Protocol: freeze device proof and browser CSRF contracts
This commit is contained in:
@@ -2,6 +2,7 @@ package protocol_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/hex"
|
||||
"reflect"
|
||||
"strings"
|
||||
"testing"
|
||||
@@ -9,6 +10,45 @@ import (
|
||||
protocol "git.sechmachine.io.vn/sechmachine/VerseVDI-Protocol/gen/go/protocol"
|
||||
)
|
||||
|
||||
func TestDeviceRegistrationProofTranscriptIsCanonicalAndStrict(t *testing.T) {
|
||||
serverID, _ := hex.DecodeString("00112233445566778899aabbccddeeff")
|
||||
principalID, _ := hex.DecodeString("102132435465768798a9bacbdcedfe0f")
|
||||
deviceID, _ := hex.DecodeString("ffeeddccbbaa99887766554433221100")
|
||||
challenge, _ := hex.DecodeString("000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f")
|
||||
want, _ := hex.DecodeString("76657273657664692d6465766963652d70726f6f662d763100112233445566778899aabbccddeeff102132435465768798a9bacbdcedfe0fffeeddccbbaa99887766554433221100000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f0000018bcfe5687b")
|
||||
|
||||
got, err := protocol.DeviceRegistrationProofTranscript(serverID, principalID, deviceID, challenge, 1700000000123)
|
||||
if err != nil || !bytes.Equal(got, want) {
|
||||
t.Fatalf("DeviceRegistrationProofTranscript() = %x, %v; want %x", got, err, want)
|
||||
}
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
serverID, principalID, deviceID, challenge []byte
|
||||
expiry int64
|
||||
field, code string
|
||||
}{
|
||||
{"server-short", serverID[:15], principalID, deviceID, challenge, 0, "server_id", "invalid_length"},
|
||||
{"server-long", append(append([]byte(nil), serverID...), 0), principalID, deviceID, challenge, 0, "server_id", "invalid_length"},
|
||||
{"principal-short", serverID, principalID[:15], deviceID, challenge, 0, "principal_id", "invalid_length"},
|
||||
{"principal-long", serverID, append(append([]byte(nil), principalID...), 0), deviceID, challenge, 0, "principal_id", "invalid_length"},
|
||||
{"device-short", serverID, principalID, deviceID[:15], challenge, 0, "device_id", "invalid_length"},
|
||||
{"device-long", serverID, principalID, append(append([]byte(nil), deviceID...), 0), challenge, 0, "device_id", "invalid_length"},
|
||||
{"challenge-short", serverID, principalID, deviceID, challenge[:31], 0, "challenge", "invalid_length"},
|
||||
{"challenge-long", serverID, principalID, deviceID, append(append([]byte(nil), challenge...), 0), 0, "challenge", "invalid_length"},
|
||||
{"negative-expiry", serverID, principalID, deviceID, challenge, -1, "expiry_unix_milliseconds", "minimum"},
|
||||
}
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
_, err := protocol.DeviceRegistrationProofTranscript(test.serverID, test.principalID, test.deviceID, test.challenge, test.expiry)
|
||||
validation, ok := err.(protocol.ValidationError)
|
||||
if !ok || len(validation.Violations) != 1 || validation.Violations[0] != (protocol.FieldViolation{Field: test.field, Code: test.code}) {
|
||||
t.Fatalf("error = %#v; want %s/%s validation error", err, test.field, test.code)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestManifestRejectsForbiddenAndUnknownFields(t *testing.T) {
|
||||
valid := `{"version":"1","purpose":"launch","session_id":"session-1","reconnect_sequence":0,"gateway":{"id":"gateway-1","addresses":["gateway.control.test:443"],"public_identity":"gateway.control.test"},"tunnel":{"versions":["verse-gateway-v1/1"],"features":["control.v1"]},"profile":{"id":"standard","bounds":{"minimum_kbps":1,"target_kbps":2,"maximum_kbps":3}},"grant":{"opaque_value":"opaque-one-time-grant-value-with-at-least-43-bytes","expires_at":"2099-01-01T00:00:00Z","audience":"versevdi-gateway"},"correlation_id":"correlation-1"}`
|
||||
manifest, err := protocol.DecodeConnectionManifest([]byte(valid))
|
||||
|
||||
Reference in New Issue
Block a user