123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156 |
- <?php
- /**
- * @author Lukas Reschke <lukas@owncloud.com>
- *
- * @copyright Copyright (c) 2016, ownCloud, Inc.
- * @license AGPL-3.0
- *
- * This code is free software: you can redistribute it and/or modify
- * it under the terms of the GNU Affero General Public License, version 3,
- * as published by the Free Software Foundation.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU Affero General Public License for more details.
- *
- * You should have received a copy of the GNU Affero General Public License, version 3,
- * along with this program. If not, see <http://www.gnu.org/licenses/>
- *
- */
- namespace Test\Security\CSRF;
- class CsrfTokenManagerTest extends \Test\TestCase {
- /** @var \OC\Security\CSRF\CsrfTokenManager */
- private $csrfTokenManager;
- /** @var \OC\Security\CSRF\CsrfTokenGenerator */
- private $tokenGenerator;
- /** @var \OC\Security\CSRF\TokenStorage\SessionStorage */
- private $storageInterface;
- public function setUp() {
- parent::setUp();
- $this->tokenGenerator = $this->getMockBuilder('\OC\Security\CSRF\CsrfTokenGenerator')
- ->disableOriginalConstructor()->getMock();
- $this->storageInterface = $this->getMockBuilder('\OC\Security\CSRF\TokenStorage\SessionStorage')
- ->disableOriginalConstructor()->getMock();
- $this->csrfTokenManager = new \OC\Security\CSRF\CsrfTokenManager(
- $this->tokenGenerator,
- $this->storageInterface
- );
- }
- public function testGetTokenWithExistingToken() {
- $this->storageInterface
- ->expects($this->once())
- ->method('hasToken')
- ->willReturn(true);
- $this->storageInterface
- ->expects($this->once())
- ->method('getToken')
- ->willReturn('MyExistingToken');
- $expected = new \OC\Security\CSRF\CsrfToken('MyExistingToken');
- $this->assertEquals($expected, $this->csrfTokenManager->getToken());
- }
- public function testGetTokenWithExistingTokenKeepsOnSecondRequest() {
- $this->storageInterface
- ->expects($this->once())
- ->method('hasToken')
- ->willReturn(true);
- $this->storageInterface
- ->expects($this->once())
- ->method('getToken')
- ->willReturn('MyExistingToken');
- $expected = new \OC\Security\CSRF\CsrfToken('MyExistingToken');
- $token = $this->csrfTokenManager->getToken();
- $this->assertSame($token, $this->csrfTokenManager->getToken());
- $this->assertSame($token, $this->csrfTokenManager->getToken());
- }
- public function testGetTokenWithoutExistingToken() {
- $this->storageInterface
- ->expects($this->once())
- ->method('hasToken')
- ->willReturn(false);
- $this->tokenGenerator
- ->expects($this->once())
- ->method('generateToken')
- ->willReturn('MyNewToken');
- $this->storageInterface
- ->expects($this->once())
- ->method('setToken')
- ->with('MyNewToken');
- $expected = new \OC\Security\CSRF\CsrfToken('MyNewToken');
- $this->assertEquals($expected, $this->csrfTokenManager->getToken());
- }
- public function testRefreshToken() {
- $this->tokenGenerator
- ->expects($this->once())
- ->method('generateToken')
- ->willReturn('MyNewToken');
- $this->storageInterface
- ->expects($this->once())
- ->method('setToken')
- ->with('MyNewToken');
- $expected = new \OC\Security\CSRF\CsrfToken('MyNewToken');
- $this->assertEquals($expected, $this->csrfTokenManager->refreshToken());
- }
- public function testRemoveToken() {
- $this->storageInterface
- ->expects($this->once())
- ->method('removeToken');
- $this->csrfTokenManager->removeToken();
- }
- public function testIsTokenValidWithoutToken() {
- $this->storageInterface
- ->expects($this->once())
- ->method('hasToken')
- ->willReturn(false);
- $token = new \OC\Security\CSRF\CsrfToken('Token');
- $this->assertSame(false, $this->csrfTokenManager->isTokenValid($token));
- }
- public function testIsTokenValidWithWrongToken() {
- $this->storageInterface
- ->expects($this->once())
- ->method('hasToken')
- ->willReturn(true);
- $token = new \OC\Security\CSRF\CsrfToken('Token');
- $this->storageInterface
- ->expects($this->once())
- ->method('getToken')
- ->willReturn('MyToken');
- $this->assertSame(false, $this->csrfTokenManager->isTokenValid($token));
- }
- public function testIsTokenValidWithValidToken() {
- $a = 'abc';
- $b = 'def';
- $xorB64 = 'BQcF';
- $tokenVal = sprintf('%s:%s', $xorB64, base64_encode($a));
- $this->storageInterface
- ->expects($this->once())
- ->method('hasToken')
- ->willReturn(true);
- $token = new \OC\Security\CSRF\CsrfToken($tokenVal);
- $this->storageInterface
- ->expects($this->once())
- ->method('getToken')
- ->willReturn($b);
- $this->assertSame(true, $this->csrfTokenManager->isTokenValid($token));
- }
- }
|