2020-12-28 15:04:52 +01:00
|
|
|
/*
|
|
|
|
* Copyright (C) Sapphirecode - All Rights Reserved
|
|
|
|
* This file is part of Auth-Server-Helper which is released under MIT.
|
|
|
|
* See file 'LICENSE' for full license details.
|
|
|
|
* Created by Timo Hocker <timo@scode.ovh>, December 2020
|
|
|
|
*/
|
|
|
|
|
2020-12-19 16:19:09 +01:00
|
|
|
import auth from '../../lib/Authority';
|
2020-12-28 14:53:14 +01:00
|
|
|
import bl from '../../lib/Blacklist';
|
2021-01-01 14:14:19 +01:00
|
|
|
import { modify_signature } from '../Helper';
|
2020-12-28 14:53:14 +01:00
|
|
|
|
|
|
|
// eslint-disable-next-line max-lines-per-function
|
2020-12-19 16:19:09 +01:00
|
|
|
describe ('authority', () => {
|
|
|
|
beforeEach (() => {
|
|
|
|
jasmine.clock ()
|
|
|
|
.install ();
|
|
|
|
jasmine.clock ()
|
|
|
|
.mockDate (new Date);
|
|
|
|
});
|
|
|
|
|
|
|
|
afterEach (() => {
|
2020-12-28 14:53:14 +01:00
|
|
|
jasmine.clock ()
|
|
|
|
.tick (24 * 60 * 60 * 1000);
|
2020-12-19 16:19:09 +01:00
|
|
|
jasmine.clock ()
|
|
|
|
.uninstall ();
|
|
|
|
});
|
|
|
|
|
|
|
|
it ('should create an access token', () => {
|
|
|
|
const token = auth.sign ('access_token', 60);
|
|
|
|
jasmine.clock ()
|
|
|
|
.tick (30000);
|
|
|
|
const res = auth.verify (token.signature);
|
|
|
|
expect (res.authorized)
|
|
|
|
.toBeTrue ();
|
2020-12-28 14:53:14 +01:00
|
|
|
expect (res.valid)
|
|
|
|
.toBeTrue ();
|
2020-12-19 16:19:09 +01:00
|
|
|
expect (res.type)
|
|
|
|
.toEqual ('access_token');
|
|
|
|
expect (res.next_module)
|
|
|
|
.toBeUndefined ();
|
|
|
|
});
|
|
|
|
|
|
|
|
it ('should create a refresh token', () => {
|
|
|
|
const token = auth.sign ('refresh_token', 600);
|
|
|
|
jasmine.clock ()
|
|
|
|
.tick (30000);
|
|
|
|
const res = auth.verify (token.signature);
|
|
|
|
expect (res.authorized)
|
|
|
|
.toBeFalse ();
|
2020-12-28 14:53:14 +01:00
|
|
|
expect (res.valid)
|
|
|
|
.toBeTrue ();
|
2020-12-19 16:19:09 +01:00
|
|
|
expect (res.type)
|
|
|
|
.toEqual ('refresh_token');
|
|
|
|
expect (res.next_module)
|
|
|
|
.toBeUndefined ();
|
|
|
|
});
|
|
|
|
|
|
|
|
it ('should create a part token', () => {
|
2021-01-03 15:13:03 +01:00
|
|
|
const token = auth.sign ('part_token', 60, { next_module: '2fa' });
|
2020-12-19 16:19:09 +01:00
|
|
|
jasmine.clock ()
|
|
|
|
.tick (30000);
|
|
|
|
const res = auth.verify (token.signature);
|
|
|
|
expect (res.authorized)
|
|
|
|
.toBeFalse ();
|
2020-12-28 14:53:14 +01:00
|
|
|
expect (res.valid)
|
|
|
|
.toBeTrue ();
|
2020-12-19 16:19:09 +01:00
|
|
|
expect (res.type)
|
|
|
|
.toEqual ('part_token');
|
|
|
|
expect (res.next_module)
|
|
|
|
.toEqual ('2fa');
|
|
|
|
});
|
2020-12-28 14:53:14 +01:00
|
|
|
|
|
|
|
it ('should reject an invalid access token', () => {
|
|
|
|
const token = auth.sign ('access_token', 60);
|
|
|
|
token.signature = modify_signature (token.signature);
|
|
|
|
jasmine.clock ()
|
|
|
|
.tick (30000);
|
|
|
|
const res = auth.verify (token.signature);
|
|
|
|
expect (res.authorized)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.valid)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.type)
|
|
|
|
.toEqual ('none');
|
|
|
|
expect (res.next_module)
|
|
|
|
.toBeUndefined ();
|
|
|
|
});
|
|
|
|
|
|
|
|
it ('should reject blacklisted access token', () => {
|
|
|
|
const token = auth.sign ('access_token', 60);
|
|
|
|
jasmine.clock ()
|
|
|
|
.tick (30000);
|
|
|
|
bl.add_signature (token.id);
|
|
|
|
const res = auth.verify (token.signature);
|
|
|
|
expect (res.authorized)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.valid)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.type)
|
|
|
|
.toEqual ('access_token');
|
|
|
|
expect (res.next_module)
|
|
|
|
.toBeUndefined ();
|
|
|
|
});
|
|
|
|
|
|
|
|
it ('should reject an invalid refresh token', () => {
|
|
|
|
const token = auth.sign ('refresh_token', 600);
|
|
|
|
token.signature = modify_signature (token.signature);
|
|
|
|
jasmine.clock ()
|
|
|
|
.tick (30000);
|
|
|
|
const res = auth.verify (token.signature);
|
|
|
|
expect (res.authorized)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.valid)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.type)
|
|
|
|
.toEqual ('none');
|
|
|
|
expect (res.next_module)
|
|
|
|
.toBeUndefined ();
|
|
|
|
});
|
|
|
|
|
|
|
|
it ('should reject a blacklisted refresh token', () => {
|
|
|
|
const token = auth.sign ('refresh_token', 600);
|
|
|
|
jasmine.clock ()
|
|
|
|
.tick (30000);
|
|
|
|
bl.add_signature (token.id);
|
|
|
|
const res = auth.verify (token.signature);
|
|
|
|
expect (res.authorized)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.valid)
|
|
|
|
.toBeFalse ();
|
|
|
|
expect (res.type)
|
|
|
|
.toEqual ('refresh_token');
|
|
|
|
expect (res.next_module)
|
|
|
|
.toBeUndefined ();
|
|
|
|
});
|
2020-12-19 16:19:09 +01:00
|
|
|
});
|