Something went wrong. Try again.
Monorepo for Tangled tangled.org
Something went wrong. Try again.
Go
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125package oauth
import ( "context" "io" "log/slog" "net/http" "net/http/httptest" "strings" "testing" "time"
"github.com/bluesky-social/indigo/atproto/syntax" "github.com/samber/lo" "tangled.org/core/appview/config" "tangled.org/core/consts" "tangled.org/core/xrpc/serviceauth")
type fakeAcl struct { member bool gotHost string gotDid string}
func (f *fakeAcl) InvalidateMembers(host string) {}
func (f *fakeAcl) IsKnotMember(ctx context.Context, host, userDid string) bool { f.gotHost = host f.gotDid = userDid return f.member}
func TestAddToDefaultKnot_ShortCircuitsWhenAlreadyMember(t *testing.T) { acl := &fakeAcl{member: true} o := &OAuth{ Acl: acl, Logger: slog.New(slog.NewTextHandler(io.Discard, nil)), Config: &config.Config{ Core: config.CoreConfig{Dev: true}, Knot: config.KnotConfig{Default: consts.DefaultKnot}, }, }
o.addToDefaultKnot(syntax.DID("did:plc:akshay"), "session-1")
if acl.gotDid != "did:plc:akshay" { t.Fatalf("IsKnotMember did = %q, want did:plc:akshay", acl.gotDid) } if acl.gotHost != consts.DefaultKnot { t.Fatalf("IsKnotMember host = %q, want %q", acl.gotHost, consts.DefaultKnot) }}
func TestAddMemberViaKnotAdmin_HonorsDeadline(t *testing.T) { release := make(chan struct{}) srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { <-release })) defer srv.Close() defer close(release)
o := &OAuth{Config: &config.Config{ Core: config.CoreConfig{Dev: true}, Knot: config.KnotConfig{AdminSecret: "hunter2"}, }}
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond) defer cancel()
done := make(chan error, 1) go func() { done <- o.addMemberViaKnotAdmin(ctx, strings.TrimPrefix(srv.URL, "http://"), syntax.DID("did:plc:whelk")) }()
select { case err := <-done: if err == nil { t.Fatal("a hung knot must surface an error, got nil") } case <-time.After(5 * time.Second): t.Fatal("addMemberViaKnotAdmin blocked past its deadline; the request has no timeout") }}
func TestOnboardActionFor(t *testing.T) { cases := []struct { name string state defaultKnotState want onboardAction }{ {"native default knot with admin secret uses the admin api", defaultKnotState{native: true, adminSecretSet: true}, onboardViaAdminAPI}, {"native default knot without admin secret is blocked", defaultKnotState{native: true, adminSecretSet: false}, onboardBlockedMissingSecret}, {"legacy default knot with admin secret skips the legacy record", defaultKnotState{native: false, adminSecretSet: true}, onboardBlockedSecretSet}, {"legacy default knot without admin secret writes the legacy record", defaultKnotState{native: false, adminSecretSet: false}, onboardViaRecord}, } for _, c := range cases { t.Run(c.name, func(t *testing.T) { if got := onboardActionFor(c.state); got != c.want { t.Fatalf("onboardActionFor(%+v) = %d, want %d", c.state, got, c.want) } }) }}
func TestTheConsentHandshakeIsScopedAndKeyedByTheKnotsDidWeb(t *testing.T) { if missing := lo.Without([]string{"repo:sh.tangled.knot.memberAcceptance", "repo:sh.tangled.repo.collaboratorAcceptance", "rpc:sh.tangled.knot.acceptMembership?aud=*", "rpc:sh.tangled.repo.acceptCollaboration?aud=*"}, TangledScopes...); len(missing) != 0 { t.Errorf("TangledScopes is missing %v; a user can't accept an invite without them", missing) } if audience := serviceauth.DidWeb("knot.example:3000").String(); audience != "did:web:knot.example%3A3000" { t.Errorf("service auth audience = %q, want the colon percent-encoded", audience) } lo.ForEach([]string{"knot.example:3000", "knot.example/path", ""}, func(host string, _ int) { if _, err := serviceauth.RkeyForService(host); err == nil { t.Errorf("RkeyForService(%q) succeeded; a record key must be the bare host", host) } }) switch rkey, err := serviceauth.RkeyForService("knot.example"); { case err != nil: t.Fatalf("RkeyForService(bare host) = %v, want a record key", err) case rkey.String() != "did:web:knot.example" || rkey.String() != serviceauth.DidWeb("knot.example").String(): t.Errorf("acceptance rkey = %q, want the unencoded did:web DidWeb returns", rkey) }}