summaryrefslogtreecommitdiff
path: root/internal/controlplane/mail_operations_test.go
diff options
context:
space:
mode:
authorChia <Chia@93.nz>2026-08-05 22:01:29 +1200
committerChia <Chia@93.nz>2026-08-05 22:07:50 +1200
commiteadb2ffe85c43cf6fc741c9823cd28eedb4a844c (patch)
tree1aba2536d57360da403aa35c9ced58b615c7064e /internal/controlplane/mail_operations_test.go
parentcd0dd91ab93653631904f2ea0e574ccde6d60339 (diff)
feat: harden prepaid billing and commercial operations
Diffstat (limited to 'internal/controlplane/mail_operations_test.go')
-rw-r--r--internal/controlplane/mail_operations_test.go29
1 files changed, 29 insertions, 0 deletions
diff --git a/internal/controlplane/mail_operations_test.go b/internal/controlplane/mail_operations_test.go
new file mode 100644
index 0000000..0b47cdb
--- /dev/null
+++ b/internal/controlplane/mail_operations_test.go
@@ -0,0 +1,29 @@
+package controlplane
+
+import (
+ "crypto/hmac"
+ "crypto/sha256"
+ "encoding/hex"
+ "strconv"
+ "testing"
+ "time"
+)
+
+func TestMailFeedbackSignature(t *testing.T) {
+ now := time.Unix(1_800_000_000, 0).UTC()
+ timestamp := strconv.FormatInt(now.Unix(), 10)
+ body := []byte(`{"event_id":"evt_1","event_type":"bounce","recipient":"test@example.com","provider":"test"}`)
+ mac := hmac.New(sha256.New, []byte("a-production-length-feedback-secret"))
+ _, _ = mac.Write([]byte(timestamp + "."))
+ _, _ = mac.Write(body)
+ signature := "sha256=" + hex.EncodeToString(mac.Sum(nil))
+ if !validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now) {
+ t.Fatal("valid signature was rejected")
+ }
+ if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, []byte(`{}`), now) {
+ t.Fatal("signature must bind the raw body")
+ }
+ if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now.Add(6*time.Minute)) {
+ t.Fatal("stale signature was accepted")
+ }
+}