2019-04-25 04:52:08 +07:00
|
|
|
package handlers
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"testing"
|
|
|
|
|
2019-12-24 09:14:52 +07:00
|
|
|
"github.com/authelia/authelia/internal/mocks"
|
|
|
|
"github.com/authelia/authelia/internal/models"
|
2019-04-25 04:52:08 +07:00
|
|
|
|
2019-12-24 09:14:52 +07:00
|
|
|
"github.com/authelia/authelia/internal/authentication"
|
2019-04-25 04:52:08 +07:00
|
|
|
"github.com/golang/mock/gomock"
|
|
|
|
"github.com/sirupsen/logrus"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"github.com/stretchr/testify/suite"
|
|
|
|
)
|
|
|
|
|
|
|
|
type FirstFactorSuite struct {
|
|
|
|
suite.Suite
|
|
|
|
|
|
|
|
mock *mocks.MockAutheliaCtx
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *FirstFactorSuite) SetupTest() {
|
|
|
|
s.mock = mocks.NewMockAutheliaCtx(s.T())
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *FirstFactorSuite) TearDownTest() {
|
|
|
|
s.mock.Close()
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *FirstFactorSuite) assertError500(err string) {
|
|
|
|
assert.Equal(s.T(), 500, s.mock.Ctx.Response.StatusCode())
|
|
|
|
assert.Equal(s.T(), []byte(InternalError), s.mock.Ctx.Response.Body())
|
|
|
|
assert.Equal(s.T(), err, s.mock.Hook.LastEntry().Message)
|
|
|
|
assert.Equal(s.T(), logrus.ErrorLevel, s.mock.Hook.LastEntry().Level)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *FirstFactorSuite) TestShouldFailIfBodyIsNil() {
|
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
|
|
|
|
// No body
|
|
|
|
assert.Equal(s.T(), "Unable to parse body: unexpected end of JSON input", s.mock.Hook.LastEntry().Message)
|
|
|
|
s.mock.Assert200KO(s.T(), "Authentication failed. Check your credentials.")
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *FirstFactorSuite) TestShouldFailIfBodyIsInBadFormat() {
|
|
|
|
// Missing password
|
|
|
|
s.mock.Ctx.Request.SetBodyString(`{
|
|
|
|
"username": "test"
|
|
|
|
}`)
|
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
|
|
|
|
assert.Equal(s.T(), "Unable to validate body: password: non zero value required", s.mock.Hook.LastEntry().Message)
|
|
|
|
s.mock.Assert200KO(s.T(), "Authentication failed. Check your credentials.")
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *FirstFactorSuite) TestShouldFailIfUserProviderCheckPasswordFail() {
|
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
CheckUserPassword(gomock.Eq("test"), gomock.Eq("hello")).
|
|
|
|
Return(false, fmt.Errorf("Failed"))
|
|
|
|
|
2019-11-30 21:33:45 +07:00
|
|
|
s.mock.StorageProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
AppendAuthenticationLog(gomock.Eq(models.AuthenticationAttempt{
|
|
|
|
Username: "test",
|
|
|
|
Successful: false,
|
|
|
|
Time: s.mock.Clock.Now(),
|
|
|
|
}))
|
|
|
|
|
2019-04-25 04:52:08 +07:00
|
|
|
s.mock.Ctx.Request.SetBodyString(`{
|
|
|
|
"username": "test",
|
|
|
|
"password": "hello",
|
|
|
|
"keepMeLoggedIn": true
|
|
|
|
}`)
|
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
|
|
|
|
assert.Equal(s.T(), "Error while checking password for user test: Failed", s.mock.Hook.LastEntry().Message)
|
|
|
|
s.mock.Assert200KO(s.T(), "Authentication failed. Check your credentials.")
|
|
|
|
}
|
|
|
|
|
2019-11-25 03:27:59 +07:00
|
|
|
func (s *FirstFactorSuite) TestShouldCheckAuthenticationIsMarkedWhenInvalidCredentials() {
|
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
CheckUserPassword(gomock.Eq("test"), gomock.Eq("hello")).
