chore: update golangci-lint to v2.12.2 with canonical config
All checks were successful
check / check (push) Successful in 2m3s
All checks were successful
check / check (push) Successful in 2m3s
Replace .golangci.yml with the canonical v2-schema config (default: all minus six disabled linters, lll 88, tests included) and bump every golangci-lint pin to v2.12.2: - Dockerfile: golangci/golangci-lint:v2.12.2-alpine (hash-pinned) - script/bootstrap: GOLANGCI_LINT_VERSION 2.12.2 with new linux-amd64/arm64 release-archive sha256 pins Fix all 747 findings the stricter config surfaces, with no behavior changes: t.Parallel() throughout the test suite, static sentinel errors and errors.Is comparisons, checked error returns, context propagation (contextcheck/noctx), 88-column wrapping, extracted constants and helpers for goconst/dupl/funlen/cyclop, exhaustive switch cases replicating existing defaults, and white-box test files renamed to *_internal_test.go for testpackage. Three nolint:tagliatelle directives preserve the existing snake_case JSON wire and on-disk metadata formats.
This commit is contained in:
@@ -1,21 +1,36 @@
|
||||
package signature
|
||||
package signature_test
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"sneak.berlin/go/pixa/internal/signature"
|
||||
)
|
||||
|
||||
// Shared fixture values used across the signature tests.
|
||||
const (
|
||||
testHost = "cdn.example.com"
|
||||
testPath = "/photos/cat.jpg"
|
||||
testFormatWebP = "webp"
|
||||
testFormatPNG = "png"
|
||||
testSignedPath = "/v1/image/cdn.example.com/photos/cat.jpg/800x600.webp"
|
||||
testSig = "abc123"
|
||||
)
|
||||
|
||||
func TestSigner_Sign(t *testing.T) {
|
||||
signer := New("test-secret-key")
|
||||
t.Parallel()
|
||||
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
signer := signature.New("test-secret-key")
|
||||
|
||||
req := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
SourceQuery: "",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
Expires: time.Unix(1704067200, 0), // Fixed timestamp for reproducibility
|
||||
}
|
||||
|
||||
@@ -24,7 +39,8 @@ func TestSigner_Sign(t *testing.T) {
|
||||
|
||||
// Same input should produce same signature
|
||||
if sig1 != sig2 {
|
||||
t.Errorf("Sign() produced different signatures for same input: %q vs %q", sig1, sig2)
|
||||
t.Errorf("Sign() produced different signatures for same input: %q vs %q",
|
||||
sig1, sig2)
|
||||
}
|
||||
|
||||
// Signature should be non-empty
|
||||
@@ -33,13 +49,13 @@ func TestSigner_Sign(t *testing.T) {
|
||||
}
|
||||
|
||||
// Different input should produce different signature
|
||||
req2 := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
req2 := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: "/photos/dog.jpg", // Different path
|
||||
SourceQuery: "",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
Expires: time.Unix(1704067200, 0),
|
||||
}
|
||||
|
||||
@@ -49,25 +65,31 @@ func TestSigner_Sign(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestSigner_Verify(t *testing.T) {
|
||||
signer := New("test-secret-key")
|
||||
// validVerifyRequest returns a fully-populated request that verifies
|
||||
// successfully once signed.
