fix: 统一对话密码锁键为发送方加对方不含 IP
This commit is contained in:
@@ -501,6 +501,98 @@ func TestAdminDisableDeleteHTTP(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestU03AdminTalkPasswordHTTP(t *testing.T) {
|
||||
t.Parallel()
|
||||
dir := t.TempDir()
|
||||
db, err := store.Open(filepath.Join(dir, "data"), "FULL")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Cleanup(func() { _ = db.Close() })
|
||||
|
||||
fixed := time.UnixMilli(1_700_000_000_000)
|
||||
hash := auth.NewStubHashPool()
|
||||
if seedErr := admin.SeedAdminPassword(context.Background(), db, hash, "adminpassword1"); seedErr != nil {
|
||||
t.Fatal(seedErr)
|
||||
}
|
||||
locks := auth.NewLoginLocks()
|
||||
locks.SetClock(func() time.Time { return fixed })
|
||||
idApp := identity.New(identity.Config{
|
||||
DB: db, Hash: hash, Locks: locks, Sessions: auth.NewSessionTokens(),
|
||||
MaxScheduleSeconds: 86400, Now: func() time.Time { return fixed },
|
||||
})
|
||||
h := admin.New(admin.Deps{
|
||||
DB: db, Hash: hash, Tokens: admin.NewRandomAPITokens(),
|
||||
Locks: locks, Identity: idApp,
|
||||
})
|
||||
srv := httptest.NewServer(h)
|
||||
t.Cleanup(srv.Close)
|
||||
|
||||
jar, _ := cookiejar.New(nil)
|
||||
client := &http.Client{Jar: jar}
|
||||
loginRes, err := client.Post(srv.URL+"/api/admin/login", "application/json",
|
||||
strings.NewReader(`{"username":"admin","password":"adminpassword1"}`))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
_ = loginRes.Body.Close()
|
||||
if loginRes.StatusCode != 200 {
|
||||
t.Fatalf("login %d", loginRes.StatusCode)
|
||||
}
|
||||
|
||||
req, _ := http.NewRequest(http.MethodPost, srv.URL+"/api/admin/endpoints",
|
||||
strings.NewReader(`{"id":"alice","name":"alice","login_password":"password12"}`))
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
req.Header.Set("X-Nixmsg-Request", "1")
|
||||
res, err := client.Do(req)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
raw, _ := io.ReadAll(res.Body)
|
||||
_ = res.Body.Close()
|
||||
if res.StatusCode != 200 {
|
||||
t.Fatalf("create: %d %s", res.StatusCode, raw)
|
||||
}
|
||||
|
||||
for i := 0; i < 50; i++ {
|
||||
locks.Fail(auth.LockKey{Kind: auth.LockTalkTarget, EndpointID: "alice"})
|
||||
}
|
||||
if locked, _ := locks.Check(auth.LockKey{Kind: auth.LockTalkTarget, EndpointID: "alice"}); !locked {
|
||||
t.Fatal("expected target lock")
|
||||
}
|
||||
|
||||
req, _ = http.NewRequest(http.MethodPut, srv.URL+"/api/admin/endpoints/alice/talk-password",
|
||||
strings.NewReader(`{"talk_password":"secret"}`))
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
req.Header.Set("X-Nixmsg-Request", "1")
|
||||
res, err = client.Do(req)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
raw, _ = io.ReadAll(res.Body)
|
||||
_ = res.Body.Close()
|
||||
if res.StatusCode != 200 {
|
||||
t.Fatalf("talk-password: %d %s", res.StatusCode, raw)
|
||||
}
|
||||
if locked, _ := locks.Check(auth.LockKey{Kind: auth.LockTalkTarget, EndpointID: "alice"}); locked {
|
||||
t.Fatal("identity SelfSetTalkPassword should clear LockTalkTarget")
|
||||
}
|
||||
|
||||
req, _ = http.NewRequest(http.MethodPut, srv.URL+"/api/admin/endpoints/missing/talk-password",
|
||||
strings.NewReader(`{"talk_password":"secret"}`))
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
req.Header.Set("X-Nixmsg-Request", "1")
|
||||
res, err = client.Do(req)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
raw, _ = io.ReadAll(res.Body)
|
||||
_ = res.Body.Close()
|
||||
if res.StatusCode != http.StatusNotFound {
|
||||
t.Fatalf("missing endpoint want 404 got %d %s", res.StatusCode, raw)
|
||||
}
|
||||
}
|
||||
|
||||
type lifecycleKick struct {
|
||||
Calls []string
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user