CsrfTokenTest.php 1.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. <?php
  2. /**
  3. * @author Lukas Reschke <lukas@owncloud.com>
  4. *
  5. * @copyright Copyright (c) 2016, ownCloud, Inc.
  6. * @license AGPL-3.0
  7. *
  8. * This code is free software: you can redistribute it and/or modify
  9. * it under the terms of the GNU Affero General Public License, version 3,
  10. * as published by the Free Software Foundation.
  11. *
  12. * This program is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. * GNU Affero General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU Affero General Public License, version 3,
  18. * along with this program. If not, see <http://www.gnu.org/licenses/>
  19. *
  20. */
  21. namespace Test\Security\CSRF;
  22. class CsrfTokenTest extends \Test\TestCase {
  23. public function testGetEncryptedValue() {
  24. $csrfToken = new \OC\Security\CSRF\CsrfToken('MyCsrfToken');
  25. $this->assertSame(33, strlen($csrfToken->getEncryptedValue()));
  26. $this->assertSame(':', $csrfToken->getEncryptedValue()[16]);
  27. }
  28. public function testGetEncryptedValueStaysSameOnSecondRequest() {
  29. $csrfToken = new \OC\Security\CSRF\CsrfToken('MyCsrfToken');
  30. $tokenValue = $csrfToken->getEncryptedValue();
  31. $this->assertSame($tokenValue, $csrfToken->getEncryptedValue());
  32. $this->assertSame($tokenValue, $csrfToken->getEncryptedValue());
  33. }
  34. public function testGetDecryptedValue() {
  35. $a = 'abc';
  36. $b = 'def';
  37. $xorB64 = 'BQcF';
  38. $tokenVal = sprintf('%s:%s', $xorB64, base64_encode($a));
  39. $csrfToken = new \OC\Security\CSRF\CsrfToken($tokenVal);
  40. $this->assertSame($b, $csrfToken->getDecryptedValue());
  41. }
  42. }