summaryrefslogtreecommitdiff
path: root/internal/controlplane/mail_operations_test.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/controlplane/mail_operations_test.go')
-rw-r--r--internal/controlplane/mail_operations_test.go29
1 files changed, 29 insertions, 0 deletions
diff --git a/internal/controlplane/mail_operations_test.go b/internal/controlplane/mail_operations_test.go
new file mode 100644
index 0000000..0b47cdb
--- /dev/null
+++ b/internal/controlplane/mail_operations_test.go
@@ -0,0 +1,29 @@
+package controlplane
+
+import (
+ "crypto/hmac"
+ "crypto/sha256"
+ "encoding/hex"
+ "strconv"
+ "testing"
+ "time"
+)
+
+func TestMailFeedbackSignature(t *testing.T) {
+ now := time.Unix(1_800_000_000, 0).UTC()
+ timestamp := strconv.FormatInt(now.Unix(), 10)
+ body := []byte(`{"event_id":"evt_1","event_type":"bounce","recipient":"test@example.com","provider":"test"}`)
+ mac := hmac.New(sha256.New, []byte("a-production-length-feedback-secret"))
+ _, _ = mac.Write([]byte(timestamp + "."))
+ _, _ = mac.Write(body)
+ signature := "sha256=" + hex.EncodeToString(mac.Sum(nil))
+ if !validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now) {
+ t.Fatal("valid signature was rejected")
+ }
+ if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, []byte(`{}`), now) {
+ t.Fatal("signature must bind the raw body")
+ }
+ if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now.Add(6*time.Minute)) {
+ t.Fatal("stale signature was accepted")
+ }
+}