e2e/disabled_test.go
52 lines · 1875 bytes
1 symbol in this file
1package e2e
2
3import (
4 "encoding/json"
5 "testing"
6)
7
8// Disabling an account ends every way in, not just SSH. The API used to
9// keep answering a disabled account's bearer token, because only the SSH
10// listener checked the flag and disabling deleted sessions but not tokens
11// (#95).
12func TestDisabledAccountAPI(t *testing.T) {
13 t.Parallel()
14 inst := startInstanceWith(t, "[api]\nenabled = true\n")
15 aliceKey := inst.newKey(t, "alice")
16 inst.admin(t, "admin", "user", "create", "alice",
17 "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified")
18
19 out, errOut, code := inst.ssh(t, aliceKey, "", "token", "create", "--name", "ci", "--json")
20 if code != 0 {
21 t.Fatalf("token create: %s", errOut)
22 }
23 var env struct {
24 Data struct {
25 Token string `json:"token"`
26 } `json:"data"`
27 }
28 if err := json.Unmarshal([]byte(out), &env); err != nil {
29 t.Fatalf("token create output: %v %s", err, out)
30 }
31 token := env.Data.Token
32 if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 200 {
33 t.Fatalf("token before disable: %d", status)
34 }
35
36 inst.admin(t, "admin", "user", "disable", "alice")
37 if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 {
38 t.Fatalf("disabled account's token still answers: %d, want 401", status)
39 }
40 if status, _ := inst.apiCall(t, token, []string{"repo", "create", "alice/late"}, ""); status != 401 {
41 t.Fatalf("disabled account's token still writes: %d, want 401", status)
42 }
43
44 // Re-enabling restores the account, not the token: it was revoked.
45 inst.admin(t, "admin", "user", "enable", "alice")
46 if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 {
47 t.Fatalf("revoked token answers after enable: %d, want 401", status)
48 }
49 if _, _, code := inst.ssh(t, aliceKey, "", "whoami"); code != 0 {
50 t.Fatalf("re-enabled account refused over ssh: exit %d", code)
51 }
52}