test_keys.py 4.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130
  1. # -*- coding: utf-8 -*-
  2. # Copyright 2017 Vector Creations Ltd
  3. #
  4. # Licensed under the Apache License, Version 2.0 (the "License");
  5. # you may not use this file except in compliance with the License.
  6. # You may obtain a copy of the License at
  7. #
  8. # http://www.apache.org/licenses/LICENSE-2.0
  9. #
  10. # Unless required by applicable law or agreed to in writing, software
  11. # distributed under the License is distributed on an "AS IS" BASIS,
  12. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. # See the License for the specific language governing permissions and
  14. # limitations under the License.
  15. import signedjson.key
  16. import unpaddedbase64
  17. from twisted.internet.defer import Deferred
  18. from synapse.storage.keys import FetchKeyResult
  19. import tests.unittest
  20. def decode_verify_key_base64(key_id: str, key_base64: str):
  21. key_bytes = unpaddedbase64.decode_base64(key_base64)
  22. return signedjson.key.decode_verify_key_bytes(key_id, key_bytes)
  23. KEY_1 = decode_verify_key_base64(
  24. "ed25519:key1", "fP5l4JzpZPq/zdbBg5xx6lQGAAOM9/3w94cqiJ5jPrw"
  25. )
  26. KEY_2 = decode_verify_key_base64(
  27. "ed25519:key2", "Noi6WqcDj0QmPxCNQqgezwTlBKrfqehY1u2FyWP9uYw"
  28. )
  29. class KeyStoreTestCase(tests.unittest.HomeserverTestCase):
  30. def test_get_server_verify_keys(self):
  31. store = self.hs.get_datastore()
  32. key_id_1 = "ed25519:key1"
  33. key_id_2 = "ed25519:KEY_ID_2"
  34. d = store.store_server_verify_keys(
  35. "from_server",
  36. 10,
  37. [
  38. ("server1", key_id_1, FetchKeyResult(KEY_1, 100)),
  39. ("server1", key_id_2, FetchKeyResult(KEY_2, 200)),
  40. ],
  41. )
  42. self.get_success(d)
  43. d = store.get_server_verify_keys(
  44. [("server1", key_id_1), ("server1", key_id_2), ("server1", "ed25519:key3")]
  45. )
  46. res = self.get_success(d)
  47. self.assertEqual(len(res.keys()), 3)
  48. res1 = res[("server1", key_id_1)]
  49. self.assertEqual(res1.verify_key, KEY_1)
  50. self.assertEqual(res1.verify_key.version, "key1")
  51. self.assertEqual(res1.valid_until_ts, 100)
  52. res2 = res[("server1", key_id_2)]
  53. self.assertEqual(res2.verify_key, KEY_2)
  54. # version comes from the ID it was stored with
  55. self.assertEqual(res2.verify_key.version, "KEY_ID_2")
  56. self.assertEqual(res2.valid_until_ts, 200)
  57. # non-existent result gives None
  58. self.assertIsNone(res[("server1", "ed25519:key3")])
  59. def test_cache(self):
  60. """Check that updates correctly invalidate the cache."""
  61. store = self.hs.get_datastore()
  62. key_id_1 = "ed25519:key1"
  63. key_id_2 = "ed25519:key2"
  64. d = store.store_server_verify_keys(
  65. "from_server",
  66. 0,
  67. [
  68. ("srv1", key_id_1, FetchKeyResult(KEY_1, 100)),
  69. ("srv1", key_id_2, FetchKeyResult(KEY_2, 200)),
  70. ],
  71. )
  72. self.get_success(d)
  73. d = store.get_server_verify_keys([("srv1", key_id_1), ("srv1", key_id_2)])
  74. res = self.get_success(d)
  75. self.assertEqual(len(res.keys()), 2)
  76. res1 = res[("srv1", key_id_1)]
  77. self.assertEqual(res1.verify_key, KEY_1)
  78. self.assertEqual(res1.valid_until_ts, 100)
  79. res2 = res[("srv1", key_id_2)]
  80. self.assertEqual(res2.verify_key, KEY_2)
  81. self.assertEqual(res2.valid_until_ts, 200)
  82. # we should be able to look up the same thing again without a db hit
  83. res = store.get_server_verify_keys([("srv1", key_id_1)])
  84. if isinstance(res, Deferred):
  85. res = self.successResultOf(res)
  86. self.assertEqual(len(res.keys()), 1)
  87. self.assertEqual(res[("srv1", key_id_1)].verify_key, KEY_1)
  88. new_key_2 = signedjson.key.get_verify_key(
  89. signedjson.key.generate_signing_key("key2")
  90. )
  91. d = store.store_server_verify_keys(
  92. "from_server", 10, [("srv1", key_id_2, FetchKeyResult(new_key_2, 300))]
  93. )
  94. self.get_success(d)
  95. d = store.get_server_verify_keys([("srv1", key_id_1), ("srv1", key_id_2)])
  96. res = self.get_success(d)
  97. self.assertEqual(len(res.keys()), 2)
  98. res1 = res[("srv1", key_id_1)]
  99. self.assertEqual(res1.verify_key, KEY_1)
  100. self.assertEqual(res1.valid_until_ts, 100)
  101. res2 = res[("srv1", key_id_2)]
  102. self.assertEqual(res2.verify_key, new_key_2)
  103. self.assertEqual(res2.valid_until_ts, 300)