|
||||
func validVerifyRequest() *signature.Request {
|
||||
return &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: testFormatWebP,
|
||||
Expires: time.Now().Add(1 * time.Hour),
|
||||
}
|
||||
}
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
setup func() *Request
|
||||
wantErr error
|
||||
}{
|
||||
type verifyCase struct {
|
||||
name string
|
||||
setup func() *signature.Request
|
||||
wantErr error
|
||||
}
|
||||
|
||||
func verifyCases(signer *signature.Signer) []verifyCase {
|
||||
return []verifyCase{
|
||||
{
|
||||
name: "valid signature",
|
||||
setup: func() *Request {
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Expires: time.Now().Add(1 * time.Hour),
|
||||
}
|
||||
setup: func() *signature.Request {
|
||||
req := validVerifyRequest()
|
||||
req.Signature = signer.Sign(req)
|
||||
|
||||
return req
|
||||
@@ -76,74 +98,59 @@ func TestSigner_Verify(t *testing.T) {
|
||||
},
|
||||
{
|
||||
name: "expired signature",
|
||||
setup: func() *Request {
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Expires: time.Now().Add(-1 * time.Hour), // Expired
|
||||
}
|
||||
setup: func() *signature.Request {
|
||||
req := validVerifyRequest()
|
||||
req.Expires = time.Now().Add(-1 * time.Hour)
|
||||
req.Signature = signer.Sign(req)
|
||||
|
||||
return req
|
||||
},
|
||||
wantErr: ErrExpired,
|
||||
wantErr: signature.ErrExpired,
|
||||
},
|
||||
{
|
||||
name: "invalid signature",
|
||||
setup: func() *Request {
|
||||
return &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Expires: time.Now().Add(1 * time.Hour),
|
||||
Signature: "invalid-signature",
|
||||
}
|
||||
setup: func() *signature.Request {
|
||||
req := validVerifyRequest()
|
||||
req.Signature = "invalid-signature"
|
||||
|
||||
return req
|
||||
},
|
||||
wantErr: ErrInvalid,
|
||||
wantErr: signature.ErrInvalid,
|
||||
},
|
||||
{
|
||||
name: "missing expiration",
|
||||
setup: func() *Request {
|
||||
return &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Signature: "some-signature",
|
||||
// Expires is zero
|
||||
}
|
||||
setup: func() *signature.Request {
|
||||
req := validVerifyRequest()
|
||||
req.Expires = time.Time{}
|
||||
req.Signature = "some-signature"
|
||||
|
||||
return req
|
||||
},
|
||||
wantErr: ErrMissingExpiration,
|
||||
wantErr: signature.ErrMissingExpiration,
|
||||
},
|
||||
{
|
||||
name: "tampered request",
|
||||
setup: func() *Request {
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Expires: time.Now().Add(1 * time.Hour),
|
||||
}
|
||||
setup: func() *signature.Request {
|
||||
req := validVerifyRequest()
|
||||
req.Signature = signer.Sign(req)
|
||||
// Tamper with the request
|
||||
req.SourcePath = "/photos/secret.jpg"
|
||||
|
||||
return req
|
||||
},
|
||||
wantErr: ErrInvalid,
|
||||
wantErr: signature.ErrInvalid,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
func TestSigner_Verify(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
signer := signature.New("test-secret-key")
|
||||
|
||||
for _, tt := range verifyCases(signer) {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
req := tt.setup()
|
||||
err := signer.Verify(req)
|
||||
|
||||
@@ -151,30 +158,102 @@ func TestSigner_Verify(t *testing.T) {
|
||||
if err != nil {
|
||||
t.Errorf("Verify() unexpected error = %v", err)
|
||||
}
|
||||
} else {
|
||||
if err != tt.wantErr {
|
||||
t.Errorf("Verify() error = %v, wantErr %v", err, tt.wantErr)
|
||||
}
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
if !errors.Is(err, tt.wantErr) {
|
||||
t.Errorf("Verify() error = %v, wantErr %v", err, tt.wantErr)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
type tamperCase struct {
|
||||
name string
|
||||
tamper func(r *signature.Request)
|
||||
}
|
||||
|
||||
// exactMatchTamperCases mutates one signed component per case; every
|
||||
// mutation must cause verification to fail with ErrInvalid.
