| @@ -0,0 +1,51 @@ |
| |
1 | package e2e |
| |
2 | |
| |
3 | import ( |
| |
4 | "encoding/json" |
| |
5 | "testing" |
| |
6 | ) |
| |
7 | |
| |
8 | // Disabling an account ends every way in, not just SSH. The API used to |
| |
9 | // keep answering a disabled account's bearer token, because only the SSH |
| |
10 | // listener checked the flag and disabling deleted sessions but not tokens |
| |
11 | // (#95). |
| |
12 | func TestDisabledAccountAPI(t *testing.T) { |
| |
13 | inst := startInstanceWith(t, "[api]\nenabled = true\n") |
| |
14 | aliceKey := inst.newKey(t, "alice") |
| |
15 | inst.admin(t, "admin", "user", "create", "alice", |
| |
16 | "--key", aliceKey+".pub", "--email", "alice@example.test", "--verified") |
| |
17 | |
| |
18 | out, errOut, code := inst.ssh(t, aliceKey, "", "token", "create", "--name", "ci", "--json") |
| |
19 | if code != 0 { |
| |
20 | t.Fatalf("token create: %s", errOut) |
| |
21 | } |
| |
22 | var env struct { |
| |
23 | Data struct { |
| |
24 | Token string `json:"token"` |
| |
25 | } `json:"data"` |
| |
26 | } |
| |
27 | if err := json.Unmarshal([]byte(out), &env); err != nil { |
| |
28 | t.Fatalf("token create output: %v %s", err, out) |
| |
29 | } |
| |
30 | token := env.Data.Token |
| |
31 | if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 200 { |
| |
32 | t.Fatalf("token before disable: %d", status) |
| |
33 | } |
| |
34 | |
| |
35 | inst.admin(t, "admin", "user", "disable", "alice") |
| |
36 | if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 { |
| |
37 | t.Fatalf("disabled account's token still answers: %d, want 401", status) |
| |
38 | } |
| |
39 | if status, _ := inst.apiCall(t, token, []string{"repo", "create", "alice/late"}, ""); status != 401 { |
| |
40 | t.Fatalf("disabled account's token still writes: %d, want 401", status) |
| |
41 | } |
| |
42 | |
| |
43 | // Re-enabling restores the account, not the token: it was revoked. |
| |
44 | inst.admin(t, "admin", "user", "enable", "alice") |
| |
45 | if status, _ := inst.apiCall(t, token, []string{"whoami"}, ""); status != 401 { |
| |
46 | t.Fatalf("revoked token answers after enable: %d, want 401", status) |
| |
47 | } |
| |
48 | if _, _, code := inst.ssh(t, aliceKey, "", "whoami"); code != 0 { |
| |
49 | t.Fatalf("re-enabled account refused over ssh: exit %d", code) |
| |
50 | } |
| |
51 | } |