| @@ -0,0 +1,51 @@ |
| 1 | package e2e |
| 2 | |
| 3 | import ( |
| 4 | "encoding/json" |
| 5 | "testing" |
| 6 | ) |
| 7 | |
| 8 | // Disabling an account ends every way in, not just SSH. The API used to |
| 9 | // keep answering a disabled account's bearer token, because only the SSH |
| 10 | // listener checked the flag and disabling deleted sessions but not tokens |
| 11 | // (#95). |
| 12 | func TestDisabledAccountAPI(t *testing.T) { |
| 13 | inst := startInstanceWith(t, "[api]\nenabled = true\n") |
| 14 | aliceKey := inst.newKey(t, "alice") |
| 15 | inst.admin(t, "admin", "user", "create", "alice", |
| 16 | "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified") |
| 17 | |
| 18 | out, errOut, code := inst.ssh(t, aliceKey, "", "token", "create", "--name", "ci", "--json") |
| 19 | if code != 0 { |
| 20 | t.Fatalf("token create: %s", errOut) |
| 21 | } |
| 22 | var env struct { |
| 23 | Data struct { |
| 24 | Token string `json:"token"` |
| 25 | } `json:"data"` |
| 26 | } |
| 27 | if err := json.Unmarshal([]byte(out), &env); err != nil { |
| 28 | t.Fatalf("token create output: %v %s", err, out) |
| 29 | } |
| 30 | token := env.Data.Token |
| 31 | if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 200 { |
| 32 | t.Fatalf("token before disable: %d", status) |
| 33 | } |
| 34 | |
| 35 | inst.admin(t, "admin", "user", "disable", "alice") |
| 36 | if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 { |
| 37 | t.Fatalf("disabled account's token still answers: %d, want 401", status) |
| 38 | } |
| 39 | if status, _ := inst.apiCall(t, token, []string{"repo", "create", "alice/late"}, ""); status != 401 { |
| 40 | t.Fatalf("disabled account's token still writes: %d, want 401", status) |
| 41 | } |
| 42 | |
| 43 | // Re-enabling restores the account, not the token: it was revoked. |
| 44 | inst.admin(t, "admin", "user", "enable", "alice") |
| 45 | if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 { |
| 46 | t.Fatalf("revoked token answers after enable: %d, want 401", status) |
| 47 | } |
| 48 | if _, _, code := inst.ssh(t, aliceKey, "", "whoami"); code != 0 { |
| 49 | t.Fatalf("re-enabled account refused over ssh: exit %d", code) |
| 50 | } |
| 51 | } |