|
|
|
|
Return(false, fmt.Errorf("Invalid credentials"))
|
|
|
|
|
|
|
|
s.mock.StorageProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
AppendAuthenticationLog(gomock.Eq(models.AuthenticationAttempt{
|
|
|
|
Username: "test",
|
|
|
|
Successful: false,
|
2019-11-30 21:33:45 +07:00
|
|
|
Time: s.mock.Clock.Now(),
|
2019-11-25 03:27:59 +07:00
|
|
|
}))
|
|
|
|
|
|
|
|
s.mock.Ctx.Request.SetBodyString(`{
|
|
|
|
"username": "test",
|
|
|
|
"password": "hello",
|
|
|
|
"keepMeLoggedIn": true
|
|
|
|
}`)
|
|
|
|
|
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
}
|
|
|
|
|
2019-04-25 04:52:08 +07:00
|
|
|
func (s *FirstFactorSuite) TestShouldFailIfUserProviderGetDetailsFail() {
|
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
CheckUserPassword(gomock.Eq("test"), gomock.Eq("hello")).
|
|
|
|
Return(true, nil)
|
|
|
|
|
|
|
|
s.mock.StorageProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
AppendAuthenticationLog(gomock.Any()).
|
|
|
|
Return(nil)
|
|
|
|
|
2019-11-30 21:33:45 +07:00
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
GetDetails(gomock.Eq("test")).
|
|
|
|
Return(nil, fmt.Errorf("Failed"))
|
|
|
|
|
2019-04-25 04:52:08 +07:00
|
|
|
s.mock.Ctx.Request.SetBodyString(`{
|
|
|
|
"username": "test",
|
|
|
|
"password": "hello",
|
|
|
|
"keepMeLoggedIn": true
|
|
|
|
}`)
|
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
|
|
|
|
assert.Equal(s.T(), "Error while retrieving details from user test: Failed", s.mock.Hook.LastEntry().Message)
|
|
|
|
s.mock.Assert200KO(s.T(), "Authentication failed. Check your credentials.")
|
|
|
|
}
|
|
|
|
|
2019-11-30 21:33:45 +07:00
|
|
|
func (s *FirstFactorSuite) TestShouldFailIfAuthenticationMarkFail() {
|
2019-04-25 04:52:08 +07:00
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
CheckUserPassword(gomock.Eq("test"), gomock.Eq("hello")).
|
|
|
|
Return(true, nil)
|
|
|
|
|
|
|
|
s.mock.StorageProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
AppendAuthenticationLog(gomock.Any()).
|
|
|
|
Return(fmt.Errorf("failed"))
|
|
|
|
|
|
|
|
s.mock.Ctx.Request.SetBodyString(`{
|
|
|
|
"username": "test",
|
|
|
|
"password": "hello",
|
|
|
|
"keepMeLoggedIn": true
|
|
|
|
}`)
|
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
|
|
|
|
assert.Equal(s.T(), "Unable to mark authentication: failed", s.mock.Hook.LastEntry().Message)
|
|
|
|
s.mock.Assert200KO(s.T(), "Authentication failed. Check your credentials.")
|
|
|
|
}
|
|
|
|
|
2020-01-18 05:48:48 +07:00
|
|
|
func (s *FirstFactorSuite) TestShouldAuthenticateUserWithRememberMeChecked() {
|
2019-04-25 04:52:08 +07:00
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
CheckUserPassword(gomock.Eq("test"), gomock.Eq("hello")).
|
|
|
|
Return(true, nil)
|
|
|
|
|
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
GetDetails(gomock.Eq("test")).
|
|
|
|
Return(&authentication.UserDetails{
|
|
|
|
Emails: []string{"test@example.com"},
|
2019-11-30 23:49:52 +07:00
|
|
|
Groups: []string{"dev", "admins"},
|
2019-04-25 04:52:08 +07:00
|
|
|
}, nil)
|
|
|
|
|
|
|
|
s.mock.StorageProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
AppendAuthenticationLog(gomock.Any()).
