2019-02-20 12:27:28 +03:00
|
|
|
# Pleroma: A lightweight social networking server
|
2021-01-13 07:49:20 +01:00
|
|
|
# Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
|
2019-02-20 12:27:28 +03:00
|
|
|
# SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
|
2020-06-23 18:16:47 +03:00
|
|
|
defmodule Pleroma.Web.Plugs.OAuthScopesPlugTest do
|
2023-08-01 11:43:50 +01:00
|
|
|
use Pleroma.Web.ConnCase, async: false
|
2023-08-04 12:50:50 +01:00
|
|
|
@moduletag :mocked
|
2019-02-20 12:27:28 +03:00
|
|
|
|
|
|
|
alias Pleroma.Repo
|
2020-06-24 13:07:47 +03:00
|
|
|
alias Pleroma.Web.Plugs.OAuthScopesPlug
|
2019-02-20 12:27:28 +03:00
|
|
|
|
2019-09-17 22:19:39 +03:00
|
|
|
import Mock
|
2019-02-20 12:27:28 +03:00
|
|
|
import Pleroma.Factory
|
|
|
|
|
2020-04-15 21:19:16 +03:00
|
|
|
test "is not performed if marked as skipped", %{conn: conn} do
|
|
|
|
with_mock OAuthScopesPlug, [:passthrough], perform: &passthrough([&1, &2]) do
|
|
|
|
conn =
|
|
|
|
conn
|
2020-04-17 21:21:10 +03:00
|
|
|
|> OAuthScopesPlug.skip_plug()
|
2020-04-15 21:19:16 +03:00
|
|
|
|> OAuthScopesPlug.call(%{scopes: ["random_scope"]})
|
|
|
|
|
|
|
|
refute called(OAuthScopesPlug.perform(:_, :_))
|
|
|
|
refute conn.halted
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-09-17 22:19:39 +03:00
|
|
|
test "if `token.scopes` fulfills specified 'any of' conditions, " <>
|
|
|
|
"proceeds with no op",
|
|
|
|
%{conn: conn} do
|
2019-02-20 12:27:28 +03:00
|
|
|
token = insert(:oauth_token, scopes: ["read", "write"]) |> Repo.preload(:user)
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn
|
|
|
|
|> assign(:user, token.user)
|
|
|
|
|> assign(:token, token)
|
|
|
|
|> OAuthScopesPlug.call(%{scopes: ["read"]})
|
|
|
|
|
|
|
|
refute conn.halted
|
|
|
|
assert conn.assigns[:user]
|
|
|
|
end
|
|
|
|
|
2019-09-17 22:19:39 +03:00
|
|
|
test "if `token.scopes` fulfills specified 'all of' conditions, " <>
|
|
|
|
"proceeds with no op",
|
|
|
|
%{conn: conn} do
|
2019-02-20 12:27:28 +03:00
|
|
|
token = insert(:oauth_token, scopes: ["scope1", "scope2", "scope3"]) |> Repo.preload(:user)
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn
|
|
|
|
|> assign(:user, token.user)
|
|
|
|
|> assign(:token, token)
|
|
|
|
|> OAuthScopesPlug.call(%{scopes: ["scope2", "scope3"], op: :&})
|
|
|
|
|
|
|
|
refute conn.halted
|
|
|
|
assert conn.assigns[:user]
|
|
|
|
end
|
|
|
|
|
2019-09-17 22:19:39 +03:00
|
|
|
describe "with `fallback: :proceed_unauthenticated` option, " do
|
2019-12-15 22:32:42 +03:00
|
|
|
test "if `token.scopes` doesn't fulfill specified conditions, " <>
|
2020-04-21 16:29:19 +03:00
|
|
|
"clears :user and :token assigns",
|
2019-09-17 22:19:39 +03:00
|
|
|
%{conn: conn} do
|
2019-12-15 22:32:42 +03:00
|
|
|
user = insert(:user)
|
|
|
|
token1 = insert(:oauth_token, scopes: ["read", "write"], user: user)
|
|
|
|
|
|
|
|
for token <- [token1, nil], op <- [:|, :&] do
|
|
|
|
ret_conn =
|
|
|
|
conn
|
|
|
|
|> assign(:user, user)
|
|
|
|
|> assign(:token, token)
|
|
|
|
|> OAuthScopesPlug.call(%{
|
|
|
|
scopes: ["follow"],
|
|
|
|
op: op,
|
|
|
|
fallback: :proceed_unauthenticated
|
|
|
|
})
|
|
|
|
|
|
|
|
refute ret_conn.halted
|
|
|
|
refute ret_conn.assigns[:user]
|
|
|
|
refute ret_conn.assigns[:token]
|
|
|
|
end
|
2019-09-17 22:19:39 +03:00
|
|
|
end
|
2019-02-20 12:27:28 +03:00
|
|
|
end
|
|
|
|
|
2019-09-17 22:19:39 +03:00
|
|
|
describe "without :fallback option, " do
|
|
|
|
test "if `token.scopes` does not fulfill specified 'any of' conditions, " <>
|
|
|
|
"returns 403 and halts",
|
|
|
|
%{conn: conn} do
|
2019-12-15 22:32:42 +03:00
|
|
|
for token <- [insert(:oauth_token, scopes: ["read", "write"]), nil] do
|
|
|
|
any_of_scopes = ["follow", "push"]
|
2019-02-20 12:27:28 +03:00
|
|
|
|
2019-12-15 22:32:42 +03:00
|
|
|
ret_conn =
|
|
|
|
conn
|
|
|
|
|> assign(:token, token)
|
|
|
|
|> OAuthScopesPlug.call(%{scopes: any_of_scopes})
|
2019-09-17 22:19:39 +03:00
|
|
|
|
2019-12-15 22:32:42 +03:00
|
|
|
assert ret_conn.halted
|
|
|
|
assert 403 == ret_conn.status
|
2019-09-17 22:19:39 +03:00
|
|
|
|
2019-12-15 22:32:42 +03:00
|
|
|
expected_error = "Insufficient permissions: #{Enum.join(any_of_scopes, " | ")}."
