e2e/disabled_test.go
51 lines · 1861 bytes
1package e2e
2
3import (
4 "encoding/json"
5 "testing"
6)
7
8// Disabling an account ends every way in, not just SSH. The API used to
9// keep answering a disabled account's bearer token, because only the SSH
10// listener checked the flag and disabling deleted sessions but not tokens
11// (#95).
12func TestDisabledAccountAPI(t *testing.T) {
13 inst := startInstanceWith(t, "[api]\nenabled = true\n")
14 aliceKey := inst.newKey(t, "alice")
15 inst.admin(t, "admin", "user", "create", "alice",
16 "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
17
18 out, errOut, code := inst.ssh(t, aliceKey, "", "token", "create", "--name", "ci", "--json")
19 if code != 0 {
20 t.Fatalf("token create: %s", errOut)
21 }
22 var env struct {
23 Data struct {
24 Token string `json:"token"`
25 } `json:"data"`
26 }
27 if err := json.Unmarshal([]byte(out), &env); err != nil {
28 t.Fatalf("token create output: %v %s", err, out)
29 }
30 token := env.Data.Token
31 if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 200 {
32 t.Fatalf("token before disable: %d", status)
33 }
34
35 inst.admin(t, "admin", "user", "disable", "alice")
36 if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 {
37 t.Fatalf("disabled account's token still answers: %d, want 401", status)
38 }
39 if status, _ := inst.apiCall(t, token, []string{"repo", "create", "alice/late"}, ""); status != 401 {
40 t.Fatalf("disabled account's token still writes: %d, want 401", status)
41 }
42
43 // Re-enabling restores the account, not the token: it was revoked.
44 inst.admin(t, "admin", "user", "enable", "alice")
45 if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 {
46 t.Fatalf("revoked token answers after enable: %d, want 401", status)
47 }
48 if _, _, code := inst.ssh(t, aliceKey, "", "whoami"); code != 0 {
49 t.Fatalf("re-enabled account refused over ssh: exit %d", code)
50 }
51}