package security import ( "encoding/base64" "strings" "testing" ) func TestCredentialCipherRoundTrip(t *testing.T) { key := base64.StdEncoding.EncodeToString([]byte(strings.Repeat("k", 32))) cipher, err := NewCredentialCipher(key) if err != nil { t.Fatal(err) } ciphertext, err := cipher.Encrypt("upstream-secret") if err != nil { t.Fatal(err) } plaintext, err := cipher.Decrypt(ciphertext) if err != nil { t.Fatal(err) } if plaintext != "upstream-secret" { t.Fatalf("unexpected plaintext: %q", plaintext) } ciphertext[len(ciphertext)-1] ^= 1 if _, err := cipher.Decrypt(ciphertext); err == nil { t.Fatal("expected authentication failure for modified ciphertext") } }