2017-05-25 20:09:29 +07:00
|
|
|
|
|
|
|
import sinon = require("sinon");
|
|
|
|
import BluebirdPromise = require("bluebird");
|
|
|
|
import assert = require("assert");
|
2017-10-07 05:09:42 +07:00
|
|
|
import U2FRegisterPost = require("../../../../../src/lib/routes/secondfactor/u2f/register/post");
|
2017-10-22 22:42:05 +07:00
|
|
|
import { AuthenticationSessionHandler } from "../../../../../src/lib/AuthenticationSessionHandler";
|
|
|
|
import { AuthenticationSession } from "../../../../../types/AuthenticationSession";
|
2017-05-25 20:09:29 +07:00
|
|
|
import ExpressMock = require("../../../../mocks/express");
|
2017-07-20 02:06:12 +07:00
|
|
|
import { UserDataStoreStub } from "../../../../mocks/storage/UserDataStoreStub";
|
2017-10-18 04:24:02 +07:00
|
|
|
import { ServerVariablesMockBuilder, ServerVariablesMock } from "../../../../mocks/ServerVariablesMockBuilder";
|
|
|
|
import { ServerVariables } from "../../../../../src/lib/ServerVariables";
|
|
|
|
|
2017-05-25 20:09:29 +07:00
|
|
|
|
|
|
|
describe("test u2f routes: register", function () {
|
|
|
|
let req: ExpressMock.RequestMock;
|
|
|
|
let res: ExpressMock.ResponseMock;
|
2017-10-18 04:24:02 +07:00
|
|
|
let mocks: ServerVariablesMock;
|
|
|
|
let vars: ServerVariables;
|
2017-10-22 22:42:05 +07:00
|
|
|
let authSession: AuthenticationSession;
|
2017-05-25 20:09:29 +07:00
|
|
|
|
|
|
|
beforeEach(function () {
|
|
|
|
req = ExpressMock.RequestMock();
|
2017-11-01 20:24:18 +07:00
|
|
|
req.originalUrl = "/api/xxxx";
|
2017-05-25 20:09:29 +07:00
|
|
|
req.app = {};
|
2017-10-18 04:24:02 +07:00
|
|
|
req.session = {
|
|
|
|
auth: {
|
|
|
|
userid: "user",
|
|
|
|
first_factor: true,
|
|
|
|
second_factor: false,
|
|
|
|
identity_check: {
|
|
|
|
challenge: "u2f-register",
|
|
|
|
userid: "user"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
};
|
2017-05-25 20:09:29 +07:00
|
|
|
req.headers = {};
|
|
|
|
req.headers.host = "localhost";
|
|
|
|
|
2017-10-18 04:24:02 +07:00
|
|
|
const s = ServerVariablesMockBuilder.build();
|
|
|
|
mocks = s.mocks;
|
|
|
|
vars = s.variables;
|
|
|
|
|
2017-05-25 20:09:29 +07:00
|
|
|
const options = {
|
|
|
|
inMemoryOnly: true
|
|
|
|
};
|
|
|
|
|
2017-07-20 02:06:12 +07:00
|
|
|
mocks.userDataStore.saveU2FRegistrationStub.returns(BluebirdPromise.resolve({}));
|
|
|
|
mocks.userDataStore.retrieveU2FRegistrationStub.returns(BluebirdPromise.resolve({}));
|
2017-05-25 20:09:29 +07:00
|
|
|
|
|
|
|
res = ExpressMock.ResponseMock();
|
|
|
|
res.send = sinon.spy();
|
|
|
|
res.json = sinon.spy();
|
|
|
|
res.status = sinon.spy();
|
2017-10-22 22:42:05 +07:00
|
|
|
|
|
|
|
authSession = AuthenticationSessionHandler.get(req as any, vars.logger);
|
2017-05-25 20:09:29 +07:00
|
|
|
});
|
|
|
|
|
|
|
|
describe("test registration", test_registration);
|
|
|
|
|
|
|
|
|
|
|
|
function test_registration() {
|
|
|
|
it("should save u2f meta and return status code 200", function () {
|
|
|
|
const expectedStatus = {
|
|
|
|
keyHandle: "keyHandle",
|
|
|
|
publicKey: "pbk",
|
|
|
|
certificate: "cert"
|
|
|
|
};
|
2017-10-18 04:24:02 +07:00
|
|
|
mocks.u2f.checkRegistrationStub.returns(BluebirdPromise.resolve(expectedStatus));
|
2017-09-22 03:07:34 +07:00
|
|
|
|
2017-10-22 22:42:05 +07:00
|
|
|
authSession.register_request = {
|
|
|
|
appId: "app",
|
|
|
|
challenge: "challenge",
|
|
|
|
keyHandle: "key",
|
|
|
|
version: "U2F_V2"
|
|
|
|
};
|
|
|
|
return U2FRegisterPost.default(vars)(req as any, res as any)
|
2017-05-25 20:09:29 +07:00
|
|
|
.then(function () {
|
2017-07-20 02:06:12 +07:00
|
|
|
