Commit b5cc83bf50
Verified · cmc
Layout: unified · split
internal/httpd/lfsauth_test.go +45
| @@ -1,6 +1,7 @@ | ||
| 1 | 1 | package httpd |
| 2 | 2 | |
| 3 | 3 | import ( |
| 4 | "fmt" | |
| 4 | 5 | "net/http" |
| 5 | 6 | "net/http/httptest" |
| 6 | 7 | "testing" |
| @@ -177,3 +178,47 @@ func TestLFSTokenNeedsCurrentAccess(t *testing.T) { | ||
| 177 | 178 | t.Errorf("download after the repository went private: %q", op) |
| 178 | 179 | } |
| 179 | 180 | } |
| 181 | ||
| 182 | // A deploy key's token lasts as long as the deploy key: removed from the | |
| 183 | // repository or on a disabled account it is refused, and a read-only | |
| 184 | // binding never uploads. | |
| 185 | func TestLFSDeployKeyToken(t *testing.T) { | |
| 186 | s, st, u := newTokenTestServer(t) | |
| 187 | repo := lfsTestRepo(t, st, u.ID, "app", "private") | |
| 188 | secret, err := s.lfsSecret() | |
| 189 | if err != nil { | |
| 190 | t.Fatal(err) | |
| 191 | } | |
| 192 | now := time.Now() | |
| 193 | rw := fmt.Sprintf("deploy:%d:rw", repo.ID) | |
| 194 | ro := fmt.Sprintf("deploy:%d:ro", repo.ID) | |
| 195 | ||
| 196 | live := lfsTestKey(t, st, u.ID, "SHA256:deploy-live", rw) | |
| 197 | if op, key := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, live, "upload", now)), repo); op != "upload" || key != live { | |
| 198 | t.Fatalf("live deploy key: %q, %d", op, key) | |
| 199 | } | |
| 200 | ||
| 201 | removed := lfsTestKey(t, st, u.ID, "SHA256:deploy-removed", rw) | |
| 202 | tok := lfs.Sign(secret, repo.ID, removed, "download", now) | |
| 203 | if err := st.RemoveDeployKey(repo.ID, "SHA256:deploy-removed"); err != nil { | |
| 204 | t.Fatal(err) | |
| 205 | } | |
| 206 | if op, _ := s.lfsAuth(lfsRequest(tok), repo); op != "" { | |
| 207 | t.Errorf("removed deploy key: %q", op) | |
| 208 | } | |
| 209 | ||
| 210 | readOnly := lfsTestKey(t, st, u.ID, "SHA256:deploy-ro", ro) | |
| 211 | if op, _ := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, readOnly, "download", now)), repo); op != "download" { | |
| 212 | t.Errorf("read-only deploy key download: %q", op) | |
| 213 | } | |
| 214 | if op, _ := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, readOnly, "upload", now)), repo); op != "" { | |
| 215 | t.Errorf("read-only deploy key upload: %q", op) | |
| 216 | } | |
| 217 | ||
| 218 | if err := st.SetUserDisabled(u.ID, true); err != nil { | |
| 219 | t.Fatal(err) | |
| 220 | } | |
| 221 | if op, _ := s.lfsAuth(lfsRequest(lfs.Sign(secret, repo.ID, live, "download", now)), repo); op != "" { | |
| 222 | t.Errorf("deploy key of a disabled account: %q", op) | |
| 223 | } | |
| 224 | } | |