2022-07-06 23:19:05 +02:00
|
|
|
package apis_test
|
|
|
|
|
|
|
|
import (
|
2023-03-01 23:45:54 +02:00
|
|
|
"crypto/ecdsa"
|
|
|
|
"crypto/elliptic"
|
|
|
|
"crypto/rand"
|
|
|
|
"crypto/x509"
|
|
|
|
"encoding/pem"
|
|
|
|
"fmt"
|
2022-07-06 23:19:05 +02:00
|
|
|
"net/http"
|
|
|
|
"strings"
|
|
|
|
"testing"
|
|
|
|
|
2022-08-21 13:30:36 +02:00
|
|
|
"github.com/labstack/echo/v5"
|
2022-07-06 23:19:05 +02:00
|
|
|
"github.com/pocketbase/pocketbase/tests"
|
|
|
|
)
|
|
|
|
|
|
|
|
func TestSettingsList(t *testing.T) {
|
|
|
|
scenarios := []tests.ApiScenario{
|
|
|
|
{
|
|
|
|
Name: "unauthorized",
|
|
|
|
Method: http.MethodGet,
|
|
|
|
Url: "/api/settings",
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
2022-10-30 10:28:14 +02:00
|
|
|
Name: "authorized as auth record",
|
2022-07-06 23:19:05 +02:00
|
|
|
Method: http.MethodGet,
|
|
|
|
Url: "/api/settings",
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiJ9.eyJpZCI6IjRxMXhsY2xtZmxva3UzMyIsInR5cGUiOiJhdXRoUmVjb3JkIiwiY29sbGVjdGlvbklkIjoiX3BiX3VzZXJzX2F1dGhfIiwiZXhwIjoyMjA4OTg1MjYxfQ.UwD8JvkbQtXpymT09d7J6fdA0aP9g4FJ1GPh_ggEkzc",
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin",
|
|
|
|
Method: http.MethodGet,
|
|
|
|
Url: "/api/settings",
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 200,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"meta":{`,
|
|
|
|
`"logs":{`,
|
|
|
|
`"smtp":{`,
|
|
|
|
`"s3":{`,
|
2023-05-13 21:10:14 +02:00
|
|
|
`"backups":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"adminAuthToken":{`,
|
|
|
|
`"adminPasswordResetToken":{`,
|
2023-04-04 19:47:03 +02:00
|
|
|
`"adminFileToken":{`,
|
2022-10-30 10:28:14 +02:00
|
|
|
`"recordAuthToken":{`,
|
|
|
|
`"recordPasswordResetToken":{`,
|
|
|
|
`"recordEmailChangeToken":{`,
|
|
|
|
`"recordVerificationToken":{`,
|
2023-04-04 19:47:03 +02:00
|
|
|
`"recordFileToken":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"emailAuth":{`,
|
|
|
|
`"googleAuth":{`,
|
|
|
|
`"facebookAuth":{`,
|
|
|
|
`"githubAuth":{`,
|
|
|
|
`"gitlabAuth":{`,
|
2022-10-30 10:28:14 +02:00
|
|
|
`"twitterAuth":{`,
|
2022-08-21 18:38:42 +02:00
|
|
|
`"discordAuth":{`,
|
2022-10-31 21:17:10 +02:00
|
|
|
`"microsoftAuth":{`,
|
2022-11-01 17:06:06 +02:00
|
|
|
`"spotifyAuth":{`,
|
2022-11-13 13:05:06 +02:00
|
|
|
`"kakaoAuth":{`,
|
2022-11-13 14:20:11 +02:00
|
|
|
`"twitchAuth":{`,
|
2022-12-31 02:21:41 +02:00
|
|
|
`"stravaAuth":{`,
|
2022-12-31 11:46:36 +02:00
|
|
|
`"giteeAuth":{`,
|
2023-01-12 22:12:34 +02:00
|
|
|
`"livechatAuth":{`,
|
2023-01-20 10:17:57 +02:00
|
|
|
`"giteaAuth":{`,
|
2023-02-23 21:07:00 +02:00
|
|
|
`"oidcAuth":{`,
|
|
|
|
`"oidc2Auth":{`,
|
|
|
|
`"oidc3Auth":{`,
|
2023-03-01 23:29:45 +02:00
|
|
|
`"appleAuth":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"secret":"******"`,
|
|
|
|
`"clientSecret":"******"`,
|
|
|
|
},
|
|
|
|
ExpectedEvents: map[string]int{
|
|
|
|
"OnSettingsListRequest": 1,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, scenario := range scenarios {
|
|
|
|
scenario.Test(t)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestSettingsSet(t *testing.T) {
|
2022-10-30 10:28:14 +02:00
|
|
|
validData := `{"meta":{"appName":"update_test"}}`
|
2022-07-06 23:19:05 +02:00
|
|
|
|
|
|
|
scenarios := []tests.ApiScenario{
|
|
|
|
{
|
|
|
|
Name: "unauthorized",
|
|
|
|
Method: http.MethodPatch,
|
|
|
|
Url: "/api/settings",
|
|
|
|
Body: strings.NewReader(validData),
