2022-09-16 08:02:08 +02:00
|
|
|
import path from 'path';
|
2021-10-29 17:33:05 +02:00
|
|
|
|
2022-09-16 08:02:08 +02:00
|
|
|
import { Config as AppConfig, ROLES, getDefaultConfig } from '@verdaccio/config';
|
2021-09-26 00:08:00 +02:00
|
|
|
import { errorUtils } from '@verdaccio/core';
|
2021-10-29 17:33:05 +02:00
|
|
|
import { setup } from '@verdaccio/logger';
|
|
|
|
import { Config } from '@verdaccio/types';
|
2019-07-16 08:40:01 +02:00
|
|
|
|
2020-08-11 07:21:51 +02:00
|
|
|
import { Auth } from '../src';
|
2021-10-29 17:33:05 +02:00
|
|
|
import { authPluginFailureConf, authPluginPassThrougConf, authProfileConf } from './helper/plugin';
|
2020-03-03 23:59:19 +01:00
|
|
|
|
2023-04-22 20:55:45 +02:00
|
|
|
setup({ level: 'debug', type: 'stdout' });
|
2019-07-16 08:40:01 +02:00
|
|
|
|
|
|
|
describe('AuthTest', () => {
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should init correctly', async () => {
|
|
|
|
const config: Config = new AppConfig({ ...authProfileConf });
|
2021-11-05 16:29:48 +01:00
|
|
|
config.checkSecretKey('12345');
|
|
|
|
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
|
|
|
expect(auth).toBeDefined();
|
|
|
|
});
|
2019-07-16 08:40:01 +02:00
|
|
|
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should load default auth plugin', async () => {
|
|
|
|
const config: Config = new AppConfig({ ...authProfileConf, auth: undefined });
|
|
|
|
config.checkSecretKey('12345');
|
2023-04-22 20:55:45 +02:00
|
|
|
|
|
|
|
const auth: Auth = new Auth(config);
|
|
|
|
await auth.init();
|
|
|
|
expect(auth).toBeDefined();
|
|
|
|
});
|
|
|
|
|
|
|
|
test('should load custom algorithm', async () => {
|
|
|
|
const config: Config = new AppConfig({
|
|
|
|
...authProfileConf,
|
|
|
|
auth: { htpasswd: { algorithm: 'sha1', file: './foo' } },
|
|
|
|
});
|
|
|
|
config.checkSecretKey('12345');
|
2022-09-16 08:02:08 +02:00
|
|
|
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
2019-07-16 08:40:01 +02:00
|
|
|
expect(auth).toBeDefined();
|
|
|
|
});
|
|
|
|
|
|
|
|
describe('test authenticate method', () => {
|
|
|
|
describe('test authenticate states', () => {
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should be a success login', async () => {
|
|
|
|
const config: Config = new AppConfig({ ...authProfileConf });
|
2021-11-05 16:29:48 +01:00
|
|
|
config.checkSecretKey('12345');
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
2019-07-16 08:40:01 +02:00
|
|
|
expect(auth).toBeDefined();
|
|
|
|
|
|
|
|
const callback = jest.fn();
|
2020-08-13 23:27:00 +02:00
|
|
|
const groups = ['test'];
|
2019-07-16 08:40:01 +02:00
|
|
|
|
|
|
|
auth.authenticate('foo', 'bar', callback);
|
|
|
|
|
|
|
|
expect(callback).toHaveBeenCalledTimes(1);
|
2020-08-13 23:27:00 +02:00
|
|
|
expect(callback).toHaveBeenCalledWith(null, {
|
2020-09-17 06:48:16 +02:00
|
|
|
groups: [
|
|
|
|
'test',
|
|
|
|
ROLES.$ALL,
|
|
|
|
ROLES.$AUTH,
|
|
|
|
ROLES.DEPRECATED_ALL,
|
|
|
|
ROLES.DEPRECATED_AUTH,
|
|
|
|
ROLES.ALL,
|
|
|
|
],
|
2020-08-13 23:27:00 +02:00
|
|
|
name: 'foo',
|
|
|
|
real_groups: groups,
|
|
|
|
});
|
2019-07-16 08:40:01 +02:00
|
|
|
});
|
|
|
|
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should be a fail on login', async () => {
|
2022-08-19 20:25:20 +02:00
|
|
|
const config: Config = new AppConfig(authPluginFailureConf);
|
2021-11-05 16:29:48 +01:00
|
|
|
config.checkSecretKey('12345');
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
2019-07-16 08:40:01 +02:00
|
|
|
expect(auth).toBeDefined();
|
|
|
|
|
|
|
|
const callback = jest.fn();
|
|
|
|
|
|
|
|
auth.authenticate('foo', 'bar', callback);
|
|
|
|
expect(callback).toHaveBeenCalledTimes(1);
|
2021-09-26 00:08:00 +02:00
|
|
|
expect(callback).toHaveBeenCalledWith(errorUtils.getInternalError());
|
2019-07-16 08:40:01 +02:00
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
// plugins are free to send whatever they want, so, we need to test some scenarios
|
|
|
|
// that might make break the request
|
|
|
|
// the @ts-ignore below are intended
|
|
|
|
describe('test authenticate out of control inputs from plugins', () => {
