user-engine/tests/test_account_identity_disclosure.py

107 lines
4.8 KiB
Python
Raw Normal View History

"""An existing NetKingdom sign-in is shown before the account site continues it."""
import unittest
from urllib.parse import parse_qs, urlparse
import test_portal_navigation
from test_web import invoke
class RecordingLookup:
def __init__(self, result):
self.result = result
self.headers = []
def username(self, header):
self.headers.append(header)
if isinstance(self.result, BaseException):
raise self.result
if callable(self.result):
return self.result(header)
return self.result
class AccountIdentityDisclosureTests(unittest.TestCase):
setUp = test_portal_navigation.PortalNavigationTests.setUp
def test_confirmed_sign_in_is_named_before_the_account_site_continues(self):
def answer(header):
if "authelia_session=super-secret-session" in header:
return "platform-root"
return None
self.app.identity_lookup = RecordingLookup(answer)
cookie = "ue_session=absent; authelia_session=super-secret-session"
response, body = invoke(self.app, "/", cookie=cookie)
self.assertEqual("200 OK", response["status"])
self.assertEqual(1, len(self.app.identity_lookup.headers))
self.assertIn(b"NetKingdom sign-in is <strong>platform-root</strong>", body)
self.assertIn(b"This account site has no session yet.", body)
self.assertIn(b'href="/login">Continue as platform-root', body)
self.assertIn(b'href="/login?fresh=1">Use a different identity', body)
self.assertNotIn(b"Not signed in", body)
self.assertNotIn(b"You are not signed in.", body)
self.assertNotIn(b"Signed in as", body)
self.assertNotIn(b"super-secret-session", body)
self.assertNotIn(b"Active now", body)
_response, body = invoke(self.app, "/")
self.assertIn(b'href="/login">Sign in', body)
self.assertIn(b"Not signed in", body)
self.assertNotIn(b"platform-root", body)
self.assertEqual(2, len(self.app.identity_lookup.headers))
def test_account_session_is_not_replaced_by_the_netkingdom_cookie(self):
self.app.identity_lookup = RecordingLookup("platform-root")
_, body = invoke(
self.app, "/", cookie="ue_session=member; authelia_session=super-secret-session"
)
self.assertIn(b"Signed in as", body)
self.assertIn(b"sample.user", body)
self.assertNotIn(b"platform-root", body)
self.assertNotIn(b'href="/login"', body)
self.assertEqual([], self.app.identity_lookup.headers)
def test_lookup_failure_or_unsafe_name_stays_signed_out(self):
for result in [TimeoutError("slow"), "<script>alert(1)</script>", "platform root"]:
with self.subTest(result=result):
self.app.identity_lookup = RecordingLookup(result)
_, body = invoke(self.app, "/", cookie="authelia_session=opaque")
self.assertIn(b'href="/login">Sign in', body)
self.assertIn(b"You are not signed in.", body)
self.assertNotIn(b"Signed in as", body)
self.assertNotIn(b"<script>", body)
self.assertNotIn(b"platform root", body)
def test_logged_out_and_recovery_name_the_same_sign_in(self):
self.app.identity_lookup = RecordingLookup("platform-root")
cookie = "authelia_session=super-secret-session"
_, logged_out = invoke(self.app, "/logged-out", cookie=cookie)
self.assertIn(b"NetKingdom sign-in is <strong>platform-root</strong>", logged_out)
self.assertIn(b"This account site has no session yet.", logged_out)
self.assertNotIn(b"may still be active", logged_out)
self.assertNotIn(b"super-secret-session", logged_out)
self.assertIn(b"https://kc.example/account/logout", logged_out)
_, recovery = invoke(self.app, "/access-recovery", cookie=cookie)
self.assertIn(b"NetKingdom sign-in is <strong>platform-root</strong>", recovery)
self.assertNotIn(b"Signed in as", recovery)
self.assertIn(b"/logout", recovery)
def test_different_identity_requests_a_fresh_sign_in(self):
response, _body = invoke(self.app, "/login", query="fresh=1")
location = response["headers"]["Location"]
query = parse_qs(urlparse(location).query)
self.assertEqual(["login"], query["prompt"])
self.assertEqual(["0"], query["max_age"])
self.assertNotIn("acr_values", query)
def test_query_parameters_do_not_invent_the_shown_identity(self):
self.app.identity_lookup = RecordingLookup("platform-root")
_, body = invoke(
self.app,
"/",
query="username=forged",
cookie="authelia_session=super-secret-session",
)
self.assertIn(b"platform-root", body)
self.assertNotIn(b"forged", body)