check / check (push) Failing after 3s
New tests only. MetricsAuth on its own answers 401 with a challenge without credentials or with a wrong username or password, and lets the configured ones through. A CORS preflight request gets the same Access-Control-Allow-Origin as a GET. A POST / carrying the signing key leaves the key out of the request log line, and the login handler's own log lines leave out the submitted key. The metrics middleware on its own records a request it served; the router records nothing while no metrics username is set. Not tested through the router: the basic auth in front of /metrics and recording with a metrics username set (#180). The pinned basicauth-go compares the password in constant time. Model: opus-5-5
60 lines
1.4 KiB
Go
60 lines
1.4 KiB
Go
package handlers
|
|
|
|
import (
|
|
"bytes"
|
|
"log/slog"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"net/url"
|
|
"strings"
|
|
"testing"
|
|
|
|
"sneak.berlin/go/pixa/internal/config"
|
|
"sneak.berlin/go/pixa/internal/session"
|
|
)
|
|
|
|
// TestLoginLogLeavesOutSubmittedKey verifies that the log lines for a
|
|
// failed and for a successful login do not contain the submitted key.
|
|
func TestLoginLogLeavesOutSubmittedKey(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
const wrongKey = "wrong-signing-key-fedcba9876543210"
|
|
|
|
var buf bytes.Buffer
|
|
|
|
sessMgr, err := session.NewManager(testSigningKey)
|
|
if err != nil {
|
|
t.Fatalf("session.NewManager() error = %v", err)
|
|
}
|
|
|
|
h := &Handlers{
|
|
log: slog.New(slog.NewJSONHandler(&buf, nil)),
|
|
config: &config.Config{SigningKey: testSigningKey},
|
|
sessMgr: sessMgr,
|
|
}
|
|
|
|
submittedKeys := []string{wrongKey, testSigningKey}
|
|
|
|
for _, key := range submittedKeys {
|
|
form := url.Values{loginKeyField: {key}}
|
|
req := httptest.NewRequestWithContext(
|
|
t.Context(), http.MethodPost, "/",
|
|
strings.NewReader(form.Encode()))
|
|
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
|
|
|
|
h.handleLoginPost(httptest.NewRecorder(), req)
|
|
}
|
|
|
|
for _, msg := range []string{"failed login attempt", "successful login"} {
|
|
if !strings.Contains(buf.String(), msg) {
|
|
t.Fatalf("log missing %q; got %q", msg, buf.String())
|
|
}
|
|
}
|
|
|
|
for _, key := range submittedKeys {
|
|
if strings.Contains(buf.String(), key) {
|
|
t.Errorf("log contains submitted key %q; got %q", key, buf.String())
|
|
}
|
|
}
|
|
}
|