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
2022-10-30 10:28:14 +02:00
|
|
|
Name: "authorized as auth record",
|
2022-07-06 23:19:05 +02:00
|
|
|
Method: http.MethodPatch,
|
|
|
|
Url: "/api/settings",
|
|
|
|
Body: strings.NewReader(validData),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiJ9.eyJpZCI6IjRxMXhsY2xtZmxva3UzMyIsInR5cGUiOiJhdXRoUmVjb3JkIiwiY29sbGVjdGlvbklkIjoiX3BiX3VzZXJzX2F1dGhfIiwiZXhwIjoyMjA4OTg1MjYxfQ.UwD8JvkbQtXpymT09d7J6fdA0aP9g4FJ1GPh_ggEkzc",
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin submitting empty data",
|
|
|
|
Method: http.MethodPatch,
|
|
|
|
Url: "/api/settings",
|
|
|
|
Body: strings.NewReader(``),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 200,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"meta":{`,
|
|
|
|
`"logs":{`,
|
|
|
|
`"smtp":{`,
|
|
|
|
`"s3":{`,
|
2023-05-13 21:10:14 +02:00
|
|
|
`"backups":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"adminAuthToken":{`,
|
|
|
|
`"adminPasswordResetToken":{`,
|
2023-04-04 19:47:03 +02:00
|
|
|
`"adminFileToken":{`,
|
2022-10-30 10:28:14 +02:00
|
|
|
`"recordAuthToken":{`,
|
|
|
|
`"recordPasswordResetToken":{`,
|
|
|
|
`"recordEmailChangeToken":{`,
|
|
|
|
`"recordVerificationToken":{`,
|
2023-04-04 19:47:03 +02:00
|
|
|
`"recordFileToken":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"emailAuth":{`,
|
|
|
|
`"googleAuth":{`,
|
|
|
|
`"facebookAuth":{`,
|
|
|
|
`"githubAuth":{`,
|
|
|
|
`"gitlabAuth":{`,
|
2022-08-21 18:38:42 +02:00
|
|
|
`"discordAuth":{`,
|
2022-10-31 21:17:10 +02:00
|
|
|
`"microsoftAuth":{`,
|
2022-11-01 17:06:06 +02:00
|
|
|
`"spotifyAuth":{`,
|
2022-11-13 13:05:06 +02:00
|
|
|
`"kakaoAuth":{`,
|
2022-11-13 14:20:11 +02:00
|
|
|
`"twitchAuth":{`,
|
2022-12-31 02:21:41 +02:00
|
|
|
`"stravaAuth":{`,
|
2022-12-31 11:46:36 +02:00
|
|
|
`"giteeAuth":{`,
|
2023-01-12 22:12:34 +02:00
|
|
|
`"livechatAuth":{`,
|
2023-01-20 10:17:57 +02:00
|
|
|
`"giteaAuth":{`,
|
2023-02-23 21:07:00 +02:00
|
|
|
`"oidcAuth":{`,
|
|
|
|
`"oidc2Auth":{`,
|
|
|
|
`"oidc3Auth":{`,
|
2023-03-01 23:29:45 +02:00
|
|
|
`"appleAuth":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"secret":"******"`,
|
|
|
|
`"clientSecret":"******"`,
|
2022-11-26 14:42:45 +02:00
|
|
|
`"appName":"acme_test"`,
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
ExpectedEvents: map[string]int{
|
|
|
|
"OnModelBeforeUpdate": 1,
|
|
|
|
"OnModelAfterUpdate": 1,
|
|
|
|
"OnSettingsBeforeUpdateRequest": 1,
|
|
|
|
"OnSettingsAfterUpdateRequest": 1,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin submitting invalid data",
|
|
|
|
Method: http.MethodPatch,
|
|
|
|
Url: "/api/settings",
|
2022-10-30 10:28:14 +02:00
|
|
|
Body: strings.NewReader(`{"meta":{"appName":""}}`),
|
2022-07-06 23:19:05 +02:00
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"data":{`,
|
2022-10-30 10:28:14 +02:00
|
|
|
`"meta":{"appName":{"code":"validation_required"`,
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin submitting valid data",
|
|
|
|
Method: http.MethodPatch,
|
|
|
|
Url: "/api/settings",
|
|
|
|
Body: strings.NewReader(validData),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-07-06 23:19:05 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 200,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"meta":{`,
|
|
|
|
`"logs":{`,
|
|
|
|
`"smtp":{`,
|
|
|
|
`"s3":{`,
|
2023-05-13 21:10:14 +02:00
|
|
|