|
||||
func exactMatchTamperCases() []tamperCase {
|
||||
return []tamperCase{
|
||||
{
|
||||
name: "parent domain does not match subdomain",
|
||||
tamper: func(r *signature.Request) { r.SourceHost = "example.com" },
|
||||
},
|
||||
{
|
||||
name: "subdomain does not match parent domain",
|
||||
tamper: func(r *signature.Request) { r.SourceHost = "images.cdn.example.com" },
|
||||
},
|
||||
{
|
||||
name: "sibling subdomain does not match",
|
||||
tamper: func(r *signature.Request) { r.SourceHost = "images.example.com" },
|
||||
},
|
||||
{
|
||||
name: "host with suffix appended does not match",
|
||||
tamper: func(r *signature.Request) { r.SourceHost = testHost + ".evil.com" },
|
||||
},
|
||||
{
|
||||
name: "host with prefix does not match",
|
||||
tamper: func(r *signature.Request) { r.SourceHost = "evilcdn.example.com" },
|
||||
},
|
||||
{
|
||||
name: "different path does not match",
|
||||
tamper: func(r *signature.Request) { r.SourcePath = "/photos/dog.jpg" },
|
||||
},
|
||||
{
|
||||
name: "path suffix does not match",
|
||||
tamper: func(r *signature.Request) { r.SourcePath = testPath + "/extra" },
|
||||
},
|
||||
{
|
||||
name: "path prefix does not match",
|
||||
tamper: func(r *signature.Request) { r.SourcePath = "/other" + testPath },
|
||||
},
|
||||
{
|
||||
name: "different query does not match",
|
||||
tamper: func(r *signature.Request) { r.SourceQuery = "token=xyz" },
|
||||
},
|
||||
{
|
||||
name: "added query does not match empty query",
|
||||
tamper: func(r *signature.Request) { r.SourceQuery = "extra=1" },
|
||||
},
|
||||
{
|
||||
name: "removed query does not match",
|
||||
tamper: func(r *signature.Request) { r.SourceQuery = "" },
|
||||
},
|
||||
{
|
||||
name: "different width does not match",
|
||||
tamper: func(r *signature.Request) { r.Width = 801 },
|
||||
},
|
||||
{
|
||||
name: "different height does not match",
|
||||
tamper: func(r *signature.Request) { r.Height = 601 },
|
||||
},
|
||||
{
|
||||
name: "different format does not match",
|
||||
tamper: func(r *signature.Request) { r.Format = testFormatPNG },
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
// TestSigner_Verify_ExactMatchOnly verifies that signatures enforce exact
|
||||
// matching on every URL component. No suffix matching, wildcard matching,
|
||||
// or partial matching is supported.
|
||||
func TestSigner_Verify_ExactMatchOnly(t *testing.T) {
|
||||
signer := New("test-secret-key")
|
||||
t.Parallel()
|
||||
|
||||
signer := signature.New("test-secret-key")
|
||||
|
||||
// Base request that we'll sign, then tamper with individual fields.
|
||||
baseReq := func() *Request {
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
baseReq := func() *signature.Request {
|
||||
req := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
SourceQuery: "token=abc",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
Expires: time.Now().Add(1 * time.Hour),
|
||||
}
|
||||
req.Signature = signer.Sign(req)
|
||||
@@ -182,117 +261,28 @@ func TestSigner_Verify_ExactMatchOnly(t *testing.T) {
|
||||
return req
|
||||
}
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
tamper func(req *Request)
|
||||
}{
|
||||
{
|
||||
name: "parent domain does not match subdomain",
|
||||
tamper: func(req *Request) {
|
||||
// Signed for cdn.example.com, try example.com
|
||||
req.SourceHost = "example.com"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "subdomain does not match parent domain",
|
||||
tamper: func(req *Request) {
|
||||
// Signed for cdn.example.com, try images.cdn.example.com
|
||||
req.SourceHost = "images.cdn.example.com"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "sibling subdomain does not match",
|
||||
tamper: func(req *Request) {
|
||||
// Signed for cdn.example.com, try images.example.com
|
||||
req.SourceHost = "images.example.com"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "host with suffix appended does not match",
|
||||
tamper: func(req *Request) {
|
||||
// Signed for cdn.example.com, try cdn.example.com.evil.com
|
||||
req.SourceHost = "cdn.example.com.evil.com"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "host with prefix does not match",
|
||||
tamper: func(req *Request) {
|
||||
// Signed for cdn.example.com, try evilcdn.example.com
|
||||
req.SourceHost = "evilcdn.example.com"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "different path does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.SourcePath = "/photos/dog.jpg"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "path suffix does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.SourcePath = "/photos/cat.jpg/extra"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "path prefix does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.SourcePath = "/other/photos/cat.jpg"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "different query does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.SourceQuery = "token=xyz"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "added query does not match empty query",
|
||||
tamper: func(req *Request) {
|
||||
req.SourceQuery = "extra=1"
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "removed query does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.SourceQuery = ""
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "different width does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.Width = 801
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "different height does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.Height = 601
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "different format does not match",
|
||||
tamper: func(req *Request) {
|
||||
req.Format = "png"
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
for _, tt := range exactMatchTamperCases() {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
req := baseReq()
|
||||
tt.tamper(req)
|
||||
|
||||
err := signer.Verify(req)
|
||||
if err != ErrInvalid {
|
||||
t.Errorf("Verify() = %v, want %v", err, ErrInvalid)
|
||||
if !errors.Is(err, signature.ErrInvalid) {
|
||||
t.Errorf("Verify() = %v, want %v", err, signature.ErrInvalid)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
// Verify the unmodified base request still passes
|
||||
t.Run("unmodified request passes", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
req := baseReq()
|
||||
if err := signer.Verify(req); err != nil {
|
||||
|
||||
err := signer.Verify(req)
|
||||
if err != nil {
|
||||
t.Errorf("Verify() unmodified request failed: %v", err)
|
||||
}
|
||||
})
|
||||
@@ -302,10 +292,12 @@ func TestSigner_Verify_ExactMatchOnly(t *testing.T) {
|
||||
// string in the signature data, producing different signatures for
|
||||
// suffix-related hosts.
