Files
felhom.eu/hub/internal/web/r133_reveal_wrongkey_test.go
T

33 lines
1.2 KiB
Go

package web
import (
"net/http"
"net/http/httptest"
"strings"
"testing"
)
// R-133: with the wrong sealing key the reveal endpoint fails CLOSED — 500, no password in the body, nothing
// in the log, and no "revealed" event (nothing was delivered). The right-key path is TestReveal_B.
func TestR133_RevealWithWrongKeyFailsClosed(t *testing.T) {
s, st, logBuf := newRevealServer(t)
cookie, csrf := newRevealSession(t, s)
seedRevealHost(t, st, "demo-hp-bb76ea", "demo-hp", revealCanary)
if err := st.SetOffsiteSecretKey([]byte("another-key-of-exactly-32-bytes!")); err != nil {
t.Fatal(err)
}
req := httptest.NewRequest(http.MethodPost, "/hosts/demo-hp-bb76ea/reveal-recovery-credential", nil)
req.AddCookie(cookie)
req.Header.Set("X-CSRF-Token", csrf)
rr := serveReveal(t, s, req)
if rr.Code != http.StatusInternalServerError {
t.Fatalf("reveal with a wrong key = %d, want 500", rr.Code)
}
if strings.Contains(rr.Body.String(), revealCanary) || strings.Contains(logBuf.String(), revealCanary) {
t.Fatal("the secret leaked into the body or the log")
}
if n := countEvents(t, st, "demo-hp", "recovery_credential_revealed"); n != 0 {
t.Fatalf("%d reveal event(s) for a reveal that delivered nothing", n)
}
}