e2e/emailthrottle_test.go
29 lines · 971 bytes
1 symbol in this file
1package e2e
2
3import (
4 "fmt"
5 "strings"
6 "testing"
7)
8
9// email add mails a verification code. SSH auth and registration are
10// rate-limited; this path was not, so an authenticated account could
11// enqueue mail without bound (#136).
12func TestEmailAddThrottled(t *testing.T) {
13 t.Parallel()
14 smtp := startFakeSMTP(t)
15 inst := startInstanceWith(t, fmt.Sprintf(
16 "[mail]\nsmtp_host = %q\nfrom = \"noreply@gitbay.test\"\n", smtp.addr))
17 aliceKey := inst.newKey(t, "alice")
18 inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
19
20 for i := 0; i < 5; i++ {
21 if _, errOut, code := inst.ssh(t, aliceKey, "", "email", "add", fmt.Sprintf("alice%d@example.test", i)); code != 0 {
22 t.Fatalf("email add %d: exit %d %s", i, code, errOut)
23 }
24 }
25 _, errOut, code := inst.ssh(t, aliceKey, "", "email", "add", "alice5@example.test")
26 if code != 4 || !strings.Contains(errOut, "last hour") {
27 t.Fatalf("sixth email add in an hour: exit %d %s", code, errOut)
28 }
29}