|
||||
func TestSigner_Sign_ExactHostInData(t *testing.T) {
|
||||
signer := New("test-secret-key")
|
||||
t.Parallel()
|
||||
|
||||
signer := signature.New("test-secret-key")
|
||||
|
||||
hosts := []string{
|
||||
"cdn.example.com",
|
||||
testHost,
|
||||
"example.com",
|
||||
"images.example.com",
|
||||
"images.cdn.example.com",
|
||||
@@ -315,13 +307,13 @@ func TestSigner_Sign_ExactHostInData(t *testing.T) {
|
||||
sigs := make(map[string]string)
|
||||
|
||||
for _, host := range hosts {
|
||||
req := &Request{
|
||||
req := &signature.Request{
|
||||
SourceHost: host,
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
SourcePath: testPath,
|
||||
SourceQuery: "",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
Expires: time.Unix(1704067200, 0),
|
||||
}
|
||||
|
||||
@@ -335,15 +327,17 @@ func TestSigner_Sign_ExactHostInData(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestSigner_DifferentKeys(t *testing.T) {
|
||||
signer1 := New("secret-key-1")
|
||||
signer2 := New("secret-key-2")
|
||||
t.Parallel()
|
||||
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
signer1 := signature.New("secret-key-1")
|
||||
signer2 := signature.New("secret-key-2")
|
||||
|
||||
req := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
Expires: time.Now().Add(1 * time.Hour),
|
||||
}
|
||||
|
||||
@@ -351,35 +345,38 @@ func TestSigner_DifferentKeys(t *testing.T) {
|
||||
req.Signature = signer1.Sign(req)
|
||||
|
||||
// Verify with key 1 should succeed
|
||||
if err := signer1.Verify(req); err != nil {
|
||||
err := signer1.Verify(req)
|
||||
if err != nil {
|
||||
t.Errorf("Verify() with same key failed: %v", err)
|
||||
}
|
||||
|
||||
// Verify with key 2 should fail
|
||||
if err := signer2.Verify(req); err != ErrInvalid {
|
||||
err = signer2.Verify(req)
|
||||
if !errors.Is(err, signature.ErrInvalid) {
|
||||
t.Errorf("Verify() with different key should fail, got: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGenerateSignedURL(t *testing.T) {
|
||||
signer := New("test-secret-key")
|
||||
t.Parallel()
|
||||
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
signer := signature.New("test-secret-key")
|
||||
|
||||
req := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
SourceQuery: "",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
}
|
||||
|
||||
ttl := 1 * time.Hour
|
||||
path, sig, exp := signer.GenerateSignedURL(req, ttl)
|
||||
|
||||
// Path should be correct format
|
||||
expectedPath := "/v1/image/cdn.example.com/photos/cat.jpg/800x600.webp"
|
||||
if path != expectedPath {
|
||||
t.Errorf("GenerateSignedURL() path = %q, want %q", path, expectedPath)
|
||||
if path != testSignedPath {
|
||||
t.Errorf("GenerateSignedURL() path = %q, want %q", path, testSignedPath)
|
||||
}
|
||||
|
||||
// Signature should be non-empty
|
||||
@@ -389,6 +386,7 @@ func TestGenerateSignedURL(t *testing.T) {
|
||||
|
||||
// Expiration should be approximately now + TTL
|
||||
expTime := time.Unix(exp, 0)
|
||||
|
||||
expectedExp := time.Now().Add(ttl)
|
||||
if expTime.Sub(expectedExp) > time.Second {
|
||||
t.Errorf("GenerateSignedURL() exp time off by too much")
|
||||
@@ -401,14 +399,16 @@ func TestGenerateSignedURL(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestGenerateSignedURL_OrigSize(t *testing.T) {
|
||||
signer := New("test-secret-key")
|
||||
t.Parallel()
|
||||
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
signer := signature.New("test-secret-key")
|
||||
|
||||
req := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
Width: 0, // Original size
|
||||
Height: 0,
|
||||
Format: "png",
|
||||
Format: testFormatPNG,
|
||||
}
|
||||
|
||||
path, _, _ := signer.GenerateSignedURL(req, time.Hour)
|
||||
@@ -420,21 +420,24 @@ func TestGenerateSignedURL_OrigSize(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestGenerateSignedURL_WithQueryString(t *testing.T) {
|
||||
signer := New("test-secret-key-for-testing!")
