test_e2e_room_keys.py 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564
  1. # Copyright 2016 OpenMarket Ltd
  2. # Copyright 2017 New Vector Ltd
  3. # Copyright 2019 Matrix.org Foundation C.I.C.
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License");
  6. # you may not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. import copy
  17. from unittest import mock
  18. from twisted.test.proto_helpers import MemoryReactor
  19. from synapse.api.errors import SynapseError
  20. from synapse.server import HomeServer
  21. from synapse.util import Clock
  22. from tests import unittest
  23. # sample room_key data for use in the tests
  24. room_keys = {
  25. "rooms": {
  26. "!abc:matrix.org": {
  27. "sessions": {
  28. "c0ff33": {
  29. "first_message_index": 1,
  30. "forwarded_count": 1,
  31. "is_verified": False,
  32. "session_data": "SSBBTSBBIEZJU0gK",
  33. }
  34. }
  35. }
  36. }
  37. }
  38. class E2eRoomKeysHandlerTestCase(unittest.HomeserverTestCase):
  39. def make_homeserver(self, reactor: MemoryReactor, clock: Clock) -> HomeServer:
  40. return self.setup_test_homeserver(replication_layer=mock.Mock())
  41. def prepare(self, reactor: MemoryReactor, clock: Clock, hs: HomeServer) -> None:
  42. self.handler = hs.get_e2e_room_keys_handler()
  43. self.local_user = "@boris:" + hs.hostname
  44. def test_get_missing_current_version_info(self) -> None:
  45. """Check that we get a 404 if we ask for info about the current version
  46. if there is no version.
  47. """
  48. e = self.get_failure(
  49. self.handler.get_version_info(self.local_user), SynapseError
  50. )
  51. res = e.value.code
  52. self.assertEqual(res, 404)
  53. def test_get_missing_version_info(self) -> None:
  54. """Check that we get a 404 if we ask for info about a specific version
  55. if it doesn't exist.
  56. """
  57. e = self.get_failure(
  58. self.handler.get_version_info(self.local_user, "bogus_version"),
  59. SynapseError,
  60. )
  61. res = e.value.code
  62. self.assertEqual(res, 404)
  63. def test_create_version(self) -> None:
  64. """Check that we can create and then retrieve versions."""
  65. version = self.get_success(
  66. self.handler.create_version(
  67. self.local_user,
  68. {
  69. "algorithm": "m.megolm_backup.v1",
  70. "auth_data": "first_version_auth_data",
  71. },
  72. )
  73. )
  74. self.assertEqual(version, "1")
  75. # check we can retrieve it as the current version
  76. res = self.get_success(self.handler.get_version_info(self.local_user))
  77. version_etag = res["etag"]
  78. self.assertIsInstance(version_etag, str)
  79. del res["etag"]
  80. self.assertDictEqual(
  81. res,
  82. {
  83. "version": "1",
  84. "algorithm": "m.megolm_backup.v1",
  85. "auth_data": "first_version_auth_data",
  86. "count": 0,
  87. },
  88. )
  89. # check we can retrieve it as a specific version
  90. res = self.get_success(self.handler.get_version_info(self.local_user, "1"))
  91. self.assertEqual(res["etag"], version_etag)
  92. del res["etag"]
  93. self.assertDictEqual(
  94. res,
  95. {
  96. "version": "1",
  97. "algorithm": "m.megolm_backup.v1",
  98. "auth_data": "first_version_auth_data",
  99. "count": 0,
  100. },
  101. )
  102. # upload a new one...
  103. version = self.get_success(
  104. self.handler.create_version(
  105. self.local_user,
  106. {
  107. "algorithm": "m.megolm_backup.v1",
  108. "auth_data": "second_version_auth_data",
  109. },
  110. )
  111. )
  112. self.assertEqual(version, "2")
  113. # check we can retrieve it as the current version
  114. res = self.get_success(self.handler.get_version_info(self.local_user))
  115. del res["etag"]
  116. self.assertDictEqual(
  117. res,
  118. {
  119. "version": "2",
  120. "algorithm": "m.megolm_backup.v1",
  121. "auth_data": "second_version_auth_data",
  122. "count": 0,
  123. },
  124. )
  125. def test_update_version(self) -> None:
  126. """Check that we can update versions."""
