"""The account site may name a NetKingdom sign-in only after Authelia confirms it.""" import json import threading import unittest from http.server import BaseHTTPRequestHandler, ThreadingHTTPServer from user_engine.identity_state import ( AutheliaIdentityState, authelia_session_token, username_from_state, validate_identity_state_host, validate_identity_state_url, _read_state, ) class IdentityStateUrlTests(unittest.TestCase): def test_accepts_the_cluster_state_endpoint_and_public_https(self): cluster = "http://authelia.sso.svc.cluster.local:9091/api/state" public = "https://login.coulomb.social/api/state" self.assertEqual(cluster, validate_identity_state_url(cluster)) self.assertEqual(public, validate_identity_state_url(public)) def test_public_sign_in_host_is_separate_from_the_cluster_address(self): self.assertEqual("login.coulomb.social", validate_identity_state_host("login.coulomb.social")) for host in [ "authelia.sso.svc.cluster.local", "login.coulomb.social:443", "https://login.coulomb.social", "login", " login.coulomb.social", ]: with self.subTest(host=host): with self.assertRaises(ValueError): validate_identity_state_host(host) def test_rejects_anything_that_could_carry_the_session_cookie_elsewhere(self): for url in [ "http://login.coulomb.social/api/state", "http://authelia.sso.svc.cluster.local.example/api/state", "http://169.254.169.254/api/state", "https://user:pass@login.coulomb.social/api/state", "https://login.coulomb.social/api/state?next=1", "https://login.coulomb.social/api/state#fragment", "https://login.coulomb.social/api/userinfo", "https://login.coulomb.social/api/state/", " https://login.coulomb.social/api/state", "http://svc.cluster.local/api/state", ]: with self.subTest(url=url): with self.assertRaises(ValueError): validate_identity_state_url(url) class IdentityStateParseTests(unittest.TestCase): def test_wrapped_and_flat_confirmed_usernames_are_accepted(self): wrapped = { "status": "OK", "data": {"username": "platform-root", "authentication_level": 1}, } flat = {"username": "bernd.worsch-99", "authentication_level": 2} self.assertEqual("platform-root", username_from_state(wrapped)) self.assertEqual("bernd.worsch-99", username_from_state(flat)) def test_unconfirmed_or_unsafe_answers_are_ignored(self): for payload in [ {"status": "OK", "data": {"username": "", "authentication_level": 0}}, {"status": "OK", "data": {"username": "platform-root", "authentication_level": 0}}, {"status": "OK", "data": {"username": "platform-root", "authentication_level": True}}, {"status": "KO", "data": {"username": "platform-root", "authentication_level": 1}}, {"username": "