check / check (push) Successful in 12s
The signed data is now host:path:query:width:height:format:expiration:quality:fit. The route turns a missing q into 85 and a missing fit into cover before checking the signature, so those are the values signed for a URL without them; imgcache fills both from the parsed request. imgcache.Service.GenerateSignedURL now writes q and fit into the URL next to sig and exp, first setting an unset quality or fit to 85 or cover, so a generated URL verifies for the values it signed. The known-answer vectors in golden_test.go, including one for quality 40 and fit contain, and the README signature section describe the new format. Model: opus-4-8 (implementation); opus-5-5 (rework)
146 lines
4.3 KiB
Go
146 lines
4.3 KiB
Go
package signature_test
|
|
|
|
import (
|
|
"testing"
|
|
"time"
|
|
|
|
"sneak.berlin/go/pixa/internal/signature"
|
|
)
|
|
|
|
// goldenExpiresUnix is the fixed expiration timestamp used by all golden
|
|
// vectors: 2024-01-01T00:00:00Z.
|
|
const goldenExpiresUnix int64 = 1704067200
|
|
|
|
// goldenSigningKey is the fixed signing key used by all golden vectors.
|
|
const goldenSigningKey = "golden-test-key"
|
|
|
|
type goldenVector struct {
|
|
name string
|
|
req signature.Request
|
|
// wantSignature is the exact base64url (RFC 4648 URL-safe,
|
|
// padded) HMAC-SHA256 signature for the request with Expires
|
|
// set to goldenExpiresUnix.
|
|
wantSignature string
|
|
// wantSignedPath is the exact path returned by
|
|
// GenerateSignedURL for the request. The signature and
|
|
// expiration are returned separately by GenerateSignedURL and
|
|
// are not embedded in the path.
|
|
wantSignedPath string
|
|
}
|
|
|
|
// goldenVectors returns the known-answer vectors. The expected values
|
|
// were computed once and are hardcoded here.
|
|
func goldenVectors() []goldenVector {
|
|
return []goldenVector{
|
|
{
|
|
name: "resized without query",
|
|
req: signature.Request{
|
|
SourceHost: testHost,
|
|
SourcePath: testPath,
|
|
SourceQuery: "",
|
|
Width: 800,
|
|
Height: 600,
|
|
Format: testFormatWebP,
|
|
Quality: 85,
|
|
FitMode: testFitCover,
|
|
},
|
|
// Signed data:
|
|
// "cdn.example.com:/photos/cat.jpg::800:600:webp:1704067200:85:cover"
|
|
wantSignature: "kdqeGoW2SX7qnaYtoB970wEnLydn0UnIgQYQLfAnjXQ=",
|
|
wantSignedPath: testSignedPath,
|
|
},
|
|
{
|
|
name: "resized with query string",
|
|
req: signature.Request{
|
|
SourceHost: testHost,
|
|
SourcePath: testPath,
|
|
SourceQuery: "token=abc&v=2",
|
|
Width: 800,
|
|
Height: 600,
|
|
Format: testFormatWebP,
|
|
Quality: 85,
|
|
FitMode: testFitCover,
|
|
},
|
|
// Signed data:
|
|
// "cdn.example.com:/photos/cat.jpg:token=abc&v=2:800:600:webp:1704067200:85:cover"
|
|
wantSignature: "pKgVBOTd_Q_EikI7MNQLC9Q8Hurdxzyv3EIYvVhqc2I=",
|
|
wantSignedPath: "/v1/image/cdn.example.com/photos/cat.jpg" +
|
|
"%3Ftoken=abc&v=2/800x600.webp",
|
|
},
|
|
{
|
|
name: "original size without query",
|
|
req: signature.Request{
|
|
SourceHost: testHost,
|
|
SourcePath: testPath,
|
|
SourceQuery: "",
|
|
Width: 0,
|
|
Height: 0,
|
|
Format: testFormatPNG,
|
|
Quality: 85,
|
|
FitMode: testFitCover,
|
|
},
|
|
// Signed data:
|
|
// "cdn.example.com:/photos/cat.jpg::0:0:png:1704067200:85:cover"
|
|
wantSignature: "6_rZ0yyVbGZRs8kG7n7HLgLi5Jt8vjiWQljIEL1jbIs=",
|
|
wantSignedPath: "/v1/image/cdn.example.com/photos/cat.jpg/orig.png",
|
|
},
|
|
{
|
|
name: "non-default quality and fit",
|
|
req: signature.Request{
|
|
SourceHost: testHost,
|
|
SourcePath: testPath,
|
|
SourceQuery: "",
|
|
Width: 800,
|
|
Height: 600,
|
|
Format: testFormatWebP,
|
|
Quality: 40,
|
|
FitMode: testFitContain,
|
|
},
|
|
// Signed data:
|
|
// "cdn.example.com:/photos/cat.jpg::800:600:webp:1704067200:40:contain"
|
|
wantSignature: "pGaXpPUbI3A7nMx-4T9bfq9bYWBNL0kY4bxlcv3g1F8=",
|
|
// The path is the same as for the default quality and fit:
|
|
// q=40&fit=contain go in the query string next to sig and
|
|
// exp (imgcache.Service.GenerateSignedURL adds all four).
|
|
wantSignedPath: testSignedPath,
|
|
},
|
|
}
|
|
}
|
|
|
|
// TestSigner_GoldenVectors pins the exact HMAC-SHA256 signature output and
|
|
// the exact generated signed URL path for fully-specified requests with a
|
|
// hardcoded signing key.
|
|
//
|
|
// If any of these assertions fail, the signed byte format
|
|
// ("host:path:query:width:height:format:expiration:quality:fit"), the
|
|
// base64url encoding, or the signed URL layout has changed. Update these
|
|
// constants only when that change is intended.
|
|
func TestSigner_GoldenVectors(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
signer := signature.New(goldenSigningKey)
|
|
|
|
for _, tt := range goldenVectors() {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
signReq := tt.req
|
|
signReq.Expires = time.Unix(goldenExpiresUnix, 0)
|
|
|
|
gotSignature := signer.Sign(&signReq)
|
|
if gotSignature != tt.wantSignature {
|
|
t.Errorf("Sign() = %q, want %q (signed byte format changed?)",
|
|
gotSignature, tt.wantSignature)
|
|
}
|
|
|
|
urlReq := tt.req
|
|
|
|
gotPath, _, _ := signer.GenerateSignedURL(&urlReq, time.Hour)
|
|
if gotPath != tt.wantSignedPath {
|
|
t.Errorf("GenerateSignedURL() path = %q, want %q (signed URL layout changed?)",
|
|
gotPath, tt.wantSignedPath)
|
|
}
|
|
})
|
|
}
|
|
}
|