`"backups":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"adminAuthToken":{`,
|
|
|
|
`"adminPasswordResetToken":{`,
|
2023-04-04 19:47:03 +02:00
|
|
|
`"adminFileToken":{`,
|
2022-10-30 10:28:14 +02:00
|
|
|
`"recordAuthToken":{`,
|
|
|
|
`"recordPasswordResetToken":{`,
|
|
|
|
`"recordEmailChangeToken":{`,
|
|
|
|
`"recordVerificationToken":{`,
|
2023-04-04 19:47:03 +02:00
|
|
|
`"recordFileToken":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"emailAuth":{`,
|
|
|
|
`"googleAuth":{`,
|
|
|
|
`"facebookAuth":{`,
|
|
|
|
`"githubAuth":{`,
|
|
|
|
`"gitlabAuth":{`,
|
2022-10-30 10:28:14 +02:00
|
|
|
`"twitterAuth":{`,
|
2022-08-21 18:38:42 +02:00
|
|
|
`"discordAuth":{`,
|
2022-10-31 21:17:10 +02:00
|
|
|
`"microsoftAuth":{`,
|
2022-11-01 17:06:06 +02:00
|
|
|
`"spotifyAuth":{`,
|
2022-11-13 13:05:06 +02:00
|
|
|
`"kakaoAuth":{`,
|
2022-11-13 14:20:11 +02:00
|
|
|
`"twitchAuth":{`,
|
2022-12-31 02:21:41 +02:00
|
|
|
`"stravaAuth":{`,
|
2022-12-31 11:46:36 +02:00
|
|
|
`"giteeAuth":{`,
|
2023-01-12 22:12:34 +02:00
|
|
|
`"livechatAuth":{`,
|
2023-01-20 10:17:57 +02:00
|
|
|
`"giteaAuth":{`,
|
2023-02-23 21:07:00 +02:00
|
|
|
`"oidcAuth":{`,
|
|
|
|
`"oidc2Auth":{`,
|
|
|
|
`"oidc3Auth":{`,
|
2023-03-01 23:29:45 +02:00
|
|
|
`"appleAuth":{`,
|
2022-07-06 23:19:05 +02:00
|
|
|
`"secret":"******"`,
|
|
|
|
`"clientSecret":"******"`,
|
|
|
|
`"appName":"update_test"`,
|
|
|
|
},
|
|
|
|
ExpectedEvents: map[string]int{
|
|
|
|
"OnModelBeforeUpdate": 1,
|
|
|
|
"OnModelAfterUpdate": 1,
|
|
|
|
"OnSettingsBeforeUpdateRequest": 1,
|
|
|
|
"OnSettingsAfterUpdateRequest": 1,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, scenario := range scenarios {
|
|
|
|
scenario.Test(t)
|
|
|
|
}
|
|
|
|
}
|
2022-08-21 13:30:36 +02:00
|
|
|
|
|
|
|
func TestSettingsTestS3(t *testing.T) {
|
|
|
|
scenarios := []tests.ApiScenario{
|
|
|
|
{
|
|
|
|
Name: "unauthorized",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/s3",
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
2022-10-30 10:28:14 +02:00
|
|
|
Name: "authorized as auth record",
|
2022-08-21 13:30:36 +02:00
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/s3",
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiJ9.eyJpZCI6IjRxMXhsY2xtZmxva3UzMyIsInR5cGUiOiJhdXRoUmVjb3JkIiwiY29sbGVjdGlvbklkIjoiX3BiX3VzZXJzX2F1dGhfIiwiZXhwIjoyMjA4OTg1MjYxfQ.UwD8JvkbQtXpymT09d7J6fdA0aP9g4FJ1GPh_ggEkzc",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
2023-05-13 21:10:14 +02:00
|
|
|
Name: "authorized as admin (missing body + no s3)",
|
2022-08-21 13:30:36 +02:00
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/s3",
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
2023-05-13 21:10:14 +02:00
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"data":{`,
|
|
|
|
`"filesystem":{`,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (invalid filesystem)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/s3",
|
|
|
|
Body: strings.NewReader(`{"filesystem":"invalid"}`),
|
|
|
|
RequestHeaders: map[string]string{
|
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"data":{`,
|
|
|
|
`"filesystem":{`,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (valid filesystem and no s3)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/s3",
|
|
|
|
Body: strings.NewReader(`{"filesystem":"storage"}`),
|
|
|
|
RequestHeaders: map[string]string{
|
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"data":{}`,
