generated from Nodarx/template
feat: implement initial read only access
Signed-off-by: Sebastian Krupinski <krupinski01@gmail.com>
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
|
||||
use KTXM\ServiceWopi\Host\ProofValidator;
|
||||
use PHPUnit\Framework\TestCase;
|
||||
|
||||
final class ProofTest extends TestCase
|
||||
{
|
||||
public function testProofBytesAndRotationWithIndependentOpenSslSignatures(): void
|
||||
{
|
||||
$randomFile = tempnam(sys_get_temp_dir(), 'wopi-test-random-');
|
||||
$previousRandomFile = getenv('RANDFILE');
|
||||
putenv('RANDFILE=' . $randomFile);
|
||||
try {
|
||||
$private = openssl_pkey_new(['private_key_bits' => 2048, 'private_key_type' => OPENSSL_KEYTYPE_RSA]);
|
||||
} finally {
|
||||
putenv($previousRandomFile === false ? 'RANDFILE' : 'RANDFILE=' . $previousRandomFile);
|
||||
unlink($randomFile);
|
||||
}
|
||||
$rsa = openssl_pkey_get_details($private)['rsa'];
|
||||
$keys = ['modulus' => base64_encode($rsa['n']), 'exponent' => base64_encode($rsa['e'])];
|
||||
$token = 'secret-token';
|
||||
$url = 'https://app.test/wopi/files/test?access_token=secret-token';
|
||||
$now = time();
|
||||
$timestamp = ($now + 62135596800) * 10000000;
|
||||
$upper = strtoupper($url);
|
||||
$data = pack('N', strlen($token)) . $token . pack('N', strlen($upper)) . $upper
|
||||
. pack('N', 8) . pack('N2', intdiv($timestamp, 4294967296), $timestamp % 4294967296);
|
||||
openssl_sign($data, $signed, $private, OPENSSL_ALGO_SHA256);
|
||||
$signature = base64_encode($signed);
|
||||
$validator = new ProofValidator();
|
||||
self::assertTrue($validator->valid($keys, $token, $url, (string) $timestamp, $signature, '', $now));
|
||||
self::assertTrue($validator->valid($keys, $token, $url, (string) $timestamp, '', $signature, $now));
|
||||
self::assertTrue($validator->valid(['oldmodulus' => $keys['modulus'], 'oldexponent' => $keys['exponent']], $token, $url, (string) $timestamp, $signature, '', $now));
|
||||
self::assertFalse($validator->valid($keys, 'wrong-token', $url, (string) $timestamp, $signature, '', $now));
|
||||
self::assertFalse($validator->valid($keys, $token, $url . '&extra=1', (string) $timestamp, $signature, '', $now));
|
||||
self::assertFalse($validator->valid($keys, $token, $url, (string) $timestamp, $signature, '', $now + 1201));
|
||||
self::assertFalse($validator->valid($keys, $token, $url, (string) $timestamp, $signature, '', $now - 1201));
|
||||
self::assertFalse($validator->valid([], $token, $url, (string) $timestamp, $signature, '', $now));
|
||||
self::assertFalse($validator->valid($keys, $token, $url, 'not-a-timestamp', $signature, '', $now));
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user