assert.equal("user", mocks.userDataStore.saveU2FRegistrationStub.getCall(0).args[0]);
|
2017-05-25 20:09:29 +07:00
|
|
|
assert.equal(authSession.identity_check, undefined);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2017-10-11 04:03:30 +07:00
|
|
|
it("should return error message on finishRegistration error", function () {
|
2017-10-18 04:24:02 +07:00
|
|
|
mocks.u2f.checkRegistrationStub.returns({ errorCode: 500 });
|
2017-09-22 03:07:34 +07:00
|
|
|
|
2017-10-22 22:42:05 +07:00
|
|
|
authSession.register_request = {
|
|
|
|
appId: "app",
|
|
|
|
challenge: "challenge",
|
|
|
|
keyHandle: "key",
|
|
|
|
version: "U2F_V2"
|
|
|
|
};
|
|
|
|
|
|
|
|
return U2FRegisterPost.default(vars)(req as any, res as any)
|
2017-05-25 20:09:29 +07:00
|
|
|
.then(function () { return BluebirdPromise.reject(new Error("It should fail")); })
|
|
|
|
.catch(function () {
|
2017-10-11 04:03:30 +07:00
|
|
|
assert.equal(200, res.status.getCall(0).args[0]);
|
|
|
|
assert.deepEqual(res.send.getCall(0).args[0], {
|
|
|
|
error: "Operation failed."
|
|
|
|
});
|
2017-05-25 20:09:29 +07:00
|
|
|
return BluebirdPromise.resolve();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2017-10-11 04:03:30 +07:00
|
|
|
it("should return error message when register_request is not provided", function () {
|
2017-10-18 04:24:02 +07:00
|
|
|
mocks.u2f.checkRegistrationStub.returns(BluebirdPromise.resolve());
|
2017-10-22 22:42:05 +07:00
|
|
|
authSession.register_request = undefined;
|
|
|
|
return U2FRegisterPost.default(vars)(req as any, res as any)
|
2017-05-25 20:09:29 +07:00
|
|
|
.then(function () { return BluebirdPromise.reject(new Error("It should fail")); })
|
|
|
|
.catch(function () {
|
2017-10-11 04:03:30 +07:00
|
|
|
assert.equal(200, res.status.getCall(0).args[0]);
|
|
|
|
assert.deepEqual(res.send.getCall(0).args[0], {
|
|
|
|
error: "Operation failed."
|
|
|
|
});
|
2017-05-25 20:09:29 +07:00
|
|
|
return BluebirdPromise.resolve();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2017-10-11 04:03:30 +07:00
|
|
|
it("should return error message when no auth request has been initiated", function () {
|
2017-10-18 04:24:02 +07:00
|
|
|
mocks.u2f.checkRegistrationStub.returns(BluebirdPromise.resolve());
|
2017-10-22 22:42:05 +07:00
|
|
|
authSession.register_request = undefined;
|
|
|
|
return U2FRegisterPost.default(vars)(req as any, res as any)
|
2017-05-25 20:09:29 +07:00
|
|
|
.then(function () { return BluebirdPromise.reject(new Error("It should fail")); })
|
|
|
|
.catch(function () {
|
2017-10-11 04:03:30 +07:00
|
|
|
assert.equal(200, res.status.getCall(0).args[0]);
|
|
|
|
assert.deepEqual(res.send.getCall(0).args[0], {
|
|
|
|
error: "Operation failed."
|
|
|
|
});
|
2017-05-25 20:09:29 +07:00
|
|
|
return BluebirdPromise.resolve();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2017-10-11 04:03:30 +07:00
|
|
|
it("should return error message when identity has not been verified", function () {
|
2017-10-22 22:42:05 +07:00
|
|
|
authSession.identity_check = undefined;
|
|
|
|
return U2FRegisterPost.default(vars)(req as any, res as any)
|
2017-05-25 20:09:29 +07:00
|
|
|
.then(function () { return BluebirdPromise.reject(new Error("It should fail")); })
|
|
|
|
.catch(function () {
|
2017-10-11 04:03:30 +07:00
|
|
|
assert.equal(200, res.status.getCall(0).args[0]);
|
|
|
|
assert.deepEqual(res.send.getCall(0).args[0], {
|
|
|
|
error: "Operation failed."
|
|
|
|
});
|
2017-05-25 20:09:29 +07:00
|
|
|
return BluebirdPromise.resolve();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
}
|
|
|
|
});
|
|
|
|
|