package controlplane import ( "crypto/hmac" "crypto/sha256" "encoding/hex" "strconv" "testing" "time" ) func TestMailFeedbackSignature(t *testing.T) { now := time.Unix(1_800_000_000, 0).UTC() timestamp := strconv.FormatInt(now.Unix(), 10) body := []byte(`{"event_id":"evt_1","event_type":"bounce","recipient":"test@example.com","provider":"test"}`) mac := hmac.New(sha256.New, []byte("a-production-length-feedback-secret")) _, _ = mac.Write([]byte(timestamp + ".")) _, _ = mac.Write(body) signature := "sha256=" + hex.EncodeToString(mac.Sum(nil)) if !validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now) { t.Fatal("valid signature was rejected") } if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, []byte(`{}`), now) { t.Fatal("signature must bind the raw body") } if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now.Add(6*time.Minute)) { t.Fatal("stale signature was accepted") } }