27 lines
944 B
Python
27 lines
944 B
Python
import base64
|
|
|
|
import pytest
|
|
|
|
from memrelay.errors import AppError
|
|
from memrelay.security import SecretBox, load_or_create_master_key, token_digest
|
|
|
|
|
|
def test_master_key_is_persisted_and_secrets_are_context_bound(tmp_path) -> None:
|
|
path = tmp_path / "config" / "master.key"
|
|
first = load_or_create_master_key(path)
|
|
second = load_or_create_master_key(path)
|
|
assert first == second
|
|
assert len(base64.urlsafe_b64decode(path.read_bytes())) == 32
|
|
|
|
box = SecretBox(first)
|
|
encrypted = box.encrypt("private-value", "vault")
|
|
assert "private-value" not in encrypted
|
|
assert box.decrypt(encrypted, "vault") == "private-value"
|
|
with pytest.raises(AppError, match="加密数据无法解密"):
|
|
box.decrypt(encrypted, "other-context")
|
|
|
|
|
|
def test_token_digest_is_stable_without_storing_plaintext() -> None:
|
|
assert token_digest("abc") == token_digest("abc")
|
|
assert token_digest("abc") != token_digest("abcd")
|