Commit b5cc83bf50
Verified · cmc
Layout: unified · split
internal/httpd/lfsauth_test.go +45
| @@ -1,6 +1,7 @@ | |||
| 1 | package httpd | 1 | package httpd |
| 2 | 2 | ||
| 3 | import ( | 3 | import ( |
| 4 | "fmt" | ||
| 4 | "net/http" | 5 | "net/http" |
| 5 | "net/http/httptest" | 6 | "net/http/httptest" |
| 6 | "testing" | 7 | "testing" |
| @@ -177,3 +178,47 @@ func TestLFSTokenNeedsCurrentAccess(t *testing.T) { | |||
| 177 | t.Errorf("download after the repository went private: %q", op) | 178 | t.Errorf("download after the repository went private: %q", op) |
| 178 | } | 179 | } |
| 179 | } | 180 | } |
| 181 | |||
| 182 | // A deploy key's token lasts as long as the deploy key: removed from the | ||
| 183 | // repository or on a disabled account it is refused, and a read-only | ||
| 184 | // binding never uploads. | ||
| 185 | func TestLFSDeployKeyToken(t *testing.T) { | ||
| 186 | s, st, u := newTokenTestServer(t) | ||
| 187 | repo := lfsTestRepo(t, st, u.ID, "app", "private") | ||
| 188 | secret, err := s.lfsSecret() | ||
| 189 | if err != nil { | ||
| 190 | t.Fatal(err) | ||
| 191 | } | ||
| 192 | now := time.Now() | ||
| 193 | rw := fmt.Sprintf("deploy:%d:rw", repo.ID) | ||
| 194 | ro := fmt.Sprintf("deploy:%d:ro", repo.ID) | ||
| 195 | |||
| 196 | live := lfsTestKey(t, st, u.ID, "SHA256:deploy-live", rw) | ||
| 197 | if op, key := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, live, "upload", now)), repo); op != "upload" || key != live { | ||
| 198 | t.Fatalf("live deploy key: %q, %d", op, key) | ||
| 199 | } | ||
| 200 | |||
| 201 | removed := lfsTestKey(t, st, u.ID, "SHA256:deploy-removed", rw) | ||
| 202 | tok := lfs.Sign(secret, repo.ID, removed, "download", now) | ||
| 203 | if err := st.RemoveDeployKey(repo.ID, "SHA256:deploy-removed"); err != nil { | ||
| 204 | t.Fatal(err) | ||
| 205 | } | ||
| 206 | if op, _ := s.lfsAuth(lfsRequest(tok), repo); op != "" { | ||
| 207 | t.Errorf("removed deploy key: %q", op) | ||
| 208 | } | ||
| 209 | |||
| 210 | readOnly := lfsTestKey(t, st, u.ID, "SHA256:deploy-ro", ro) | ||
| 211 | if op, _ := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, readOnly, "download", now)), repo); op != "download" { | ||
| 212 | t.Errorf("read-only deploy key download: %q", op) | ||
| 213 | } | ||
| 214 | if op, _ := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, readOnly, "upload", now)), repo); op != "" { | ||
| 215 | t.Errorf("read-only deploy key upload: %q", op) | ||
| 216 | } | ||
| 217 | |||
| 218 | if err := st.SetUserDisabled(u.ID, true); err != nil { | ||
| 219 | t.Fatal(err) | ||
| 220 | } | ||
| 221 | if op, _ := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, live, "download", now)), repo); op != "" { | ||
| 222 | t.Errorf("deploy key of a disabled account: %q", op) | ||
| 223 | } | ||
| 224 | } | ||