From 67d438aab5f39a496da2d86c1b2075c01983b44c Mon Sep 17 00:00:00 2001 From: Samir Patel <48686912+54mir@users.noreply.github.com> Date: Mon, 20 Dec 2021 01:29:11 -0600 Subject: [PATCH] clean up --- http/handler.go | 6 --- http/handler_internal_test.go | 87 ++++++++++++++++++++++++++++++++++- server/config.go | 2 +- 3 files changed, 87 insertions(+), 8 deletions(-) diff --git a/http/handler.go b/http/handler.go index ada6a0f48..654f37e75 100644 --- a/http/handler.go +++ b/http/handler.go @@ -3372,14 +3372,8 @@ func (h *Handler) handleLogin(w http.ResponseWriter, r *http.Request) { http.Error(w, "Trying to login but authentication is off.", http.StatusBadRequest) return } - h.logger.Infof("Handle Login Begin") - h.logger.Infof("Handler: %+v", h) - tst := h.auth - _ = tst - h.logger.Infof("Accessing Auth") h.auth.Login(w, r) - h.logger.Infof("Handle Login End") } func (h *Handler) handleRedirect(w http.ResponseWriter, r *http.Request) { diff --git a/http/handler_internal_test.go b/http/handler_internal_test.go index ddcd2d102..f0db77695 100644 --- a/http/handler_internal_test.go +++ b/http/handler_internal_test.go @@ -3,18 +3,24 @@ package http import ( "bytes" + "encoding/hex" "encoding/json" + "fmt" + "io/ioutil" gohttp "net/http" "net/http/httptest" "os" "reflect" "strings" "testing" + "time" + "github.com/gorilla/securecookie" pilosa "github.com/molecula/featurebase/v2" "github.com/molecula/featurebase/v2/authn" "github.com/molecula/featurebase/v2/logger" "github.com/molecula/featurebase/v2/pql" + "golang.org/x/oauth2" ) // Test custom UnmarshalJSON for postIndexRequest object @@ -173,6 +179,9 @@ func TestFieldOptionValidation(t *testing.T) { } func TestAuth(t *testing.T) { + hashKey, _ := hex.DecodeString("DEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEF") + blockKey, _ := hex.DecodeString("DEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEF") + a, err := authn.NewAuth( logger.NewStandardLogger(os.Stdout), "http://localhost:10101/", @@ -185,6 +194,7 @@ func TestAuth(t *testing.T) { "DEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEF", "DEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEFDEADBEEF", ) + if err != nil { t.Errorf("building auth object %s", err) } @@ -193,12 +203,78 @@ func TestAuth(t *testing.T) { auth: a, } - t.Run("Login", func(t *testing.T) { + validToken := oauth2.Token{ + TokenType: "Bearer", + RefreshToken: "abcdef", + Expiry: time.Now().Add(time.Hour), + } + + // emptyToken := oauth2.Token{} + + grp := authn.Group{ + UserID: "snowstorm", + GroupID: "abcd123-A", + GroupName: "Romantic Painters", + } + + validCV := authn.CookieValue{ + UserID: "snowstorm", + UserName: "J.M.W. Turner", + GroupMembership: []authn.Group{grp}, + Token: &validToken, + } + + secure := securecookie.New(hashKey, blockKey) + validEncodedCV, _ := secure.Encode("molecula-chip", validCV) + validCookie := &gohttp.Cookie{ + Name: "molecula-chip", + Value: validEncodedCV, + Path: "/", + Secure: true, + HttpOnly: true, + Expires: validToken.Expiry, + } + + t.Run("Login-Cookie", func(t *testing.T) { r := httptest.NewRequest(gohttp.MethodGet, "/login", nil) w := httptest.NewRecorder() h.handleLogin(w, r) + }) + t.Run("Login-NoCookie", func(t *testing.T) { + r := httptest.NewRequest(gohttp.MethodGet, "/login", nil) + w := httptest.NewRecorder() + r.AddCookie(validCookie) + + //login w/o cookie + h.handleLogin(w, r) + res := w.Result() + defer res.Body.Close() + data, err := ioutil.ReadAll(res.Body) + if err != nil { + t.Errorf("expected no errors reading response, got: %+v", err) + } + fmt.Printf("%s", data) + + //login with cookie + + }) + t.Run("Login-BadCookie", func(t *testing.T) { + r := httptest.NewRequest(gohttp.MethodGet, "/login", nil) + w := httptest.NewRecorder() + // cookie, err := secure.Encode("molecula-chip", validCV) + if err != nil { + t.Error("encoding cookie") + } + + // r.AddCookie(cookie) + + //login w/o cookie + h.handleLogin(w, r) + + //login with cookie + }) t.Run("Logout", func(t *testing.T) { @@ -207,6 +283,9 @@ func TestAuth(t *testing.T) { h.handleLogout(w, r) + //logout with cookie + //logout without cookie + }) t.Run("Authenticate", func(t *testing.T) { @@ -215,6 +294,9 @@ func TestAuth(t *testing.T) { h.handleCheckAuthentication(w, r) + //auth with cookie + //auth w/o cookie + }) t.Run("GetUserInfo", func(t *testing.T) { @@ -223,6 +305,9 @@ func TestAuth(t *testing.T) { h.handleUserInfo(w, r) + //user info with cookie + //user info w/o cookie + }) } diff --git a/server/config.go b/server/config.go index 01492f248..18be85caa 100644 --- a/server/config.go +++ b/server/config.go @@ -632,7 +632,7 @@ func (c *Config) ValidateAuth() ([]error, error) { } if name == "HashKey" || name == "BlockKey" { - if len(value) != 32 { + if len(value) != 64 { errors = append(errors, fmt.Errorf("invalid key length for %s", name)) } }