-- Unit checks for the two auth filters, run under a standalone Lua by -- t0505-auth.sh with the script path as the first argument and the variant, -- inline or file, as the second. The scripts take luaossl and luaposix at -- load, so the harness meets both with deterministic stand-ins, which keeps -- every check about this script's own logic, the cookie layout, the expiry -- and field rules, the redirect vetting and the action flows, rather than -- about OpenSSL. The signing secret is pinned by replacing get_secret, and -- the account and access lookups are populated through each variant's own -- channel, the documented account_hash and repo_userset swap points for the -- inline script and fixture files reached through a redirected io.open for -- the file one. Both variants carry the same data so the flow checks read -- identically for the two. local test_directory = arg[0]:match("^(.*)/") or "." local h = dofile(test_directory .. "/harness.lua") local script = arg[1] local variant = arg[2] h.stub_auth_modules() -- The password behind every test account, stored as what the harness crypt -- stand-in returns for it so a login with it verifies and any other fails. local password = "open sesame" local stored_hash = "$6$rounds=300000$testsalt$" .. password if variant == "file" then local users_file = io.open("auth-users", "w") users_file:write("Alice:" .. stored_hash .. "\r\n") users_file:write("not a parsable line\n") users_file:close() local groups_file = io.open("auth-groups", "w") groups_file:write("devs:Alice, bob\n") groups_file:write("others:carol\n") groups_file:close() local repos_file = io.open("auth-repos", "w") repos_file:write("secret-repo:devs\n") repos_file:write("empty-repo:ghosts\n") repos_file:close() h.redirect_file("/etc/cgit-auth/users", "auth-users") h.redirect_file("/etc/cgit-auth/groups", "auth-groups") h.redirect_file("/etc/cgit-auth/repos", "auth-repos") end h.load(script) function get_secret() return string.rep("0123456789abcdef", 4) end if variant == "inline" then local accounts = { alice = stored_hash } local access = { ["secret-repo"] = { alice = true, bob = true }, ["empty-repo"] = {}, } function account_hash(user) if user == nil then return nil end return accounts[user:lower()] end function repo_userset(repo) if repo == nil then return nil end return access[repo] end end -- The lookups themselves, which are the part the two variants do not share. local hash = account_hash("ALICE") h.equals("an account is found whatever its case", hash, stored_hash) h.equals("an unknown account is not", account_hash("nobody"), nil) h.equals("a nil user is not", account_hash(nil), nil) local userset = repo_userset("secret-repo") h.check("a protected repository lists its users", userset ~= nil and userset.alice and userset.bob) h.equals("an unlisted repository is public", repo_userset("unlisted"), nil) h.equals("the repository name matches case exactly", repo_userset("Secret-Repo"), nil) local empty = repo_userset("empty-repo") h.check("a protected repository with no members denies as an empty set", empty ~= nil and next(empty) == nil) if variant == "file" then h.redirect_file("/etc/cgit-auth/users", "auth-users-missing") h.equals("a missing users file turns every login down", account_hash("alice"), nil) h.redirect_file("/etc/cgit-auth/users", "auth-users") end -- The url and cookie helpers. h.equals("decode handles escapes and plus", url_decode("%41+b"), "A b") h.equals("encode escapes what is not a word", url_encode("a b|c"), "a+b%7Cc") local tricky = "x&=?|" h.equals("decode inverts encode", url_decode(url_encode(tricky)), tricky) local params = parse_query("u=a&p=b=c&x=%41") h.equals("a query splits on ampersands", params.u, "a") h.equals("a value keeps its own equals signs", params.p, "b=c") h.equals("a value is decoded", params.x, "A") h.equals("a cookie is found among others", get_cookie("foo=1; cgitauth=abc; bar=2", "cgitauth"), "abc") h.equals("a lone cookie is found", get_cookie("cgitauth=abc", "cgitauth"), "abc") h.equals("no header yields no cookie", get_cookie(nil, "cgitauth"), nil) h.equals("a longer name does not match", get_cookie("xcgitauth=z", "cgitauth"), nil) h.equals("a magic character in the name is taken literally", get_cookie("a-b=z", "a-b"), "z") h.check("equal strings compare equal", constant_equals("abc", "abc")) h.check("differing strings do not", not constant_equals("abc", "abd")) h.check("differing lengths do not", not constant_equals("a", "ab")) h.check("non strings do not", not constant_equals(nil, "a")) h.check("a local path is a safe redirect", is_safe_redirect("/x")) h.check("a scheme relative target is not", not is_safe_redirect("//evil")) h.check("a backslash variant is not", not is_safe_redirect("/\\evil")) h.check("a missing target is not", not is_safe_redirect(nil)) h.equals("control characters are stripped from header values", strip_controls("a\r\nb"), "ab") -- Signing and verification. local now = os.time() local cookie = secure_value("username", "alice", now + 3600) h.equals("a signed value verifies and comes back", validate_value("username", cookie), "alice") cookie = secure_value("username", "a|b", now + 3600) h.equals("a value holding the separator survives the round trip", validate_value("username", cookie), "a|b") cookie = secure_value("username", "a\nb", now + 3600) h.equals("a signed control character is still rejected on the way out", validate_value("username", cookie), nil) cookie = secure_value("redirect", "/repo/?a=b", 0) h.equals("an expiration