mirror of
https://github.com/superseriousbusiness/gotosocial.git
synced 2025-01-30 19:52:25 +00:00
5b765d734e
* Update push subscription API model to be Mastodon 4.0 compatible * Add webpush-go dependency # Conflicts: # go.sum * Single-row table for storing instance's VAPID key pair * Generate VAPID key pair during startup * Add VAPID public key to instance info API * Return VAPID public key when registering an app * Store Web Push subscriptions in DB * Add Web Push sender (similar to email sender) * Add no-op push senders to most processor tests * Test Web Push notifications from workers * Delete Web Push subscriptions when account is deleted * Implement push subscription API * Linter fixes * Update Swagger * Fix enum to int migration * Fix GetVAPIDKeyPair * Create web push subscriptions table with indexes * Log Web Push server error messages * Send instance URL as Web Push JWT subject * Accept any 2xx code as a success * Fix malformed VAPID sub claim * Use packed notification flags * Remove unused date columns * Add notification type for update notifications Not used yet * Make GetVAPIDKeyPair idempotent and remove PutVAPIDKeyPair * Post-rebase fixes * go mod tidy * Special-case 400 errors other than 408/429 Most client errors should remove the subscription. * Improve titles, trim body to reasonable length * Disallow cleartext HTTP for Web Push servers * Fix lint * Remove redundant index on unique column Also removes redundant unique and notnull tags on ID column since these are implied by pk * Make realsender.go more readable * Use Tobi's style for wrapping errors * Restore treating all 5xx codes as temporary problems * Always load target account settings * Stub `policy` and `standard` * webpush.Sender: take type converter as ctor param * Move webpush.MockSender and noopSender into testrig
141 lines
5 KiB
Go
141 lines
5 KiB
Go
// GoToSocial
|
|
// Copyright (C) GoToSocial Authors admin@gotosocial.org
|
|
// SPDX-License-Identifier: AGPL-3.0-or-later
|
|
//
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
// (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU Affero General Public License for more details.
|
|
//
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
package auth_test
|
|
|
|
import (
|
|
"bytes"
|
|
"fmt"
|
|
"net/http/httptest"
|
|
|
|
"github.com/gin-contrib/sessions"
|
|
"github.com/gin-contrib/sessions/memstore"
|
|
"github.com/gin-gonic/gin"
|
|
"github.com/stretchr/testify/suite"
|
|
"github.com/superseriousbusiness/gotosocial/internal/admin"
|
|
"github.com/superseriousbusiness/gotosocial/internal/api/auth"
|
|
"github.com/superseriousbusiness/gotosocial/internal/config"
|
|
"github.com/superseriousbusiness/gotosocial/internal/db"
|
|
"github.com/superseriousbusiness/gotosocial/internal/email"
|
|
"github.com/superseriousbusiness/gotosocial/internal/federation"
|
|
"github.com/superseriousbusiness/gotosocial/internal/gtsmodel"
|
|
"github.com/superseriousbusiness/gotosocial/internal/media"
|
|
"github.com/superseriousbusiness/gotosocial/internal/middleware"
|
|
"github.com/superseriousbusiness/gotosocial/internal/oidc"
|
|
"github.com/superseriousbusiness/gotosocial/internal/processing"
|
|
"github.com/superseriousbusiness/gotosocial/internal/state"
|
|
"github.com/superseriousbusiness/gotosocial/internal/storage"
|
|
"github.com/superseriousbusiness/gotosocial/testrig"
|
|
)
|
|
|
|
type AuthStandardTestSuite struct {
|
|
