summaryrefslogtreecommitdiff
path: root/internal/controlplane/mail_operations_test.go
blob: 0b47cdbef8966dd869ed7375fccdb6109c707c9d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
package controlplane

import (
	"crypto/hmac"
	"crypto/sha256"
	"encoding/hex"
	"strconv"
	"testing"
	"time"
)

func TestMailFeedbackSignature(t *testing.T) {
	now := time.Unix(1_800_000_000, 0).UTC()
	timestamp := strconv.FormatInt(now.Unix(), 10)
	body := []byte(`{"event_id":"evt_1","event_type":"bounce","recipient":"test@example.com","provider":"test"}`)
	mac := hmac.New(sha256.New, []byte("a-production-length-feedback-secret"))
	_, _ = mac.Write([]byte(timestamp + "."))
	_, _ = mac.Write(body)
	signature := "sha256=" + hex.EncodeToString(mac.Sum(nil))
	if !validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now) {
		t.Fatal("valid signature was rejected")
	}
	if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, []byte(`{}`), now) {
		t.Fatal("signature must bind the raw body")
	}
	if validMailFeedbackSignature("a-production-length-feedback-secret", timestamp, signature, body, now.Add(6*time.Minute)) {
		t.Fatal("stale signature was accepted")
	}
}