SignerTest.php 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * SPDX-FileCopyrightText: 2016 Nextcloud GmbH and Nextcloud contributors
  5. * SPDX-License-Identifier: AGPL-3.0-or-later
  6. */
  7. namespace Test\Security\IdentityProof;
  8. use OC\Security\IdentityProof\Key;
  9. use OC\Security\IdentityProof\Manager;
  10. use OC\Security\IdentityProof\Signer;
  11. use OCP\AppFramework\Utility\ITimeFactory;
  12. use OCP\IUser;
  13. use OCP\IUserManager;
  14. use Test\TestCase;
  15. class SignerTest extends TestCase {
  16. /** @var string */
  17. private $private = '-----BEGIN PRIVATE KEY-----
  18. MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDImc6QvHBjBIoo
  19. w9nnywiPNESleUuFJ2yQ3Gd/3w2BkblojlUAJAsUd/bQokjOH9d+7nqyzgSiXjRl
  20. iwKagY6NjcNEEq0X5KOMNwx6uEbtq3+7pA7H2JefNrnAuD+Fhp3Hyo3h1cse6hAq
  21. 6Zr8haCiSdFBfelLnx/X3gPgCzgl6GnvSmiqPEPFGng822dlW2RW+IIUv4y2LoIH
  22. 2PKZpxottxtFGIpcKSSHGUfNWya7Ih4E6RBgOrpyu4hrkikl4Xdh4RVgAf/GH54F
  23. gQi/AFeRS6llXJhep3lZOtLnFdYNPKFz1i/UvBoyUv8lrsvNa76HIgSMmGQKON4i
  24. QO0P/OaBAgMBAAECggEAdrtCnjxKsPDQ7Yvuf9mWeVxQfTir0GYjRiKOSAs3rUcZ
  25. XJ9SBEFRJY5T0e0b9pS2MfTpPsfdylTD4o5CvjyMqZAM0U/Uj93OR4GVq1VC9g2a
  26. Du/tp6+1HpF/pGfpgRjKbqSfEdo+3U9gvmWCTJCzIRtb9c2WtiG68UQBOyyo0RYQ
  27. F2b4az2BEOa7mATgwwGfdhV4VTQ18+iQKtfVoguw0bi1khDA0t+o8phhhmBHlOOi
  28. lpV5uSnJB7H3s6B01xf1dA44y57bcFNKL4THQv9dlazL2R2DhgxmADWXGPyJs0YM
  29. mhRSB25pEcFvLu//e0fHpO+kmZ+MPsey5blH3D92+QKBgQDzmlYIWSvNWXejKMdH
  30. QGVQmrG9nExld3LhNERONhh4FaxoXOqVZgLqAAUaSMHawYzfYjRaLuW16UTYh0XC
  31. hs2ISE5Oc4abDc6obNs2Xalrxp9stmD/Ti+/aSQifm2SoIeIH2lcPYob5yh/bfqh
  32. AP/Uk9ZdDSnHcsGm6wzhCmS1UwKBgQDSzz0ogjtsmPa14jIHrHZluzbfbqOgaeQi
  33. 5WZPPbuEqdS37kaDznt4goDLOywqWUGrmBtBPi2hOqGF0K7qzUvlM0mlvedvjH1l
  34. 4JByb6gXwGoZPnnzTCfDx86gKB1+rWzVbo236dHi1oirZ52voKu57TqC8My5MTzW
  35. YFgi872GWwKBgQCkxLd8XhQqiWFKksJ3hy8AHiIqxhVGbEzf1qJ85EoYr1A2JuLk
  36. umMuM2VAKgY1GMVYMuyGM0JckLNoYdblhJhwnbeZiLp7FhO6CCcd1qxJoccjmRhy
  37. l0fkiBFQ44Lpsnr5r4VsRpOr2+agipsDW9Guz3Am8EhaB1zEsie773O+0QKBgFb/
  38. W3fqNufcQIRTMt5j2ACnwD95A2HiEVotXYl6KnbXN4god0VR4zaadNhqNRHNAAL2
  39. pNjJ9j7BWYNF2cngq1+NSOlzc51fVyjCAhqX5cDXkXGVjPJRDWAIh0clBvcOTwnN
  40. tAKgJhP9AS3rdvHR1szGEA2VnocWwMqfu//AowhdAoGACYwuBjfUWc21jcT5yeLZ
  41. ahLp+ImQsKDE0swhmk4uesbLLPRfyvpLca98XbBMuS1iLrVUY3mEfIV7ltaBajE0
  42. l3eB7suqch3WUzH1RMWzwpuUMWV/A8qjPbIrd2QYUFYxJsU88lBqRg92rPnri6Ec
  43. kC6HCb+CXsMRD7yp8KrrYnw=
  44. -----END PRIVATE KEY-----';
  45. /** @var string */
  46. private $public = '-----BEGIN PUBLIC KEY-----
  47. MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyJnOkLxwYwSKKMPZ58sI
  48. jzREpXlLhSdskNxnf98NgZG5aI5VACQLFHf20KJIzh/Xfu56ss4Eol40ZYsCmoGO
  49. jY3DRBKtF+SjjDcMerhG7at/u6QOx9iXnza5wLg/hYadx8qN4dXLHuoQKuma/IWg
  50. oknRQX3pS58f194D4As4Jehp70poqjxDxRp4PNtnZVtkVviCFL+Mti6CB9jymaca
  51. LbcbRRiKXCkkhxlHzVsmuyIeBOkQYDq6cruIa5IpJeF3YeEVYAH/xh+eBYEIvwBX
  52. kUupZVyYXqd5WTrS5xXWDTyhc9Yv1LwaMlL/Ja7LzWu+hyIEjJhkCjjeIkDtD/zm
  53. gQIDAQAB
  54. -----END PUBLIC KEY-----';
  55. /** @var Key */
  56. private $key;
  57. /** @var Manager|\PHPUnit\Framework\MockObject\MockObject */
  58. private $keyManager;
  59. /** @var ITimeFactory|\PHPUnit\Framework\MockObject\MockObject */
  60. private $timeFactory;
  61. /** @var IUserManager|\PHPUnit\Framework\MockObject\MockObject */
  62. private $userManager;
