48 lines
1.8 KiB
Go
48 lines
1.8 KiB
Go
package rpc
|
|
|
|
import (
|
|
"context"
|
|
"crypto/tls"
|
|
"crypto/x509"
|
|
"testing"
|
|
|
|
agentpb "git.ipao.vip/rogee/go-sip/gen/agent"
|
|
"google.golang.org/grpc/codes"
|
|
"google.golang.org/grpc/credentials"
|
|
"google.golang.org/grpc/peer"
|
|
"google.golang.org/grpc/status"
|
|
)
|
|
|
|
func TestRecordingPeerRequiresVerifiedPinnedCertificate(t *testing.T) {
|
|
meta := &agentpb.RequestMeta{AgentId: "agent-mock"}
|
|
certificate := &x509.Certificate{Raw: []byte("isolated-agent-certificate")}
|
|
fingerprint := CertificateFingerprint(certificate)
|
|
approved := map[string]struct{}{fingerprint: {}}
|
|
verified := peer.NewContext(context.Background(), &peer.Peer{AuthInfo: credentials.TLSInfo{
|
|
State: tls.ConnectionState{VerifiedChains: [][]*x509.Certificate{{certificate}}},
|
|
}})
|
|
unverified := peer.NewContext(context.Background(), &peer.Peer{AuthInfo: credentials.TLSInfo{
|
|
State: tls.ConnectionState{PeerCertificates: []*x509.Certificate{certificate}},
|
|
}})
|
|
for _, tc := range []struct {
|
|
name string
|
|
ctx context.Context
|
|
meta *agentpb.RequestMeta
|
|
fingerprints map[string]struct{}
|
|
want codes.Code
|
|
}{
|
|
{"missing metadata", verified, nil, approved, codes.InvalidArgument},
|
|
{"missing mTLS", context.Background(), meta, approved, codes.Unauthenticated},
|
|
{"unverified certificate", unverified, meta, approved, codes.Unauthenticated},
|
|
{"missing fingerprints", verified, meta, nil, codes.PermissionDenied},
|
|
{"unapproved certificate", verified, meta, map[string]struct{}{"different": {}}, codes.PermissionDenied},
|
|
{"approved certificate", verified, meta, approved, codes.OK},
|
|
} {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
if got := status.Code(verifyRecordingPeer(tc.ctx, tc.meta, tc.fingerprints)); got != tc.want {
|
|
t.Fatalf("peer decision = %v, want %v", got, tc.want)
|
|
}
|
|
})
|
|
}
|
|
}
|