"""An existing NetKingdom sign-in is shown before the account site continues it.""" import unittest from urllib.parse import parse_qs, urlparse import test_portal_navigation from test_web import invoke class RecordingLookup: def __init__(self, result): self.result = result self.headers = [] def username(self, header): self.headers.append(header) if isinstance(self.result, BaseException): raise self.result if callable(self.result): return self.result(header) return self.result class AccountIdentityDisclosureTests(unittest.TestCase): setUp = test_portal_navigation.PortalNavigationTests.setUp def test_confirmed_sign_in_is_named_before_the_account_site_continues(self): def answer(header): if "authelia_session=super-secret-session" in header: return "platform-root" return None self.app.identity_lookup = RecordingLookup(answer) cookie = "ue_session=absent; authelia_session=super-secret-session" response, body = invoke(self.app, "/", cookie=cookie) self.assertEqual("200 OK", response["status"]) self.assertEqual(1, len(self.app.identity_lookup.headers)) self.assertIn(b"NetKingdom sign-in is platform-root", body) self.assertIn(b"This account site has no session yet.", body) self.assertIn(b'href="/login">Continue as platform-root', body) self.assertIn(b'href="/login?fresh=1">Use a different identity', body) self.assertNotIn(b"Not signed in", body) self.assertNotIn(b"You are not signed in.", body) self.assertNotIn(b"Signed in as", body) self.assertNotIn(b"super-secret-session", body) self.assertNotIn(b"Active now", body) _response, body = invoke(self.app, "/") self.assertIn(b'href="/login">Sign in', body) self.assertIn(b"Not signed in", body) self.assertNotIn(b"platform-root", body) self.assertEqual(2, len(self.app.identity_lookup.headers)) def test_account_session_is_not_replaced_by_the_netkingdom_cookie(self): self.app.identity_lookup = RecordingLookup("platform-root") _, body = invoke( self.app, "/", cookie="ue_session=member; authelia_session=super-secret-session" ) self.assertIn(b"Signed in as", body) self.assertIn(b"sample.user", body) self.assertNotIn(b"platform-root", body) self.assertNotIn(b'href="/login"', body) self.assertEqual([], self.app.identity_lookup.headers) def test_lookup_failure_or_unsafe_name_stays_signed_out(self): for result in [TimeoutError("slow"), "", "platform root"]: with self.subTest(result=result): self.app.identity_lookup = RecordingLookup(result) _, body = invoke(self.app, "/", cookie="authelia_session=opaque") self.assertIn(b'href="/login">Sign in', body) self.assertIn(b"You are not signed in.", body) self.assertNotIn(b"Signed in as", body) self.assertNotIn(b"