  63. /** @var Signer */
  64. private $signer;
  65. protected function setUp(): void {
  66. parent::setUp();
  67. $this->key = new Key($this->public, $this->private);
  68. $this->keyManager = $this->createMock(Manager::class);
  69. $this->timeFactory = $this->createMock(ITimeFactory::class);
  70. $this->userManager = $this->createMock(IUserManager::class);
  71. $this->signer = new Signer(
  72. $this->keyManager,
  73. $this->timeFactory,
  74. $this->userManager
  75. );
  76. }
  77. public function testSign(): void {
  78. $user = $this->createMock(IUser::class);
  79. $user->method('getCloudId')
  80. ->willReturn('foo@example.com');
  81. $this->timeFactory->method('getTime')
  82. ->willReturn(42);
  83. $this->keyManager->method('getKey')
  84. ->with($this->equalTo($user))
  85. ->willReturn($this->key);
  86. $data = [
  87. 'foo' => 'bar',
  88. 'abc' => 'def',
  89. 'xyz' => 123,
  90. ];
  91. $expects = [
  92. 'message' => [
  93. 'data' => $data,
  94. 'type' => 'myType',
  95. 'signer' => 'foo@example.com',
  96. 'timestamp' => 42,
  97. ],
  98. 'signature' => 'E1fNdoWMX1QmSyKv+S3FtOgLe9niYGQFWOKGaMLxc2h7s3V++EIqJvw/NCLBfrUowzWkTzhkjfbHaf88Hz34WAn4sAwXYAO8cnboQs6SClKRzQ/nvbtLgd2wm9RQ8UTOM7wR6C7HpIn4qqJ4BTQ1bAwYAiJ2GoK+W8wC0o0Gpub2906j3JJ4cbc9lufd5ohWKCev8Ubem/EEKaRIZA7qHh+Q1MKXTaJQJlCjTMe5PyGy0fsmtVxsPls3/Fkd9sVeHEHSYHzOiF6ttlxWou4TdRbq3WSEVpt1DOOvkKI9w2+zBJ7IPH8CnVpXcdIzWDctUygZKzNMUQnweDOOziEdUw=='
  99. ];
  100. $result = $this->signer->sign('myType', $data, $user);
  101. $this->assertEquals($expects, $result);
  102. }
  103. public function testVerifyValid(): void {
  104. $data = [
  105. 'message' => [
  106. 'data' => [
  107. 'foo' => 'bar',
  108. 'abc' => 'def',
  109. 'xyz' => 123,
  110. ],
  111. 'type' => 'myType',
  112. 'signer' => 'foo@example.com',
  113. 'timestamp' => 42,
  114. ],
  115. 'signature' => 'E1fNdoWMX1QmSyKv+S3FtOgLe9niYGQFWOKGaMLxc2h7s3V++EIqJvw/NCLBfrUowzWkTzhkjfbHaf88Hz34WAn4sAwXYAO8cnboQs6SClKRzQ/nvbtLgd2wm9RQ8UTOM7wR6C7HpIn4qqJ4BTQ1bAwYAiJ2GoK+W8wC0o0Gpub2906j3JJ4cbc9lufd5ohWKCev8Ubem/EEKaRIZA7qHh+Q1MKXTaJQJlCjTMe5PyGy0fsmtVxsPls3/Fkd9sVeHEHSYHzOiF6ttlxWou4TdRbq3WSEVpt1DOOvkKI9w2+zBJ7IPH8CnVpXcdIzWDctUygZKzNMUQnweDOOziEdUw=='
  116. ];
  117. $user = $this->createMock(IUser::class);
  118. $this->keyManager->method('getKey')
  119. ->with($this->equalTo($user))
  120. ->willReturn($this->key);
  121. $this->userManager->method('get')
  122. ->with('foo')
  123. ->willReturn($user);
  124. $this->assertTrue($this->signer->verify($data));
  125. }
  126. public function testVerifyInvalid(): void {
  127. $data = [
  128. 'message' => [
  129. 'data' => [
  130. 'foo' => 'bar',
  131. 'abc' => 'def',
  132. 'xyz' => 123,
  133. ],
  134. 'type' => 'myType',
  135. 'signer' => 'foo@example.com',
  136. 'timestamp' => 42,
  137. ],
  138. 'signature' => 'Invalid sig'
  139. ];
  140. $user = $this->createMock(IUser::class);
  141. $this->keyManager->method('getKey')
  142. ->with($this->equalTo($user))
  143. ->willReturn($this->key);
  144. $this->userManager->method('get')
  145. ->with('foo')
  146. ->willReturn($user);
  147. $this->assertFalse($this->signer->verify($data));
  148. }
  149. public function testVerifyInvalidData(): void {
  150. $data = [
  151. ];
  152. $this->assertFalse($this->signer->verify($data));
  153. }
  154. }