|
|
|
|
Return(nil)
|
|
|
|
|
|
|
|
s.mock.Ctx.Request.SetBodyString(`{
|
2020-01-18 05:48:48 +07:00
|
|
|
"username": "test",
|
|
|
|
"password": "hello",
|
|
|
|
"keepMeLoggedIn": true
|
|
|
|
}`)
|
2019-04-25 04:52:08 +07:00
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
|
|
|
|
// Respond with 200.
|
|
|
|
assert.Equal(s.T(), 200, s.mock.Ctx.Response.StatusCode())
|
|
|
|
assert.Equal(s.T(), []byte("{\"status\":\"OK\"}"), s.mock.Ctx.Response.Body())
|
|
|
|
|
|
|
|
// And store authentication in session.
|
|
|
|
session := s.mock.Ctx.GetSession()
|
|
|
|
assert.Equal(s.T(), "test", session.Username)
|
2020-01-18 05:48:48 +07:00
|
|
|
assert.Equal(s.T(), true, session.KeepMeLoggedIn)
|
2019-04-25 04:52:08 +07:00
|
|
|
assert.Equal(s.T(), authentication.OneFactor, session.AuthenticationLevel)
|
|
|
|
assert.Equal(s.T(), []string{"test@example.com"}, session.Emails)
|
2019-11-30 23:49:52 +07:00
|
|
|
assert.Equal(s.T(), []string{"dev", "admins"}, session.Groups)
|
2020-01-18 05:48:48 +07:00
|
|
|
}
|
|
|
|
|
|
|
|
func (s *FirstFactorSuite) TestShouldAuthenticateUserWithRememberMeUnchecked() {
|
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
CheckUserPassword(gomock.Eq("test"), gomock.Eq("hello")).
|
|
|
|
Return(true, nil)
|
|
|
|
|
|
|
|
s.mock.UserProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
GetDetails(gomock.Eq("test")).
|
|
|
|
Return(&authentication.UserDetails{
|
|
|
|
Emails: []string{"test@example.com"},
|
|
|
|
Groups: []string{"dev", "admins"},
|
|
|
|
}, nil)
|
2019-04-25 04:52:08 +07:00
|
|
|
|
2020-01-18 05:48:48 +07:00
|
|
|
s.mock.StorageProviderMock.
|
|
|
|
EXPECT().
|
|
|
|
AppendAuthenticationLog(gomock.Any()).
|
|
|
|
Return(nil)
|
|
|
|
|
|
|
|
s.mock.Ctx.Request.SetBodyString(`{
|
|
|
|
"username": "test",
|
|
|
|
"password": "hello",
|
|
|
|
"keepMeLoggedIn": false
|
|
|
|
}`)
|
|
|
|
FirstFactorPost(s.mock.Ctx)
|
|
|
|
|
|
|
|
// Respond with 200.
|
|
|
|
assert.Equal(s.T(), 200, s.mock.Ctx.Response.StatusCode())
|
|
|
|
assert.Equal(s.T(), []byte("{\"status\":\"OK\"}"), s.mock.Ctx.Response.Body())
|
|
|
|
|
|
|
|
// And store authentication in session.
|
|
|
|
session := s.mock.Ctx.GetSession()
|
|
|
|
assert.Equal(s.T(), "test", session.Username)
|
|
|
|
assert.Equal(s.T(), false, session.KeepMeLoggedIn)
|
|
|
|
assert.Equal(s.T(), authentication.OneFactor, session.AuthenticationLevel)
|
|
|
|
assert.Equal(s.T(), []string{"test@example.com"}, session.Emails)
|
|
|
|
assert.Equal(s.T(), []string{"dev", "admins"}, session.Groups)
|
2019-04-25 04:52:08 +07:00
|
|
|
}
|
|
|
|
|
|
|
|
func TestFirstFactorSuite(t *testing.T) {
|
|
|
|
firstFactorSuite := new(FirstFactorSuite)
|
|
|
|
suite.Run(t, firstFactorSuite)
|
|
|
|
}
|