2015-01-24 02:25:12 +02:00
|
|
|
package lock
|
|
|
|
|
2015-01-25 08:19:22 +02:00
|
|
|
import (
|
|
|
|
"testing"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"gopkg.in/authboss.v0"
|
|
|
|
"gopkg.in/authboss.v0/internal/mocks"
|
|
|
|
)
|
2015-01-24 02:25:12 +02:00
|
|
|
|
|
|
|
func TestStorage(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-24 02:25:12 +02:00
|
|
|
storage := L.Storage()
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := storage[StoreAttemptNumber]; !ok {
|
2015-01-24 02:25:12 +02:00
|
|
|
t.Error("Expected attempt number storage option.")
|
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := storage[StoreAttemptTime]; !ok {
|
2015-01-24 02:25:12 +02:00
|
|
|
t.Error("Expected attempt number time option.")
|
|
|
|
}
|
|
|
|
}
|
2015-01-25 08:19:22 +02:00
|
|
|
|
|
|
|
func TestBeforeAuth(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-25 08:19:22 +02:00
|
|
|
ctx := authboss.NewContext()
|
|
|
|
|
2015-02-16 21:32:31 +02:00
|
|
|
if err := L.BeforeAuth(ctx); err == nil {
|
|
|
|
t.Error("Want death because user not loaded:", err)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
ctx.User = authboss.Attributes{"locked": true}
|
|
|
|
|
|
|
|
if err := L.BeforeAuth(ctx); err != ErrLocked {
|
|
|
|
t.Error("Expected an ErrLocked:", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAfterAuth(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-25 08:19:22 +02:00
|
|
|
lock := Lock{}
|
|
|
|
ctx := authboss.NewContext()
|
|
|
|
|
|
|
|
lock.AfterAuth(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := ctx.User[StoreAttemptNumber]; ok {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("Expected nothing to be set, missing user.")
|
|
|
|
}
|
|
|
|
|
|
|
|
ctx.User = map[string]interface{}{"otherattribute": "somevalue"}
|
|
|
|
lock.AfterAuth(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := ctx.User[StoreAttemptNumber]; ok {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("Expected username not present to stop this assignment.")
|
|
|
|
}
|
|
|
|
|
|
|
|
ctx.User["username"] = 5
|
|
|
|
lock.AfterAuth(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := ctx.User[StoreAttemptNumber]; ok {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("Expected username wrong type stop this assignment.")
|
|
|
|
}
|
|
|
|
|
|
|
|
storer := mocks.NewMockStorer()
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.Cfg.Storer = storer
|
2015-01-25 08:19:22 +02:00
|
|
|
ctx.User["username"] = "username"
|
|
|
|
lock.AfterAuth(ctx)
|
|
|
|
|
2015-02-16 23:31:26 +02:00
|
|
|
if storer.Users["username"][StoreAttemptNumber].(int) != 0 {
|
|
|
|
t.Error("StoreAttemptNumber set incorrectly.")
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := storer.Users["username"][StoreAttemptTime].(time.Time); !ok {
|
|
|
|
t.Error("StoreAttemptTime not set.")
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAfterAuthFail_Lock(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-25 08:19:22 +02:00
|
|
|
var old, current time.Time
|
|
|
|
var ok bool
|
|
|
|
|
|
|
|
ctx := authboss.NewContext()
|
|
|
|
storer := mocks.NewMockStorer()
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.Cfg.Storer = storer
|
2015-01-25 08:19:22 +02:00
|
|
|
lock := Lock{}
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.Cfg.LockWindow = 30 * time.Minute
|
|
|
|
authboss.Cfg.LockAfter = 3
|
2015-01-25 08:19:22 +02:00
|
|
|
|
|
|
|
ctx.User = map[string]interface{}{"username": "username"}
|
|
|
|
|
|
|
|
old = time.Now().UTC().Add(-1 * time.Hour)
|
|
|
|
|
|
|
|
for i := 0; i < 3; i++ {
|
2015-02-16 23:31:26 +02:00
|
|
|
if lockedIntf, ok := storer.Users["username"][StoreLocked]; ok && lockedIntf.(bool) {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Errorf("%d: User should not be locked.", i)
|
|
|
|
}
|
|
|
|
|
|
|
|
lock.AfterAuthFail(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if val := storer.Users["username"][StoreAttemptNumber].(int); val != i+1 {
|
|
|
|
t.Errorf("%d: StoreAttemptNumber set incorrectly: %v", i, val)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if current, ok = storer.Users["username"][StoreAttemptTime].(time.Time); !ok || old.After(current) {
|
|
|
|
t.Error("%d: StoreAttemptTime not set correctly: %v", i, current)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
current = old
|
|
|
|
}
|
|
|
|
|
2015-02-16 23:31:26 +02:00
|
|
|
if !storer.Users["username"][StoreLocked].(bool) {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("User should be locked.")
|
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if val := storer.Users["username"][StoreAttemptNumber].(int); val != 3 {
|
|
|
|
t.Error("StoreAttemptNumber set incorrectly:", val)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok = storer.Users["username"][StoreAttemptTime].(time.Time); !ok {
|
|
|
|
t.Error("StoreAttemptTime not set correctly.")
