"""An existing NetKingdom sign-in is shown before the account site continues it."""
import unittest
from urllib.parse import parse_qs, urlparse
import test_portal_navigation
from test_web import invoke
class RecordingLookup:
def __init__(self, result):
self.result = result
self.headers = []
def username(self, header):
self.headers.append(header)
if isinstance(self.result, BaseException):
raise self.result
if callable(self.result):
return self.result(header)
return self.result
class AccountIdentityDisclosureTests(unittest.TestCase):
setUp = test_portal_navigation.PortalNavigationTests.setUp
def test_confirmed_sign_in_is_named_before_the_account_site_continues(self):
def answer(header):
if "authelia_session=super-secret-session" in header:
return "platform-root"
return None
self.app.identity_lookup = RecordingLookup(answer)
cookie = "ue_session=absent; authelia_session=super-secret-session"
response, body = invoke(self.app, "/", cookie=cookie)
self.assertEqual("200 OK", response["status"])
self.assertEqual(1, len(self.app.identity_lookup.headers))
self.assertIn(b"NetKingdom sign-in is platform-root", body)
self.assertIn(b"This account site has no session yet.", body)
self.assertIn(b'href="/login">Continue as platform-root', body)
self.assertIn(b'href="/login?fresh=1">Use a different identity', body)
self.assertNotIn(b"Not signed in", body)
self.assertNotIn(b"You are not signed in.", body)
self.assertNotIn(b"Signed in as", body)
self.assertNotIn(b"super-secret-session", body)
self.assertNotIn(b"Active now", body)
_response, body = invoke(self.app, "/")
self.assertIn(b'href="/login">Sign in', body)
self.assertIn(b"Not signed in", body)
self.assertNotIn(b"platform-root", body)
self.assertEqual(2, len(self.app.identity_lookup.headers))
def test_account_session_is_not_replaced_by_the_netkingdom_cookie(self):
self.app.identity_lookup = RecordingLookup("platform-root")
_, body = invoke(
self.app, "/", cookie="ue_session=member; authelia_session=super-secret-session"
)
self.assertIn(b"Signed in as", body)
self.assertIn(b"sample.user", body)
self.assertNotIn(b"platform-root", body)
self.assertNotIn(b'href="/login"', body)
self.assertEqual([], self.app.identity_lookup.headers)
def test_lookup_failure_or_unsafe_name_stays_signed_out(self):
for result in [TimeoutError("slow"), "", "platform root"]:
with self.subTest(result=result):
self.app.identity_lookup = RecordingLookup(result)
_, body = invoke(self.app, "/", cookie="authelia_session=opaque")
self.assertIn(b'href="/login">Sign in', body)
self.assertIn(b"You are not signed in.", body)
self.assertNotIn(b"Signed in as", body)
self.assertNotIn(b"