Extract AppAPI auth and OCS preferences from CheckDNS.
Publish gonexapp v1 with Credentials, OCSClient, and parameterized AppAPIPreferences so ExApps share Nextcloud ExApp plumbing per ADR 0013. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
package gonexapp_test
|
||||
|
||||
import (
|
||||
"encoding/base64"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
"gitea.neitzel.de/konrad/go-nc-exapp"
|
||||
)
|
||||
|
||||
func TestUserFromRequestRoundTrip(t *testing.T) {
|
||||
token := base64.StdEncoding.EncodeToString([]byte("alice:secret"))
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
r.Header.Set("AUTHORIZATION-APP-API", token)
|
||||
user, err := gonexapp.UserFromRequest(r)
|
||||
if err != nil || user != "alice" {
|
||||
t.Fatalf("user=%q err=%v", user, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestUserFromRequestMissing(t *testing.T) {
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
_, err := gonexapp.UserFromRequest(r)
|
||||
if err == nil {
|
||||
t.Fatal("expected error for missing header")
|
||||
}
|
||||
}
|
||||
|
||||
func TestUserFromRequestInvalidBase64(t *testing.T) {
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
r.Header.Set("AUTHORIZATION-APP-API", "%%%")
|
||||
_, err := gonexapp.UserFromRequest(r)
|
||||
if err == nil {
|
||||
t.Fatal("expected error for invalid base64")
|
||||
}
|
||||
}
|
||||
|
||||
func TestUserFromRequestNoUserID(t *testing.T) {
|
||||
token := base64.StdEncoding.EncodeToString([]byte(":secret"))
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
r.Header.Set("AUTHORIZATION-APP-API", token)
|
||||
_, err := gonexapp.UserFromRequest(r)
|
||||
if err == nil {
|
||||
t.Fatal("expected error for empty user id")
|
||||
}
|
||||
}
|
||||
|
||||
func TestWithUser(t *testing.T) {
|
||||
cred := gonexapp.Credentials{UserID: "alice"}
|
||||
asBob := cred.WithUser("bob")
|
||||
if asBob.UserID != "bob" {
|
||||
t.Fatalf("user=%q", asBob.UserID)
|
||||
}
|
||||
if cred.UserID != "alice" {
|
||||
t.Fatalf("original mutated: %q", cred.UserID)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAuthHeaders(t *testing.T) {
|
||||
cred := gonexapp.Credentials{
|
||||
BaseURL: "https://nc.example",
|
||||
AppID: "myapp",
|
||||
AppVersion: "1.0.0",
|
||||
AAVersion: "2.0.0",
|
||||
AppSecret: "secret",
|
||||
UserID: "alice",
|
||||
}
|
||||
h := cred.AuthHeaders()
|
||||
if got := h.Get("EX-APP-ID"); got != "myapp" {
|
||||
t.Fatalf("EX-APP-ID=%q", got)
|
||||
}
|
||||
if got := h.Get("AA-VERSION"); got != "2.0.0" {
|
||||
t.Fatalf("AA-VERSION=%q", got)
|
||||
}
|
||||
wantToken := base64.StdEncoding.EncodeToString([]byte("alice:secret"))
|
||||
if got := h.Get("AUTHORIZATION-APP-API"); got != wantToken {
|
||||
t.Fatalf("AUTHORIZATION-APP-API=%q want %q", got, wantToken)
|
||||
}
|
||||
if got := h.Get("OCS-APIRequest"); got != "true" {
|
||||
t.Fatalf("OCS-APIRequest=%q", got)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user