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should skip falsy values', async () => {
|
|
|
|
const config: Config = new AppConfig({ ...authPluginPassThrougConf });
|
2021-11-05 16:29:48 +01:00
|
|
|
config.checkSecretKey('12345');
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
2019-07-16 08:40:01 +02:00
|
|
|
expect(auth).toBeDefined();
|
|
|
|
|
|
|
|
const callback = jest.fn();
|
|
|
|
let index = 0;
|
|
|
|
|
|
|
|
// as defined by https://developer.mozilla.org/en-US/docs/Glossary/Falsy
|
2020-08-13 23:27:00 +02:00
|
|
|
for (const value of [false, 0, '', null, undefined, NaN]) {
|
2019-07-16 08:40:01 +02:00
|
|
|
// @ts-ignore
|
|
|
|
auth.authenticate(null, value, callback);
|
|
|
|
const call = callback.mock.calls[index++];
|
|
|
|
expect(call[0]).toBeDefined();
|
|
|
|
expect(call[1]).toBeUndefined();
|
|
|
|
}
|
|
|
|
});
|
|
|
|
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should error truthy non-array', async () => {
|
|
|
|
const config: Config = new AppConfig({ ...authPluginPassThrougConf });
|
2021-11-05 16:29:48 +01:00
|
|
|
config.checkSecretKey('12345');
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
2019-07-16 08:40:01 +02:00
|
|
|
expect(auth).toBeDefined();
|
|
|
|
|
|
|
|
const callback = jest.fn();
|
|
|
|
|
2020-08-13 23:27:00 +02:00
|
|
|
for (const value of [true, 1, 'test', {}]) {
|
|
|
|
expect(function () {
|
2019-07-16 08:40:01 +02:00
|
|
|
// @ts-ignore
|
|
|
|
auth.authenticate(null, value, callback);
|
|
|
|
}).toThrow(TypeError);
|
|
|
|
expect(callback).not.toHaveBeenCalled();
|
|
|
|
}
|
|
|
|
});
|
|
|
|
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should skip empty array', async () => {
|
|
|
|
const config: Config = new AppConfig({ ...authPluginPassThrougConf });
|
2021-11-05 16:29:48 +01:00
|
|
|
config.checkSecretKey('12345');
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
2019-07-16 08:40:01 +02:00
|
|
|
expect(auth).toBeDefined();
|
|
|
|
|
|
|
|
const callback = jest.fn();
|
2020-08-13 23:27:00 +02:00
|
|
|
const value = [];
|
2019-07-16 08:40:01 +02:00
|
|
|
|
|
|
|
// @ts-ignore
|
|
|
|
auth.authenticate(null, value, callback);
|
|
|
|
expect(callback.mock.calls).toHaveLength(1);
|
|
|
|
expect(callback.mock.calls[0][0]).toBeDefined();
|
|
|
|
expect(callback.mock.calls[0][1]).toBeUndefined();
|
|
|
|
});
|
|
|
|
|
2022-09-16 08:02:08 +02:00
|
|
|
test('should accept valid array', async () => {
|
|
|
|
const config: Config = new AppConfig({ ...authPluginPassThrougConf });
|
2021-11-05 16:29:48 +01:00
|
|
|
config.checkSecretKey('12345');
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
2019-07-16 08:40:01 +02:00
|
|
|
expect(auth).toBeDefined();
|
|
|
|
|
|
|
|
const callback = jest.fn();
|
|
|
|
let index = 0;
|
|
|
|
|
2020-08-13 23:27:00 +02:00
|
|
|
for (const value of [[''], ['1'], ['0'], ['000']]) {
|
2019-07-16 08:40:01 +02:00
|
|
|
// @ts-ignore
|
|
|
|
auth.authenticate(null, value, callback);
|
|
|
|
const call = callback.mock.calls[index++];
|
|
|
|
expect(call[0]).toBeNull();
|
|
|
|
expect(call[1].real_groups).toBe(value);
|
|
|
|
}
|
|
|
|
});
|
|
|
|
});
|
2020-08-13 23:27:00 +02:00
|
|
|
});
|
2022-09-16 08:02:08 +02:00
|
|
|
|
|
|
|
describe('test multiple authenticate methods', () => {
|
|
|
|
test('should skip falsy values', async () => {
|
|
|
|
const config: Config = new AppConfig({
|
|
|
|
...getDefaultConfig(),
|
|
|
|
plugins: path.join(__dirname, './partials/plugin'),
|
|
|
|
auth: {
|
|
|
|
success: {},
|
|
|
|
'fail-invalid-method': {},
|
|
|
|
},
|
|
|
|
});
|
|
|
|
config.checkSecretKey('12345');
|
2022-10-11 23:06:55 +02:00
|
|
|
const auth: Auth = new Auth(config);
|
2022-09-16 08:02:08 +02:00
|
|
|
await auth.init();
|
|
|
|
|
|
|
|
return new Promise((resolve) => {
|
|
|
|
auth.authenticate('foo', 'bar', (err, value) => {
|
|
|
|
expect(value).toEqual({
|
|
|
|
name: 'foo',
|
|
|
|
groups: ['test', '$all', '$authenticated', '@all', '@authenticated', 'all'],
|
|
|
|
real_groups: ['test'],
|
|
|
|
});
|
|
|
|
resolve(value);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
});
|
|
|
|
});
|
2019-07-16 08:40:01 +02:00
|
|
|
});
|