  127. version = self.get_success(
  128. self.handler.create_version(
  129. self.local_user,
  130. {
  131. "algorithm": "m.megolm_backup.v1",
  132. "auth_data": "first_version_auth_data",
  133. },
  134. )
  135. )
  136. self.assertEqual(version, "1")
  137. res = self.get_success(
  138. self.handler.update_version(
  139. self.local_user,
  140. version,
  141. {
  142. "algorithm": "m.megolm_backup.v1",
  143. "auth_data": "revised_first_version_auth_data",
  144. "version": version,
  145. },
  146. )
  147. )
  148. self.assertDictEqual(res, {})
  149. # check we can retrieve it as the current version
  150. res = self.get_success(self.handler.get_version_info(self.local_user))
  151. del res["etag"]
  152. self.assertDictEqual(
  153. res,
  154. {
  155. "algorithm": "m.megolm_backup.v1",
  156. "auth_data": "revised_first_version_auth_data",
  157. "version": version,
  158. "count": 0,
  159. },
  160. )
  161. def test_update_missing_version(self) -> None:
  162. """Check that we get a 404 on updating nonexistent versions"""
  163. e = self.get_failure(
  164. self.handler.update_version(
  165. self.local_user,
  166. "1",
  167. {
  168. "algorithm": "m.megolm_backup.v1",
  169. "auth_data": "revised_first_version_auth_data",
  170. "version": "1",
  171. },
  172. ),
  173. SynapseError,
  174. )
  175. res = e.value.code
  176. self.assertEqual(res, 404)
  177. def test_update_omitted_version(self) -> None:
  178. """Check that the update succeeds if the version is missing from the body"""
  179. version = self.get_success(
  180. self.handler.create_version(
  181. self.local_user,
  182. {
  183. "algorithm": "m.megolm_backup.v1",
  184. "auth_data": "first_version_auth_data",
  185. },
  186. )
  187. )
  188. self.assertEqual(version, "1")
  189. self.get_success(
  190. self.handler.update_version(
  191. self.local_user,
  192. version,
  193. {
  194. "algorithm": "m.megolm_backup.v1",
  195. "auth_data": "revised_first_version_auth_data",
  196. },
  197. )
  198. )
  199. # check we can retrieve it as the current version
  200. res = self.get_success(self.handler.get_version_info(self.local_user))
  201. del res["etag"] # etag is opaque, so don't test its contents
  202. self.assertDictEqual(
  203. res,
  204. {
  205. "algorithm": "m.megolm_backup.v1",
  206. "auth_data": "revised_first_version_auth_data",
  207. "version": version,
  208. "count": 0,
  209. },
  210. )
  211. def test_update_bad_version(self) -> None:
  212. """Check that we get a 400 if the version in the body doesn't match"""
  213. version = self.get_success(
  214. self.handler.create_version(
  215. self.local_user,
  216. {
  217. "algorithm": "m.megolm_backup.v1",
  218. "auth_data": "first_version_auth_data",
  219. },
  220. )
  221. )
  222. self.assertEqual(version, "1")
  223. e = self.get_failure(
  224. self.handler.update_version(
  225. self.local_user,
  226. version,
  227. {
  228. "algorithm": "m.megolm_backup.v1",
  229. "auth_data": "revised_first_version_auth_data",
  230. "version": "incorrect",
  231. },
  232. ),
  233. SynapseError,
  234. )
  235. res = e.value.code
  236. self.assertEqual(res, 400)
  237. def test_delete_missing_version(self) -> None:
  238. """Check that we get a 404 on deleting nonexistent versions"""
  239. e = self.get_failure(
  240. self.handler.delete_version(self.local_user, "1"), SynapseError
  241. )
  242. res = e.value.code
  243. self.assertEqual(res, 404)
  244. def test_delete_missing_current_version(self) -> None:
  245. """Check that we get a 404 on deleting nonexistent current version"""
  246. e = self.get_failure(self.handler.delete_version(self.local_user), SynapseError)
  247. res = e.value.code
  248. self.assertEqual(res, 404)
  249. def test_delete_version(self) -> None:
  250. """Check that we can create and then delete versions."""