|
|
|
|
},
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, scenario := range scenarios {
|
|
|
|
scenario.Test(t)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestSettingsTestEmail(t *testing.T) {
|
|
|
|
scenarios := []tests.ApiScenario{
|
|
|
|
{
|
|
|
|
Name: "unauthorized",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/email",
|
|
|
|
Body: strings.NewReader(`{
|
|
|
|
"template": "verification",
|
|
|
|
"email": "test@example.com"
|
|
|
|
}`),
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
2022-10-30 10:28:14 +02:00
|
|
|
Name: "authorized as auth record",
|
2022-08-21 13:30:36 +02:00
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/email",
|
|
|
|
Body: strings.NewReader(`{
|
|
|
|
"template": "verification",
|
|
|
|
"email": "test@example.com"
|
|
|
|
}`),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiJ9.eyJpZCI6IjRxMXhsY2xtZmxva3UzMyIsInR5cGUiOiJhdXRoUmVjb3JkIiwiY29sbGVjdGlvbklkIjoiX3BiX3VzZXJzX2F1dGhfIiwiZXhwIjoyMjA4OTg1MjYxfQ.UwD8JvkbQtXpymT09d7J6fdA0aP9g4FJ1GPh_ggEkzc",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (invalid body)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/email",
|
|
|
|
Body: strings.NewReader(`{`),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (empty json)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/email",
|
|
|
|
Body: strings.NewReader(`{}`),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"email":{"code":"validation_required"`,
|
|
|
|
`"template":{"code":"validation_required"`,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (verifiation template)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/email",
|
|
|
|
Body: strings.NewReader(`{
|
|
|
|
"template": "verification",
|
|
|
|
"email": "test@example.com"
|
|
|
|
}`),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
2022-09-07 19:31:05 +02:00
|
|
|
AfterTestFunc: func(t *testing.T, app *tests.TestApp, e *echo.Echo) {
|
2022-08-21 13:30:36 +02:00
|
|
|
if app.TestMailer.TotalSend != 1 {
|
|
|
|
t.Fatalf("[verification] Expected 1 sent email, got %d", app.TestMailer.TotalSend)
|
|
|
|
}
|
|
|
|
|
2023-02-01 22:07:46 +02:00
|
|
|
if len(app.TestMailer.LastMessage.To) != 1 {
|
|
|
|
t.Fatalf("[verification] Expected 1 recipient, got %v", app.TestMailer.LastMessage.To)
|
|
|
|
}
|
|
|
|
|
|
|
|
if app.TestMailer.LastMessage.To[0].Address != "test@example.com" {
|
|
|
|
t.Fatalf("[verification] Expected the email to be sent to %s, got %s", "test@example.com", app.TestMailer.LastMessage.To[0].Address)
|
2022-08-21 13:30:36 +02:00
|
|
|
}
|
|
|
|
|
2022-11-21 14:53:05 +02:00
|
|
|
if !strings.Contains(app.TestMailer.LastMessage.HTML, "Verify") {
|
|
|
|
t.Fatalf("[verification] Expected to sent a verification email, got \n%v\n%v", app.TestMailer.LastMessage.Subject, app.TestMailer.LastMessage.HTML)
|
2022-08-21 13:30:36 +02:00
|
|
|
}
|
|
|
|
},
|
|
|
|
ExpectedStatus: 204,
|
|
|
|
ExpectedContent: []string{},
|
|
|
|
ExpectedEvents: map[string]int{
|
2022-10-30 10:28:14 +02:00
|
|
|
"OnMailerBeforeRecordVerificationSend": 1,
|
|
|
|
"OnMailerAfterRecordVerificationSend": 1,
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (password reset template)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/email",
|
|
|
|
Body: strings.NewReader(`{
|
|
|
|
"template": "password-reset",
|
|
|
|
"email": "test@example.com"
|
|
|
|
