-
Notifications
You must be signed in to change notification settings - Fork 1
/
main_test.go
73 lines (55 loc) · 1.76 KB
/
main_test.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
package main
import (
"bytes"
"crypto/hmac"
"crypto/sha256"
"encoding/base64"
"encoding/json"
"github.com/stretchr/testify/assert"
"strings"
"testing"
)
var testBody = `payload`
func TestGithubSecret(t *testing.T) {
if checkGithubSig("123", "sha256=5908ccfcc78e69944fd954f569473d5cf65ad2a9dc52056fea7e814b133dbad2", []byte(testBody)) {
t.Logf("Github token check ok")
} else {
t.Fatalf("Github sig check failed")
}
}
func MarshalSigned(v any, secret []byte) (string, error) {
hasher := hmac.New(sha256.New, secret)
header, _ := json.Marshal(map[string]string{
"alg": "HS256",
"typ": "JWT",
})
payload, err := json.Marshal(v)
if err != nil {
return "", err
}
headerB64 := base64.RawURLEncoding.EncodeToString(header)
payloadB64 := base64.RawURLEncoding.EncodeToString(payload)
hasher.Write(bytes.Join([][]byte{[]byte(headerB64), []byte(payloadB64)}, []byte(".")))
signature := hasher.Sum(nil)
sigB64 := base64.RawURLEncoding.EncodeToString(signature)
jwt := strings.Join([]string{
headerB64, payloadB64, sigB64,
}, ".")
return jwt, nil
}
func TestJwt(t *testing.T) {
token, _ := MarshalSigned(map[string]string{"grp": "root"}, []byte("shared_secret"))
Cfg.JwtHmac = "shared_secret"
Cfg.JwtClaimAny = []string{"root"}
Cfg.JwtClaim = "grp"
assert.Equal(t, true, checkJwt("Bearer "+token))
Cfg.JwtClaimAny = []string{"admin"}
assert.Equal(t, false, checkJwt("Bearer "+token))
Cfg.JwtClaimAny = []string{""}
assert.Equal(t, false, checkJwt("Bearer "+token))
Cfg.JwtClaimAny = []string{}
assert.Equal(t, false, checkJwt("Bearer "+token))
assert.Equal(t, false, checkJwt("Bearer random string"))
token, _ = MarshalSigned(map[string]string{"noclaim": "root"}, []byte("shared_secret"))
assert.Equal(t, false, checkJwt("Bearer "+token))
}