|
|
|
|
assert Jason.encode!(%{error: expected_error}) == ret_conn.resp_body
|
|
|
|
end
|
2019-09-17 22:19:39 +03:00
|
|
|
end
|
2019-02-20 12:27:28 +03:00
|
|
|
|
2019-09-17 22:19:39 +03:00
|
|
|
test "if `token.scopes` does not fulfill specified 'all of' conditions, " <>
|
|
|
|
"returns 403 and halts",
|
|
|
|
%{conn: conn} do
|
2019-12-15 22:32:42 +03:00
|
|
|
for token <- [insert(:oauth_token, scopes: ["read", "write"]), nil] do
|
|
|
|
token_scopes = (token && token.scopes) || []
|
|
|
|
all_of_scopes = ["write", "follow"]
|
2019-02-20 12:27:28 +03:00
|
|
|
|
2019-12-15 22:32:42 +03:00
|
|
|
conn =
|
|
|
|
conn
|
|
|
|
|> assign(:token, token)
|
|
|
|
|> OAuthScopesPlug.call(%{scopes: all_of_scopes, op: :&})
|
2019-02-20 12:27:28 +03:00
|
|
|
|
2019-12-15 22:32:42 +03:00
|
|
|
assert conn.halted
|
|
|
|
assert 403 == conn.status
|
2019-09-17 22:19:39 +03:00
|
|
|
|
2019-12-15 22:32:42 +03:00
|
|
|
expected_error =
|
|
|
|
"Insufficient permissions: #{Enum.join(all_of_scopes -- token_scopes, " & ")}."
|
2019-09-17 22:19:39 +03:00
|
|
|
|
2019-12-15 22:32:42 +03:00
|
|
|
assert Jason.encode!(%{error: expected_error}) == conn.resp_body
|
|
|
|
end
|
2019-09-17 22:19:39 +03:00
|
|
|
end
|
2019-02-20 12:27:28 +03:00
|
|
|
end
|
2019-09-08 15:00:03 +03:00
|
|
|
|
|
|
|
describe "with hierarchical scopes, " do
|
2019-09-17 22:19:39 +03:00
|
|
|
test "if `token.scopes` fulfills specified 'any of' conditions, " <>
|
|
|
|
"proceeds with no op",
|
|
|
|
%{conn: conn} do
|
2019-09-08 15:00:03 +03:00
|
|
|
token = insert(:oauth_token, scopes: ["read", "write"]) |> Repo.preload(:user)
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn
|
|
|
|
|> assign(:user, token.user)
|
|
|
|
|> assign(:token, token)
|
|
|
|
|> OAuthScopesPlug.call(%{scopes: ["read:something"]})
|
|
|
|
|
|
|
|
refute conn.halted
|
|
|
|
assert conn.assigns[:user]
|
|
|
|
end
|
|
|
|
|
2019-09-17 22:19:39 +03:00
|
|
|
test "if `token.scopes` fulfills specified 'all of' conditions, " <>
|
|
|
|
"proceeds with no op",
|
|
|
|
%{conn: conn} do
|
2019-09-08 15:00:03 +03:00
|
|
|
token = insert(:oauth_token, scopes: ["scope1", "scope2", "scope3"]) |> Repo.preload(:user)
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn
|
|
|
|
|> assign(:user, token.user)
|
|
|
|
|> assign(:token, token)
|
|
|
|
|> OAuthScopesPlug.call(%{scopes: ["scope1:subscope", "scope2:subscope"], op: :&})
|
|
|
|
|
|
|
|
refute conn.halted
|
|
|
|
assert conn.assigns[:user]
|
|
|
|
end
|
|
|
|
end
|
2019-09-17 22:19:39 +03:00
|
|
|
|
|
|
|
describe "filter_descendants/2" do
|
|
|
|
test "filters scopes which directly match or are ancestors of supported scopes" do
|
|
|
|
f = fn scopes, supported_scopes ->
|
|
|
|
OAuthScopesPlug.filter_descendants(scopes, supported_scopes)
|
|
|
|
end
|
|
|
|
|
|
|
|
assert f.(["read", "follow"], ["write", "read"]) == ["read"]
|
|
|
|
|
|
|
|
assert f.(["read", "write:something", "follow"], ["write", "read"]) ==
|
|
|
|
["read", "write:something"]
|
|
|
|
|
|
|
|
assert f.(["admin:read"], ["write", "read"]) == []
|
|
|
|
|
|
|
|
assert f.(["admin:read"], ["write", "admin"]) == ["admin:read"]
|
|
|
|
end
|
|
|
|
end
|
2019-02-20 12:27:28 +03:00
|
|
|
end
|