e2e/emailthrottle_test.go
28 lines · 957 bytes
1package e2e
2
3import (
4 "fmt"
5 "strings"
6 "testing"
7)
8
9// email add mails a verification code. SSH auth and registration are
10// rate-limited; this path was not, so an authenticated account could
11// enqueue mail without bound (#136).
12func TestEmailAddThrottled(t *testing.T) {
13 smtp := startFakeSMTP(t)
14 inst := startInstanceWith(t, fmt.Sprintf(
15 "[mail]\nsmtp_host = %q\nfrom = \"noreply@gitbay.test\"\n", smtp.addr))
16 aliceKey := inst.newKey(t, "alice")
17 inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
18
19 for i := 0; i < 5; i++ {
20 if _, errOut, code := inst.ssh(t, aliceKey, "", "email", "add", fmt.Sprintf("alice%d@example.test", i)); code != 0 {
21 t.Fatalf("email add %d: exit %d %s", i, code, errOut)
22 }
23 }
24 _, errOut, code := inst.ssh(t, aliceKey, "", "email", "add", "alice5@example.test")
25 if code != 4 || !strings.Contains(errOut, "last hour") {
26 t.Fatalf("sixth email add in an hour: exit %d %s", code, errOut)
27 }
28}