}`),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
2022-09-07 19:31:05 +02:00
|
|
|
AfterTestFunc: func(t *testing.T, app *tests.TestApp, e *echo.Echo) {
|
2022-08-21 13:30:36 +02:00
|
|
|
if app.TestMailer.TotalSend != 1 {
|
|
|
|
t.Fatalf("[password-reset] Expected 1 sent email, got %d", app.TestMailer.TotalSend)
|
|
|
|
}
|
|
|
|
|
2023-02-01 22:07:46 +02:00
|
|
|
if len(app.TestMailer.LastMessage.To) != 1 {
|
|
|
|
t.Fatalf("[password-reset] Expected 1 recipient, got %v", app.TestMailer.LastMessage.To)
|
|
|
|
}
|
|
|
|
|
|
|
|
if app.TestMailer.LastMessage.To[0].Address != "test@example.com" {
|
|
|
|
t.Fatalf("[password-reset] Expected the email to be sent to %s, got %s", "test@example.com", app.TestMailer.LastMessage.To[0].Address)
|
2022-08-21 13:30:36 +02:00
|
|
|
}
|
|
|
|
|
2022-11-21 14:53:05 +02:00
|
|
|
if !strings.Contains(app.TestMailer.LastMessage.HTML, "Reset password") {
|
|
|
|
t.Fatalf("[password-reset] Expected to sent a password-reset email, got \n%v\n%v", app.TestMailer.LastMessage.Subject, app.TestMailer.LastMessage.HTML)
|
2022-08-21 13:30:36 +02:00
|
|
|
}
|
|
|
|
},
|
|
|
|
ExpectedStatus: 204,
|
|
|
|
ExpectedContent: []string{},
|
|
|
|
ExpectedEvents: map[string]int{
|
2022-10-30 10:28:14 +02:00
|
|
|
"OnMailerBeforeRecordResetPasswordSend": 1,
|
|
|
|
"OnMailerAfterRecordResetPasswordSend": 1,
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (email change)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/test/email",
|
|
|
|
Body: strings.NewReader(`{
|
|
|
|
"template": "email-change",
|
|
|
|
"email": "test@example.com"
|
|
|
|
}`),
|
|
|
|
RequestHeaders: map[string]string{
|
2022-10-30 10:28:14 +02:00
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
2022-09-07 19:31:05 +02:00
|
|
|
AfterTestFunc: func(t *testing.T, app *tests.TestApp, e *echo.Echo) {
|
2022-08-21 13:30:36 +02:00
|
|
|
if app.TestMailer.TotalSend != 1 {
|
|
|
|
t.Fatalf("[email-change] Expected 1 sent email, got %d", app.TestMailer.TotalSend)
|
|
|
|
}
|
|
|
|
|
2023-02-01 22:07:46 +02:00
|
|
|
if len(app.TestMailer.LastMessage.To) != 1 {
|
|
|
|
t.Fatalf("[email-change] Expected 1 recipient, got %v", app.TestMailer.LastMessage.To)
|
|
|
|
}
|
|
|
|
|
|
|
|
if app.TestMailer.LastMessage.To[0].Address != "test@example.com" {
|
|
|
|
t.Fatalf("[email-change] Expected the email to be sent to %s, got %s", "test@example.com", app.TestMailer.LastMessage.To[0].Address)
|
2022-08-21 13:30:36 +02:00
|
|
|
}
|
|
|
|
|
2022-11-21 14:53:05 +02:00
|
|
|
if !strings.Contains(app.TestMailer.LastMessage.HTML, "Confirm new email") {
|
|
|
|
t.Fatalf("[email-change] Expected to sent a confirm new email email, got \n%v\n%v", app.TestMailer.LastMessage.Subject, app.TestMailer.LastMessage.HTML)
|
2022-08-21 13:30:36 +02:00
|
|
|
}
|
|
|
|
},
|
|
|
|
ExpectedStatus: 204,
|
|
|
|
ExpectedContent: []string{},
|
|
|
|
ExpectedEvents: map[string]int{
|
2022-10-30 10:28:14 +02:00
|
|
|
"OnMailerBeforeRecordChangeEmailSend": 1,
|
|
|
|
"OnMailerAfterRecordChangeEmailSend": 1,
|
2022-08-21 13:30:36 +02:00
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, scenario := range scenarios {
|
|
|
|
scenario.Test(t)
|
|
|
|
}
|
|
|
|
}
|
2023-03-01 23:45:54 +02:00
|
|
|
|
|
|
|
func TestGenerateAppleClientSecret(t *testing.T) {
|
|
|
|
key, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
encodedKey, err := x509.MarshalPKCS8PrivateKey(key)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
