("a value signed for one field does not serve another", validate_value("redirect", cookie), nil) h.equals("no cookie does not verify", validate_value("username", nil), nil) -h.equals("a tiny cookie does not verify", validate_value("username", "ab"), - nil) -h.equals("a leading separator does not verify", - validate_value("username", "|x|1|s|sig"), nil) +h.equals("a tiny cookie does not verify", validate_value("username", "ab"), nil) +h.equals("a leading separator does not verify", validate_value("username", "|x|1|s|sig"), nil) h.equals("an unsigned cookie does not verify", validate_value("username", "username|alice|123|salt"), nil) h.equals("an exponent spelling of the expiry does not verify", validate_value("username", "username|alice|1e9|salt|beef"), nil) -h.equals("an empty value signs to nothing", secure_value("username", "", 1), - "") +h.equals("an empty value signs to nothing", secure_value("username", "", 1), "") -- The headers the filter writes itself. @@ -220,34 +204,27 @@ out, ret = run_action("authenticate-cookie", { repo = "secret-repo" }) h.equals("a protected repository turns a bare request away", ret, 0) local session = secure_value("username", "Alice", now + 3600) -out, ret = run_action("authenticate-cookie", - { repo = "secret-repo", cookie = "cgitauth=" .. session }) +out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. session }) h.equals("a signed session for a member is let through", ret, 1) -out, ret = run_action("authenticate-cookie", - { repo = "empty-repo", cookie = "cgitauth=" .. session }) +out, ret = run_action("authenticate-cookie", { repo = "empty-repo", cookie = "cgitauth=" .. session }) h.equals("a memberless repository denies even a valid session", ret, 0) local outsider = secure_value("username", "carol", now + 3600) -out, ret = run_action("authenticate-cookie", - { repo = "secret-repo", cookie = "cgitauth=" .. outsider }) +out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. outsider }) h.equals("a signed session for an outsider is turned away", ret, 0) -local forged = session:sub(1, -2) .. - (session:sub(-1) == "0" and "1" or "0") -out, ret = run_action("authenticate-cookie", - { repo = "secret-repo", cookie = "cgitauth=" .. forged }) +local forged = session:sub(1, -2) .. (session:sub(-1) == "0" and "1" or "0") +out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. forged }) h.equals("a forged session is turned away", ret, 0) out, ret = run_action("no-such-action", {}) h.equals("an unknown action denies rather than raising", ret, 0) out, ret = run_action("body", { url = "/repo/log/?q=x" }) -h.contains("the login form posts to the login url", out, - "<form method='post' action='/?p=login'>") +h.contains("the login form posts to the login url", out, "<form method='post' action='/?p=login'>") local token = out:match("name='redirect' value='([^']*)'") -h.equals("the form carries a signed way back", - token and validate_value("redirect", token), "/repo/log/?q=x") +h.equals("the form carries a signed way back", token and validate_value("redirect", token), "/repo/log/?q=x") out, ret = run_action("body", { url = "//evil.example/x" }) token = out:match("name='redirect' value='([^']*)'") @@ -258,45 +235,37 @@ local way_back = secure_value("redirect", "/repo/", 0) out, ret = run_action("authenticate-post", { method = "POST", - body = "username=Alice&password=" .. url_encode(password) .. - "&redirect=" .. url_encode(way_back), + body = "username=Alice&password=" .. url_encode(password) .. "&redirect=" .. url_encode(way_back), }) h.contains("a good login redirects back", out, "Status: 302") h.contains("to where the form said", out, "Location: /repo/\n") local granted = out:match("Set%-Cookie: cgitauth=([^;]*);") -h.equals("and grants a session that verifies", - granted and validate_value("username", granted), "Alice") +h.equals("and grants a session that verifies", granted and validate_value("username", granted), "Alice") out, ret = run_action("authenticate-post", { method = "POST", - body = "username=Alice&password=wrong&redirect=" .. - url_encode(way_back), + body = "username=Alice&password=wrong&redirect=" .. url_encode(way_back), }) h.contains("a bad password redirects the same way", out, "Status: 302") -h.contains("but clears the session cookie", out, - "Set-Cookie: cgitauth=; ") +h.contains("but clears the session cookie", out, "Set-Cookie: cgitauth=; ") out, ret = run_action("authenticate-post", { method = "POST", body = "username=nobody&password=x&redirect=" .. url_encode(way_back), }) -h.contains("an unknown user is told nothing different", out, - "Set-Cookie: cgitauth=; ") +h.contains("an unknown user is told nothing different", out, "Set-Cookie: cgitauth=; ") out, ret = run_action("authenticate-post", { method = "POST", body = "username=Alice&password=" .. url_encode(password), }) -h.contains("a post without the signed token is not served", out, - "Status: 404") +h.contains("a post without the signed token is not served", out, "Status: 404") local hijack = secure_value("redirect", "//evil.example/", 0) out, ret = run_action("authenticate-post", { method = "POST", - body = "username=Alice&password=" .. url_encode(password) .. - "&redirect=" .. url_encode(hijack), + body = "username=Alice&password=" .. url_encode(password) .. "&redirect=" .. url_encode(hijack), }) -h.contains("even a signed unsafe destination is not followed", out, - "Status: 404") +h.contains("even a signed unsafe destination is not followed", out, "Status: 404") h.finish() |