|
||||
t.Parallel()
|
||||
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
signer := signature.New("test-secret-key-for-testing!")
|
||||
|
||||
req := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
SourceQuery: "token=abc&v=2",
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
}
|
||||
|
||||
path, _, _ := signer.GenerateSignedURL(req, time.Hour)
|
||||
|
||||
// The path must NOT contain a bare "?" that would be interpreted as a query string delimiter.
|
||||
// The size segment must appear as the last path component.
|
||||
// The path must NOT contain a bare "?" that would be interpreted as
|
||||
// a query string delimiter. The size segment must appear as the last
|
||||
// path component.
|
||||
if strings.Contains(path, "?token=abc") {
|
||||
t.Errorf("GenerateSignedURL() produced bare query string in path: %q", path)
|
||||
}
|
||||
@@ -451,25 +454,28 @@ func TestGenerateSignedURL_WithQueryString(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestGenerateSignedURL_WithoutQueryString(t *testing.T) {
|
||||
signer := New("test-secret-key-for-testing!")
|
||||
t.Parallel()
|
||||
|
||||
req := &Request{
|
||||
SourceHost: "cdn.example.com",
|
||||
SourcePath: "/photos/cat.jpg",
|
||||
signer := signature.New("test-secret-key-for-testing!")
|
||||
|
||||
req := &signature.Request{
|
||||
SourceHost: testHost,
|
||||
SourcePath: testPath,
|
||||
Width: 800,
|
||||
Height: 600,
|
||||
Format: "webp",
|
||||
Format: testFormatWebP,
|
||||
}
|
||||
|
||||
path, _, _ := signer.GenerateSignedURL(req, time.Hour)
|
||||
|
||||
expected := "/v1/image/cdn.example.com/photos/cat.jpg/800x600.webp"
|
||||
if path != expected {
|
||||
t.Errorf("GenerateSignedURL() path = %q, want %q", path, expected)
|
||||
if path != testSignedPath {
|
||||
t.Errorf("GenerateSignedURL() path = %q, want %q", path, testSignedPath)
|
||||
}
|
||||
}
|
||||
|
||||
func TestParseParams(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
sig string
|
||||
@@ -480,21 +486,21 @@ func TestParseParams(t *testing.T) {
|
||||
}{
|
||||
{
|
||||
name: "valid params",
|
||||
sig: "abc123",
|
||||
sig: testSig,
|
||||
expStr: "1704067200",
|
||||
wantSig: "abc123",
|
||||
wantSig: testSig,
|
||||
wantErr: false,
|
||||
},
|
||||
{
|
||||
name: "empty expiration",
|
||||
sig: "abc123",
|
||||
sig: testSig,
|
||||
expStr: "",
|
||||
wantSig: "abc123",
|
||||
wantSig: testSig,
|
||||
wantErr: false,
|
||||
},
|
||||
{
|
||||
name: "invalid expiration",
|
||||
sig: "abc123",
|
||||
sig: testSig,
|
||||
expStr: "not-a-number",
|
||||
wantErr: true,
|
||||
},
|
||||
@@ -502,7 +508,9 @@ func TestParseParams(t *testing.T) {
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
sig, exp, err := ParseParams(tt.sig, tt.expStr)
|
||||
t.Parallel()
|
||||
|
||||
sig, exp, err := signature.ParseParams(tt.sig, tt.expStr)
|
||||
|
||||
if tt.wantErr {
|
||||
if err == nil {
|
||||
|
||||
Reference in New Issue
Block a user