1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
|
package adminapi
import (
"encoding/json"
"net/http"
"net/http/httptest"
"testing"
"aigw/internal/controlplane"
)
func TestBootstrapActorHasNoDatabaseUserID(t *testing.T) {
handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler()
request := httptest.NewRequest(http.MethodGet, "/admin/api/me", nil)
request.Header.Set("Authorization", "Bearer bootstrap-secret")
response := httptest.NewRecorder()
handler.ServeHTTP(response, request)
if response.Code != http.StatusOK {
t.Fatalf("bootstrap me status = %d, body = %s", response.Code, response.Body.String())
}
var payload struct {
Actor controlplane.ConsoleActor `json:"actor"`
}
if err := json.Unmarshal(response.Body.Bytes(), &payload); err != nil {
t.Fatal(err)
}
if !payload.Actor.Bootstrap || payload.Actor.ID != "" || payload.Actor.Role != controlplane.RolePlatformAdmin {
t.Fatalf("unexpected bootstrap actor: %+v", payload.Actor)
}
}
func TestBootstrapSecurityEndpointsDoNotQueryUserUUID(t *testing.T) {
handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler()
for _, test := range []struct {
path string
wantStatus int
}{
{path: "/admin/api/auth/mfa", wantStatus: http.StatusBadRequest},
{path: "/admin/api/auth/sessions", wantStatus: http.StatusOK},
} {
request := httptest.NewRequest(http.MethodGet, test.path, nil)
request.Header.Set("Authorization", "Bearer bootstrap-secret")
response := httptest.NewRecorder()
handler.ServeHTTP(response, request)
if response.Code != test.wantStatus {
t.Fatalf("%s status = %d, want %d; body = %s", test.path, response.Code, test.wantStatus, response.Body.String())
}
}
}
func TestBootstrapBillingResolutionActorUsesTextEvidenceID(t *testing.T) {
actor := billingResolutionActor(controlplane.ConsoleActor{Bootstrap: true, Role: controlplane.RolePlatformAdmin}, "bootstrap")
if actor.ID != "bootstrap" || actor.Type != "bootstrap" {
t.Fatalf("unexpected resolution actor: %+v", actor)
}
}
|