  251. version = self.get_success(
  252. self.handler.create_version(
  253. self.local_user,
  254. {
  255. "algorithm": "m.megolm_backup.v1",
  256. "auth_data": "first_version_auth_data",
  257. },
  258. )
  259. )
  260. self.assertEqual(version, "1")
  261. # check we can delete it
  262. self.get_success(self.handler.delete_version(self.local_user, "1"))
  263. # check that it's gone
  264. e = self.get_failure(
  265. self.handler.get_version_info(self.local_user, "1"), SynapseError
  266. )
  267. res = e.value.code
  268. self.assertEqual(res, 404)
  269. def test_get_missing_backup(self) -> None:
  270. """Check that we get a 404 on querying missing backup"""
  271. e = self.get_failure(
  272. self.handler.get_room_keys(self.local_user, "bogus_version"), SynapseError
  273. )
  274. res = e.value.code
  275. self.assertEqual(res, 404)
  276. def test_get_missing_room_keys(self) -> None:
  277. """Check we get an empty response from an empty backup"""
  278. version = self.get_success(
  279. self.handler.create_version(
  280. self.local_user,
  281. {
  282. "algorithm": "m.megolm_backup.v1",
  283. "auth_data": "first_version_auth_data",
  284. },
  285. )
  286. )
  287. self.assertEqual(version, "1")
  288. res = self.get_success(self.handler.get_room_keys(self.local_user, version))
  289. self.assertDictEqual(res, {"rooms": {}})
  290. # TODO: test the locking semantics when uploading room_keys,
  291. # although this is probably best done in sytest
  292. def test_upload_room_keys_no_versions(self) -> None:
  293. """Check that we get a 404 on uploading keys when no versions are defined"""
  294. e = self.get_failure(
  295. self.handler.upload_room_keys(self.local_user, "no_version", room_keys),
  296. SynapseError,
  297. )
  298. res = e.value.code
  299. self.assertEqual(res, 404)
  300. def test_upload_room_keys_bogus_version(self) -> None:
  301. """Check that we get a 404 on uploading keys when an nonexistent version
  302. is specified
  303. """
  304. version = self.get_success(
  305. self.handler.create_version(
  306. self.local_user,
  307. {
  308. "algorithm": "m.megolm_backup.v1",
  309. "auth_data": "first_version_auth_data",
  310. },
  311. )
  312. )
  313. self.assertEqual(version, "1")
  314. e = self.get_failure(
  315. self.handler.upload_room_keys(self.local_user, "bogus_version", room_keys),
  316. SynapseError,
  317. )
  318. res = e.value.code
  319. self.assertEqual(res, 404)
  320. def test_upload_room_keys_wrong_version(self) -> None:
  321. """Check that we get a 403 on uploading keys for an old version"""
  322. version = self.get_success(
  323. self.handler.create_version(
  324. self.local_user,
  325. {
  326. "algorithm": "m.megolm_backup.v1",
  327. "auth_data": "first_version_auth_data",
  328. },
  329. )
  330. )
  331. self.assertEqual(version, "1")
  332. version = self.get_success(
  333. self.handler.create_version(
  334. self.local_user,
  335. {
  336. "algorithm": "m.megolm_backup.v1",
  337. "auth_data": "second_version_auth_data",
  338. },
  339. )
  340. )
  341. self.assertEqual(version, "2")
  342. e = self.get_failure(
  343. self.handler.upload_room_keys(self.local_user, "1", room_keys), SynapseError
  344. )
  345. res = e.value.code
  346. self.assertEqual(res, 403)
  347. def test_upload_room_keys_insert(self) -> None:
  348. """Check that we can insert and retrieve keys for a session"""
  349. version = self.get_success(
  350. self.handler.create_version(
  351. self.local_user,
  352. {
  353. "algorithm": "m.megolm_backup.v1",
  354. "auth_data": "first_version_auth_data",
  355. },
  356. )
  357. )
  358. self.assertEqual(version, "1")
  359. self.get_success(
  360. self.handler.upload_room_keys(self.local_user, version, room_keys)
  361. )
  362. res = self.get_success(self.handler.get_room_keys(self.local_user, version))
  363. self.assertDictEqual(res, room_keys)
  364. # check getting room_keys for a given room
  365. res = self.get_success(
  366. self.handler.get_room_keys(
  367. self.local_user, version, room_id="!abc:matrix.org"
  368. )
  369. )
  370. self.assertDictEqual(res, room_keys)
  371. # check getting room_keys for a given session_id
  372. res = self.get_success(
  373. self.handler.get_room_keys(
  374. self.local_user, version, room_id="!abc:matrix.org", session_id="c0ff33"
  375. )
  376. )
  377. self.assertDictEqual(res, room_keys)
  378. def test_upload_room_keys_merge(self) -> None:
  379. """Check that we can upload a new room_key for an existing session and
  380. have it correctly merged"""
  381. version = self.get_success(
  382. self.handler.create_version(
  383. self.local_user,