suite.Suite
|
|
db db.DB
|
|
storage *storage.Driver
|
|
state state.State
|
|
mediaManager *media.Manager
|
|
federator *federation.Federator
|
|
processor *processing.Processor
|
|
emailSender email.Sender
|
|
idp oidc.IDP
|
|
|
|
// standard suite models
|
|
testTokens map[string]*gtsmodel.Token
|
|
testClients map[string]*gtsmodel.Client
|
|
testApplications map[string]*gtsmodel.Application
|
|
testUsers map[string]*gtsmodel.User
|
|
testAccounts map[string]*gtsmodel.Account
|
|
|
|
// module being tested
|
|
authModule *auth.Module
|
|
}
|
|
|
|
const (
|
|
sessionUserID = "userid"
|
|
sessionClientID = "client_id"
|
|
)
|
|
|
|
func (suite *AuthStandardTestSuite) SetupSuite() {
|
|
suite.testTokens = testrig.NewTestTokens()
|
|
suite.testClients = testrig.NewTestClients()
|
|
suite.testApplications = testrig.NewTestApplications()
|
|
suite.testUsers = testrig.NewTestUsers()
|
|
suite.testAccounts = testrig.NewTestAccounts()
|
|
}
|
|
|
|
func (suite *AuthStandardTestSuite) SetupTest() {
|
|
suite.state.Caches.Init()
|
|
|
|
testrig.InitTestConfig()
|
|
testrig.InitTestLog()
|
|
|
|
suite.db = testrig.NewTestDB(&suite.state)
|
|
suite.state.DB = suite.db
|
|
suite.state.AdminActions = admin.New(suite.state.DB, &suite.state.Workers)
|
|
suite.storage = testrig.NewInMemoryStorage()
|
|
suite.state.Storage = suite.storage
|
|
suite.mediaManager = testrig.NewTestMediaManager(&suite.state)
|
|
suite.federator = testrig.NewTestFederator(&suite.state, testrig.NewTestTransportController(&suite.state, testrig.NewMockHTTPClient(nil, "../../../testrig/media")), suite.mediaManager)
|
|
suite.emailSender = testrig.NewEmailSender("../../../web/template/", nil)
|
|
suite.processor = testrig.NewTestProcessor(
|
|
&suite.state,
|
|
suite.federator,
|
|
suite.emailSender,
|
|
testrig.NewNoopWebPushSender(),
|
|
suite.mediaManager,
|
|
)
|
|
suite.authModule = auth.New(suite.db, suite.processor, suite.idp)
|
|
|
|
testrig.StandardDBSetup(suite.db, suite.testAccounts)
|
|
testrig.StartNoopWorkers(&suite.state)
|
|
}
|
|
|
|
func (suite *AuthStandardTestSuite) TearDownTest() {
|
|
testrig.StandardDBTeardown(suite.db)
|
|
testrig.StopWorkers(&suite.state)
|
|
}
|
|
|
|
func (suite *AuthStandardTestSuite) newContext(requestMethod string, requestPath string, requestBody []byte, bodyContentType string) (*gin.Context, *httptest.ResponseRecorder) {
|
|
// create the recorder and gin test context
|
|
recorder := httptest.NewRecorder()
|
|
ctx, engine := testrig.CreateGinTestContext(recorder, nil)
|
|
|
|
// load templates into the engine
|
|
testrig.ConfigureTemplatesWithGin(engine, "../../../web/template")
|
|
|
|
// create the request
|
|
protocol := config.GetProtocol()
|
|
host := config.GetHost()
|
|
baseURI := fmt.Sprintf("%s://%s", protocol, host)
|
|
requestURI := fmt.Sprintf("%s/%s", baseURI, requestPath)
|
|
|
|
ctx.Request = httptest.NewRequest(requestMethod, requestURI, bytes.NewReader(requestBody)) // the endpoint we're hitting
|
|
ctx.Request.Header.Set("accept", "text/html")
|
|
|
|
if bodyContentType != "" {
|
|
ctx.Request.Header.Set("Content-Type", bodyContentType)
|
|
}
|
|
|
|
// trigger the session middleware on the context
|
|
store := memstore.NewStore(make([]byte, 32), make([]byte, 32))
|
|
store.Options(middleware.SessionOptions())
|
|
sessionMiddleware := sessions.Sessions("gotosocial-localhost", store)
|
|
sessionMiddleware(ctx)
|
|
|
|
return ctx, recorder
|
|
}
|