mirror of https://github.com/go-gitea/gitea.git
Backport #29205 (including #29172) Use a clearly defined "signing secret" for token signing.pull/29327/head
parent
7ea2ffaf16
commit
511298e452
@ -0,0 +1,34 @@
|
|||||||
|
// Copyright 2024 The Gitea Authors. All rights reserved.
|
||||||
|
// SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
package generate
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/base64"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/assert"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestDecodeJwtSecretBase64(t *testing.T) {
|
||||||
|
_, err := DecodeJwtSecretBase64("abcd")
|
||||||
|
assert.ErrorContains(t, err, "invalid base64 decoded length")
|
||||||
|
_, err = DecodeJwtSecretBase64(strings.Repeat("a", 64))
|
||||||
|
assert.ErrorContains(t, err, "invalid base64 decoded length")
|
||||||
|
|
||||||
|
str32 := strings.Repeat("x", 32)
|
||||||
|
encoded32 := base64.RawURLEncoding.EncodeToString([]byte(str32))
|
||||||
|
decoded32, err := DecodeJwtSecretBase64(encoded32)
|
||||||
|
assert.NoError(t, err)
|
||||||
|
assert.Equal(t, str32, string(decoded32))
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewJwtSecretWithBase64(t *testing.T) {
|
||||||
|
secret, encoded, err := NewJwtSecretWithBase64()
|
||||||
|
assert.NoError(t, err)
|
||||||
|
assert.Len(t, secret, 32)
|
||||||
|
decoded, err := DecodeJwtSecretBase64(encoded)
|
||||||
|
assert.NoError(t, err)
|
||||||
|
assert.Equal(t, secret, decoded)
|
||||||
|
}
|
||||||
@ -0,0 +1,34 @@
|
|||||||
|
// Copyright 2024 The Gitea Authors. All rights reserved.
|
||||||
|
// SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
|
package setting
|
||||||
|
|
||||||
|
import (
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"code.gitea.io/gitea/modules/generate"
|
||||||
|
"code.gitea.io/gitea/modules/test"
|
||||||
|
|
||||||
|
"github.com/stretchr/testify/assert"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestGetGeneralSigningSecret(t *testing.T) {
|
||||||
|
// when there is no general signing secret, it should be generated, and keep the same value
|
||||||
|
assert.Nil(t, generalSigningSecret.Load())
|
||||||
|
s1 := GetGeneralTokenSigningSecret()
|
||||||
|
assert.NotNil(t, s1)
|
||||||
|
s2 := GetGeneralTokenSigningSecret()
|
||||||
|
assert.Equal(t, s1, s2)
|
||||||
|
|
||||||
|
// the config value should always override any pre-generated value
|
||||||
|
cfg, _ := NewConfigProviderFromData(`
|
||||||
|
[oauth2]
|
||||||
|
JWT_SECRET = BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
|
||||||
|
`)
|
||||||
|
defer test.MockVariableValue(&InstallLock, true)()
|
||||||
|
loadOAuth2From(cfg)
|
||||||
|
actual := GetGeneralTokenSigningSecret()
|
||||||
|
expected, _ := generate.DecodeJwtSecretBase64("BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB")
|
||||||
|
assert.Len(t, actual, 32)
|
||||||
|
assert.EqualValues(t, expected, actual)
|
||||||
|
}
|
||||||
Loading…
Reference in New Issue