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAfterAuthFail_Reset(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-25 08:19:22 +02:00
|
|
|
var old, current time.Time
|
|
|
|
var ok bool
|
|
|
|
|
|
|
|
ctx := authboss.NewContext()
|
|
|
|
storer := mocks.NewMockStorer()
|
|
|
|
lock := Lock{}
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.Cfg.LockWindow = 30 * time.Minute
|
|
|
|
authboss.Cfg.Storer = storer
|
2015-01-25 08:19:22 +02:00
|
|
|
|
|
|
|
old = time.Now().UTC().Add(-time.Hour)
|
|
|
|
|
|
|
|
ctx.User = map[string]interface{}{
|
2015-02-16 23:31:26 +02:00
|
|
|
"username": "username",
|
|
|
|
StoreAttemptNumber: 2,
|
|
|
|
StoreAttemptTime: old,
|
|
|
|
StoreLocked: false,
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
lock.AfterAuthFail(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if val := storer.Users["username"][StoreAttemptNumber].(int); val != 0 {
|
|
|
|
t.Error("StoreAttemptNumber set incorrectly:", val)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if current, ok = storer.Users["username"][StoreAttemptTime].(time.Time); !ok || current.Before(old) {
|
|
|
|
t.Error("StoreAttemptTime not set correctly.")
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if locked := storer.Users["username"][StoreLocked].(bool); locked {
|
|
|
|
t.Error("StoreLocked not set correctly:", locked)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAfterAuthFail_Errors(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-25 08:19:22 +02:00
|
|
|
lock := Lock{}
|
|
|
|
ctx := authboss.NewContext()
|
|
|
|
|
|
|
|
lock.AfterAuthFail(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := ctx.User[StoreAttemptNumber]; ok {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("Expected nothing to be set, missing user.")
|
|
|
|
}
|
|
|
|
|
|
|
|
ctx.User = map[string]interface{}{"otherattribute": "somevalue"}
|
|
|
|
lock.AfterAuthFail(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := ctx.User[StoreAttemptNumber]; ok {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("Expected username not present to stop this assignment.")
|
|
|
|
}
|
|
|
|
|
|
|
|
ctx.User["username"] = 5
|
|
|
|
lock.AfterAuthFail(ctx)
|
2015-02-16 23:31:26 +02:00
|
|
|
if _, ok := ctx.User[StoreAttemptNumber]; ok {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("Expected username wrong type stop this assignment.")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestLock(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-25 08:19:22 +02:00
|
|
|
storer := mocks.NewMockStorer()
|
|
|
|
lock := Lock{}
|
|
|
|
|
|
|
|
storer.Users["username"] = map[string]interface{}{
|
|
|
|
"username": "username",
|
|
|
|
"password": "password",
|
|
|
|
}
|
|
|
|
|
|
|
|
err := lock.Lock("username", storer)
|
|
|
|
if err != nil {
|
|
|
|
t.Error(err)
|
|
|
|
}
|
|
|
|
|
2015-02-16 23:31:26 +02:00
|
|
|
if locked := storer.Users["username"][StoreLocked].(bool); !locked {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("User should be locked.")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestUnlock(t *testing.T) {
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.NewConfig()
|
2015-01-25 08:19:22 +02:00
|
|
|
storer := mocks.NewMockStorer()
|
|
|
|
lock := Lock{}
|
2015-02-16 06:07:36 +02:00
|
|
|
authboss.Cfg.LockWindow = 1 * time.Hour
|
2015-01-25 08:19:22 +02:00
|
|
|
|
|
|
|
storer.Users["username"] = map[string]interface{}{
|
|
|
|
"username": "username",
|
|
|
|
"password": "password",
|
|
|
|
"locked": true,
|
|
|
|
}
|
|
|
|
|
|
|
|
err := lock.Unlock("username", storer)
|
|
|
|
if err != nil {
|
|
|
|
t.Error(err)
|
|
|
|
}
|
|
|
|
|
2015-02-16 23:31:26 +02:00
|
|
|
attemptTime := storer.Users["username"][StoreAttemptTime].(time.Time)
|
2015-02-16 06:07:36 +02:00
|
|
|
if attemptTime.After(time.Now().UTC().Add(-authboss.Cfg.LockWindow)) {
|
2015-02-16 23:31:26 +02:00
|
|
|
t.Error("StoreLocked not set correctly:", attemptTime)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if number := storer.Users["username"][StoreAttemptNumber].(int); number != 0 {
|
|
|
|
t.Error("StoreLocked not set correctly:", number)
|
2015-01-25 08:19:22 +02:00
|
|
|
}
|
2015-02-16 23:31:26 +02:00
|
|
|
if locked := storer.Users["username"][StoreLocked].(bool); locked {
|
2015-01-25 08:19:22 +02:00
|
|
|
t.Error("User should not be locked.")
|
|
|
|
}
|
|
|
|
}
|