privatePem := pem.EncodeToMemory(
|
|
|
|
&pem.Block{
|
|
|
|
Type: "PRIVATE KEY",
|
|
|
|
Bytes: encodedKey,
|
|
|
|
},
|
|
|
|
)
|
|
|
|
|
|
|
|
scenarios := []tests.ApiScenario{
|
|
|
|
{
|
|
|
|
Name: "unauthorized",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/apple/generate-client-secret",
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as auth record",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/apple/generate-client-secret",
|
|
|
|
RequestHeaders: map[string]string{
|
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiJ9.eyJpZCI6IjRxMXhsY2xtZmxva3UzMyIsInR5cGUiOiJhdXRoUmVjb3JkIiwiY29sbGVjdGlvbklkIjoiX3BiX3VzZXJzX2F1dGhfIiwiZXhwIjoyMjA4OTg1MjYxfQ.UwD8JvkbQtXpymT09d7J6fdA0aP9g4FJ1GPh_ggEkzc",
|
|
|
|
},
|
|
|
|
ExpectedStatus: 401,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (invalid body)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/apple/generate-client-secret",
|
|
|
|
Body: strings.NewReader(`{`),
|
|
|
|
RequestHeaders: map[string]string{
|
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{`"data":{}`},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (empty json)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/apple/generate-client-secret",
|
|
|
|
Body: strings.NewReader(`{}`),
|
|
|
|
RequestHeaders: map[string]string{
|
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"clientId":{"code":"validation_required"`,
|
|
|
|
`"teamId":{"code":"validation_required"`,
|
|
|
|
`"keyId":{"code":"validation_required"`,
|
|
|
|
`"privateKey":{"code":"validation_required"`,
|
|
|
|
`"duration":{"code":"validation_required"`,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: "authorized as admin (invalid data)",
|
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/apple/generate-client-secret",
|
|
|
|
Body: strings.NewReader(`{
|
|
|
|
"clientId": "",
|
|
|
|
"teamId": "123456789",
|
|
|
|
"keyId": "123456789",
|
|
|
|
"privateKey": "invalid",
|
|
|
|
"duration": -1
|
|
|
|
}`),
|
|
|
|
RequestHeaders: map[string]string{
|
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
|
|
|
},
|
|
|
|
ExpectedStatus: 400,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"clientId":{"code":"validation_required"`,
|
|
|
|
`"teamId":{"code":"validation_length_invalid"`,
|
|
|
|
`"keyId":{"code":"validation_length_invalid"`,
|
|
|
|
`"privateKey":{"code":"validation_match_invalid"`,
|
|
|
|
`"duration":{"code":"validation_min_greater_equal_than_required"`,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2023-03-27 15:16:09 +02:00
|
|
|
Name: "authorized as admin (valid data)",
|
2023-03-01 23:45:54 +02:00
|
|
|
Method: http.MethodPost,
|
|
|
|
Url: "/api/settings/apple/generate-client-secret",
|
|
|
|
Body: strings.NewReader(fmt.Sprintf(`{
|
|
|
|
"clientId": "123",
|
|
|
|
"teamId": "1234567890",
|
|
|
|
"keyId": "1234567891",
|
|
|
|
"privateKey": %q,
|
|
|
|
"duration": 1
|
|
|
|
}`, privatePem)),
|
|
|
|
RequestHeaders: map[string]string{
|
|
|
|
"Authorization": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InN5d2JoZWNuaDQ2cmhtMCIsInR5cGUiOiJhZG1pbiIsImV4cCI6MjIwODk4NTI2MX0.M1m--VOqGyv0d23eeUc0r9xE8ZzHaYVmVFw1VZW6gT8",
|
|
|
|
},
|
|
|
|
ExpectedStatus: 200,
|
|
|
|
ExpectedContent: []string{
|
|
|
|
`"secret":"`,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, scenario := range scenarios {
|
|
|
|
scenario.Test(t)
|
|
|
|
}
|
|
|
|
}
|