  384. {
  385. "algorithm": "m.megolm_backup.v1",
  386. "auth_data": "first_version_auth_data",
  387. },
  388. )
  389. )
  390. self.assertEqual(version, "1")
  391. self.get_success(
  392. self.handler.upload_room_keys(self.local_user, version, room_keys)
  393. )
  394. # get the etag to compare to future versions
  395. res = self.get_success(self.handler.get_version_info(self.local_user))
  396. backup_etag = res["etag"]
  397. self.assertEqual(res["count"], 1)
  398. new_room_keys = copy.deepcopy(room_keys)
  399. new_room_key = new_room_keys["rooms"]["!abc:matrix.org"]["sessions"]["c0ff33"]
  400. # test that increasing the message_index doesn't replace the existing session
  401. new_room_key["first_message_index"] = 2
  402. new_room_key["session_data"] = "new"
  403. self.get_success(
  404. self.handler.upload_room_keys(self.local_user, version, new_room_keys)
  405. )
  406. res_keys = self.get_success(
  407. self.handler.get_room_keys(self.local_user, version)
  408. )
  409. self.assertEqual(
  410. res_keys["rooms"]["!abc:matrix.org"]["sessions"]["c0ff33"]["session_data"],
  411. "SSBBTSBBIEZJU0gK",
  412. )
  413. # the etag should be the same since the session did not change
  414. res = self.get_success(self.handler.get_version_info(self.local_user))
  415. self.assertEqual(res["etag"], backup_etag)
  416. # test that marking the session as verified however /does/ replace it
  417. new_room_key["is_verified"] = True
  418. self.get_success(
  419. self.handler.upload_room_keys(self.local_user, version, new_room_keys)
  420. )
  421. res_keys = self.get_success(
  422. self.handler.get_room_keys(self.local_user, version)
  423. )
  424. self.assertEqual(
  425. res_keys["rooms"]["!abc:matrix.org"]["sessions"]["c0ff33"]["session_data"],
  426. "new",
  427. )
  428. # the etag should NOT be equal now, since the key changed
  429. res = self.get_success(self.handler.get_version_info(self.local_user))
  430. self.assertNotEqual(res["etag"], backup_etag)
  431. backup_etag = res["etag"]
  432. # test that a session with a higher forwarded_count doesn't replace one
  433. # with a lower forwarding count
  434. new_room_key["forwarded_count"] = 2
  435. new_room_key["session_data"] = "other"
  436. self.get_success(
  437. self.handler.upload_room_keys(self.local_user, version, new_room_keys)
  438. )
  439. res_keys = self.get_success(
  440. self.handler.get_room_keys(self.local_user, version)
  441. )
  442. self.assertEqual(
  443. res_keys["rooms"]["!abc:matrix.org"]["sessions"]["c0ff33"]["session_data"],
  444. "new",
  445. )
  446. # the etag should be the same since the session did not change
  447. res = self.get_success(self.handler.get_version_info(self.local_user))
  448. self.assertEqual(res["etag"], backup_etag)
  449. # TODO: check edge cases as well as the common variations here
  450. def test_delete_room_keys(self) -> None:
  451. """Check that we can insert and delete keys for a session"""
  452. version = self.get_success(
  453. self.handler.create_version(
  454. self.local_user,
  455. {
  456. "algorithm": "m.megolm_backup.v1",
  457. "auth_data": "first_version_auth_data",
  458. },
  459. )
  460. )
  461. self.assertEqual(version, "1")
  462. # check for bulk-delete
  463. self.get_success(
  464. self.handler.upload_room_keys(self.local_user, version, room_keys)
  465. )
  466. self.get_success(self.handler.delete_room_keys(self.local_user, version))
  467. res = self.get_success(
  468. self.handler.get_room_keys(
  469. self.local_user, version, room_id="!abc:matrix.org", session_id="c0ff33"
  470. )
  471. )
  472. self.assertDictEqual(res, {"rooms": {}})
  473. # check for bulk-delete per room
  474. self.get_success(
  475. self.handler.upload_room_keys(self.local_user, version, room_keys)
  476. )
  477. self.get_success(
  478. self.handler.delete_room_keys(
  479. self.local_user, version, room_id="!abc:matrix.org"
  480. )
  481. )
  482. res = self.get_success(
  483. self.handler.get_room_keys(
  484. self.local_user, version, room_id="!abc:matrix.org", session_id="c0ff33"
  485. )
  486. )
  487. self.assertDictEqual(res, {"rooms": {}})
  488. # check for bulk-delete per session
  489. self.get_success(
  490. self.handler.upload_room_keys(self.local_user, version, room_keys)
  491. )
  492. self.get_success(
  493. self.handler.delete_room_keys(
  494. self.local_user, version, room_id="!abc:matrix.org", session_id="c0ff33"
  495. )
  496. )
  497. res = self.get_success(
  498. self.handler.get_room_keys(
  499. self.local_user, version, room_id="!abc:matrix.org", session_id="c0ff33"
  500. )
  501. )
  502. self.assertDictEqual(res, {"rooms": {}})