summaryrefslogtreecommitdiff
path: root/internal/controlplane/api_key_test.go
blob: 51a3a7da2135ef39dda63f81f19b73df428b4f42 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
package controlplane

import (
	"crypto/sha256"
	"strings"
	"testing"
)

func TestGenerateAPIKeySecretReturnsOnlyDisplayFragments(t *testing.T) {
	raw, prefix, suffix, hash, err := generateAPIKeySecret()
	if err != nil {
		t.Fatal(err)
	}
	if !strings.HasPrefix(raw, "sk-aigw-") || !strings.HasPrefix(raw, strings.TrimSuffix(prefix, "...")) {
		t.Fatalf("prefix %q does not identify the generated key", prefix)
	}
	if len(suffix) != 6 || !strings.HasSuffix(raw, suffix) {
		t.Fatalf("suffix %q does not identify the generated key", suffix)
	}
	if len(prefix)+len(suffix) >= len(raw) {
		t.Fatal("display fragments reveal the complete key")
	}
	if hash != sha256.Sum256([]byte(raw)) {
		t.Fatal("generated digest does not authenticate the raw key")
	}
}