of zero never expires", validate_value("redirect", cookie), "/repo/?a=b") cookie = secure_value("username", "alice", now - 10) h.equals("an expired value is rejected", validate_value("username", cookie), nil) cookie = secure_value("username", "alice", now + 3600) local flipped = cookie:sub(1, -2) .. (cookie:sub(-1) == "0" and "1" or "0") h.equals("a tampered signature is rejected", validate_value("username", flipped), nil) h.equals("a value signed for one field does not serve another", validate_value("redirect", cookie), nil) h.equals("no cookie does not verify", validate_value("username", nil), nil) h.equals("a tiny cookie does not verify", validate_value("username", "ab"), nil) h.equals("a leading separator does not verify", validate_value("username", "|x|1|s|sig"), nil) h.equals("an unsigned cookie does not verify", validate_value("username", "username|alice|123|salt"), nil) h.equals("an exponent spelling of the expiry does not verify", validate_value("username", "username|alice|1e9|salt|beef"), nil) h.equals("an empty value signs to nothing", secure_value("username", "", 1), "") -- The headers the filter writes itself. h.reset() set_cookie("cgitauth", "value") local out = h.output() h.contains("a session cookie carries the hardening attributes", out, "Set-Cookie: cgitauth=value; HttpOnly; SameSite=Lax; Path=/; Secure; " .. "Max-Age=604800\n") h.reset() set_cookie("cgitauth", "") h.contains("an empty value clears the cookie instead", h.output(), "Set-Cookie: cgitauth=; HttpOnly; SameSite=Lax; Path=/; Secure; " .. "Max-Age=0\n") h.reset() redirect_to("/x\r\nX-Evil: 1") out = h.output() h.contains("a newline cannot split the location header", out, "Location: /xX-Evil: 1\n") h.excludes("no carriage return slips through", out, "\r") -- The three actions, driven the way cgit drives them, an open carrying the -- request, a write only for the posted form and the answer read off the -- close. local function run_action(action, opts) opts = opts or {} h.reset() filter_open(action, opts.cookie or "", opts.method or "GET", "", "", "/", "example.org", "on", opts.repo or "", "summary", opts.url or "/repo/", "/?p=login") if opts.body then filter_write(opts.body) end local ret = filter_close() return h.output(), ret end local ret out, ret = run_action("authenticate-cookie", { repo = "unlisted" }) h.equals("a public repository needs no cookie", ret, 1) out, ret = run_action("authenticate-cookie", { repo = "secret-repo" }) h.equals("a protected repository turns a bare request away", ret, 0) local session = secure_value("username", "Alice", now + 3600) out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. session }) h.equals("a signed session for a member is let through", ret, 1) out, ret = run_action("authenticate-cookie", { repo = "empty-repo", cookie = "cgitauth=" .. session }) h.equals("a memberless repository denies even a valid session", ret, 0) local outsider = secure_value("username", "carol", now + 3600) out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. outsider }) h.equals("a signed session for an outsider is turned away", ret, 0) local forged = session:sub(1, -2) .. (session:sub(-1) == "0" and "1" or "0") out, ret = run_action("authenticate-cookie", { repo = "secret-repo", cookie = "cgitauth=" .. forged }) h.equals("a forged session is turned away", ret, 0) out, ret = run_action("no-such-action", {}) h.equals("an unknown action denies rather than raising", ret, 0) out, ret = run_action("body", { url = "/repo/log/?q=x" }) h.contains("the login form posts to the login url", out, "
") local token = out:match("name='redirect' value='([^']*)'") h.equals("the form carries a signed way back", token and validate_value("redirect", token), "/repo/log/?q=x") out, ret = run_action("body", { url = "//evil.example/x" }) token = out:match("name='redirect' value='([^']*)'") h.equals("an unsafe destination is swapped for the login page", token and validate_value("redirect", token), "/?p=login") local way_back = secure_value("redirect", "/repo/", 0) out, ret = run_action("authenticate-post", { method = "POST", body = "username=Alice&password=" .. url_encode(password) .. "&redirect=" .. url_encode(way_back), }) h.contains("a good login redirects back", out, "Status: 302") h.contains("to where the form said", out, "Location: /repo/\n") local granted = out:match("Set%-Cookie: cgitauth=([^;]*);") h.equals("and grants a session that verifies", granted and validate_value("username", granted), "Alice") out, ret = run_action("authenticate-post", { method = "POST", body = "username=Alice&password=wrong&redirect=" .. url_encode(way_back), }) h.contains("a bad password redirects the same way", out, "Status: 302") h.contains("but clears the session cookie", out, "Set-Cookie: cgitauth=; ") out, ret = run_action("authenticate-post", { method = "POST", body = "username=nobody&password=x&redirect=" .. url_encode(way_back), }) h.contains("an unknown user is told nothing different", out, "Set-Cookie: cgitauth=; ") out, ret = run_action("authenticate-post", { method = "POST", body = "username=Alice&password=" .. url_encode(password), }) h.contains("a post without the signed token is not served", out, "Status: 404") local hijack = secure_value("redirect", "//evil.example/", 0) out, ret = run_action("authenticate-post", { method = "POST", body = "username=Alice&password=" .. url_encode(password) .. "&redirect=" .. url_encode(hijack), }) h.contains("even a signed unsafe destination is not followed", out, "Status: 404") h.finish()