3d7a2761fc
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
33 lines
1.2 KiB
Go
33 lines
1.2 KiB
Go
package web
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// R-133: with the wrong sealing key the reveal endpoint fails CLOSED — 500, no password in the body, nothing
|
|
// in the log, and no "revealed" event (nothing was delivered). The right-key path is TestReveal_B.
|
|
func TestR133_RevealWithWrongKeyFailsClosed(t *testing.T) {
|
|
s, st, logBuf := newRevealServer(t)
|
|
cookie, csrf := newRevealSession(t, s)
|
|
seedRevealHost(t, st, "demo-hp-bb76ea", "demo-hp", revealCanary)
|
|
if err := st.SetOffsiteSecretKey([]byte("another-key-of-exactly-32-bytes!")); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
req := httptest.NewRequest(http.MethodPost, "/hosts/demo-hp-bb76ea/reveal-recovery-credential", nil)
|
|
req.AddCookie(cookie)
|
|
req.Header.Set("X-CSRF-Token", csrf)
|
|
rr := serveReveal(t, s, req)
|
|
if rr.Code != http.StatusInternalServerError {
|
|
t.Fatalf("reveal with a wrong key = %d, want 500", rr.Code)
|
|
}
|
|
if strings.Contains(rr.Body.String(), revealCanary) || strings.Contains(logBuf.String(), revealCanary) {
|
|
t.Fatal("the secret leaked into the body or the log")
|
|
}
|
|
if n := countEvents(t, st, "demo-hp", "recovery_credential_revealed"); n != 0 {
|
|
t.Fatalf("%d reveal event(s) for a reveal that delivered nothing", n)
|
|
}
|
|
}
|