Skip to content
Snippets Groups Projects
Commit 27b82674 authored by Amna Snene's avatar Amna Snene
Browse files

test: fix certstore tests

Change-Id: I7d6099ceeb031f3edd7d393c67cbf57957832d92
parent e853f505
No related branches found
No related tags found
No related merge requests found
...@@ -17,6 +17,7 @@ ...@@ -17,6 +17,7 @@
#include <cppunit/TestAssert.h> #include <cppunit/TestAssert.h>
#include <cppunit/TestFixture.h> #include <cppunit/TestFixture.h>
#include <cppunit/extensions/HelperMacros.h> #include <cppunit/extensions/HelperMacros.h>
#include <filesystem>
#include "test_runner.h" #include "test_runner.h"
#include "certstore.h" #include "certstore.h"
...@@ -35,9 +36,8 @@ public: ...@@ -35,9 +36,8 @@ public:
void setUp(); void setUp();
void tearDown(); void tearDown();
std::string aliceId; std::shared_ptr<tls::CertificateStore> aliceCertStore;
std::string bobId; std::shared_ptr<tls::TrustStore> aliceTrustStore;
private: private:
void trustStoreTest(); void trustStoreTest();
void getCertificateWithSplitted(); void getCertificateWithSplitted();
...@@ -55,122 +55,121 @@ CPPUNIT_TEST_SUITE_NAMED_REGISTRATION(CertStoreTest, CertStoreTest::name()); ...@@ -55,122 +55,121 @@ CPPUNIT_TEST_SUITE_NAMED_REGISTRATION(CertStoreTest, CertStoreTest::name());
void void
CertStoreTest::setUp() CertStoreTest::setUp()
{ {
/*auto actors = load_actors_and_wait_for_announcement("actors/alice-bob.yml"); aliceCertStore = std::make_shared<tls::CertificateStore>("aliceCertStore", nullptr);
aliceId = actors["alice"]; aliceTrustStore = std::make_shared<tls::TrustStore>(*aliceCertStore);
bobId = actors["bob"];*/
} }
void void
CertStoreTest::tearDown() CertStoreTest::tearDown()
{ {
//wait_for_removal_of({aliceId, bobId}); std::filesystem::remove_all("aliceCertStore");
aliceCertStore.reset();
aliceTrustStore.reset();
} }
void void
CertStoreTest::trustStoreTest() CertStoreTest::trustStoreTest()
{ {
//auto aliceAccount = Manager::instance().getAccount<JamiAccount>(aliceId);
auto ca = dht::crypto::generateIdentity("test CA"); auto ca = dht::crypto::generateIdentity("test CA");
auto account = dht::crypto::generateIdentity("test account", ca, 4096, true); auto account = dht::crypto::generateIdentity("test account", ca, 4096, true);
auto device = dht::crypto::generateIdentity("test device", account); auto device = dht::crypto::generateIdentity("test device", account);
auto device2 = dht::crypto::generateIdentity("test device 2", account); auto device2 = dht::crypto::generateIdentity("test device 2", account);
/*auto storeSize = aliceAccount->certStore().getPinnedCertificates().size(); auto storeSize = aliceCertStore->getPinnedCertificates().size();
auto id = ca.second->getId().toString(); auto id = ca.second->getId().toString();
auto pinned = aliceAccount->certStore().getPinnedCertificates(); auto pinned = aliceCertStore->getPinnedCertificates();
CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; }) CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; })
== pinned.end()); == pinned.end());
// Test certificate status // Test certificate status
auto certAllowed = aliceAccount->accountManager()->getCertificatesByStatus( auto certAllowed = aliceTrustStore->getCertificatesByStatus(
dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
CPPUNIT_ASSERT( CPPUNIT_ASSERT(
std::find_if(certAllowed.begin(), certAllowed.end(), [&](auto v) { return v == id; }) std::find_if(certAllowed.begin(), certAllowed.end(), [&](auto v) { return v == id; })
== certAllowed.end()); == certAllowed.end());
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(id) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(id)
== dhtnet::tls::TrustStore::PermissionStatus::UNDEFINED); == dhtnet::tls::TrustStore::PermissionStatus::UNDEFINED);
aliceAccount->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); aliceTrustStore->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
certAllowed = aliceAccount->accountManager()->getCertificatesByStatus( certAllowed = aliceTrustStore->getCertificatesByStatus(
dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
CPPUNIT_ASSERT( CPPUNIT_ASSERT(
std::find_if(certAllowed.begin(), certAllowed.end(), [&](auto v) { return v == id; }) std::find_if(certAllowed.begin(), certAllowed.end(), [&](auto v) { return v == id; })
!= certAllowed.end()); != certAllowed.end());
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(id) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(id)
== dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); == dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
aliceAccount->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::UNDEFINED); aliceTrustStore->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::UNDEFINED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(id) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(id)
== dhtnet::tls::TrustStore::PermissionStatus::UNDEFINED); == dhtnet::tls::TrustStore::PermissionStatus::UNDEFINED);
aliceAccount->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); aliceTrustStore->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(id) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(id)
== dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); == dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
// Test getPinnedCertificates // Test getPinnedCertificates
pinned = aliceAccount->certStore().getPinnedCertificates(); pinned = aliceCertStore->getPinnedCertificates();
CPPUNIT_ASSERT(pinned.size() == storeSize + 2); CPPUNIT_ASSERT(pinned.size() == storeSize + 2);
CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; }) CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; })
!= pinned.end()); != pinned.end());
// Test findCertificateByUID & findIssuer // Test findCertificateByUID & findIssuer
CPPUNIT_ASSERT(!aliceAccount->certStore().findCertificateByUID("NON_EXISTING_ID")); CPPUNIT_ASSERT(!aliceCertStore->findCertificateByUID("NON_EXISTING_ID"));
auto cert = aliceAccount->certStore().findCertificateByUID(id); auto cert = aliceCertStore->findCertificateByUID(id);
CPPUNIT_ASSERT(cert); CPPUNIT_ASSERT(cert);
auto issuer = aliceAccount->certStore().findIssuer(cert); auto issuer = aliceCertStore->findIssuer(cert);
CPPUNIT_ASSERT(issuer); CPPUNIT_ASSERT(issuer);
CPPUNIT_ASSERT(issuer->getId().toString() == id); CPPUNIT_ASSERT(issuer->getId().toString() == id);
// Test is allowed // Test is allowed
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*ca.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*ca.second));
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*account.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*account.second));
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*device.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*device.second));
// Ban device // Ban device
aliceAccount->setCertificateStatus(device.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED); aliceTrustStore->setCertificateStatus(device.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(device.second->getId().toString()) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(device.second->getId().toString())
== dhtnet::tls::TrustStore::PermissionStatus::BANNED); == dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(id) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(id)
== dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); == dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*ca.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*ca.second));
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*account.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*account.second));
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*device.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*device.second));
// Ban account // Ban account
aliceAccount->setCertificateStatus(account.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED); aliceTrustStore->setCertificateStatus(account.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(account.second->getId().toString()) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(account.second->getId().toString())
== dhtnet::tls::TrustStore::PermissionStatus::BANNED); == dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*ca.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*ca.second));
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*account.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*account.second));
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*device2.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*device2.second));
// Unban account // Unban account
aliceAccount->setCertificateStatus(account.second, aliceTrustStore->setCertificateStatus(account.second,
dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(account.second->getId().toString()) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(account.second->getId().toString())
== dhtnet::tls::TrustStore::PermissionStatus::ALLOWED); == dhtnet::tls::TrustStore::PermissionStatus::ALLOWED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*ca.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*ca.second));
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*account.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*account.second));
CPPUNIT_ASSERT(aliceAccount->accountManager()->isAllowed(*device2.second)); CPPUNIT_ASSERT(aliceTrustStore->isAllowed(*device2.second));
// Ban CA // Ban CA
aliceAccount->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED); aliceTrustStore->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(ca.second->getId().toString()) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(ca.second->getId().toString())
== dhtnet::tls::TrustStore::PermissionStatus::BANNED); == dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*ca.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*ca.second));
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*account.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*account.second));
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*device2.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*device2.second));
aliceAccount->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED); aliceTrustStore->setCertificateStatus(ca.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(ca.second->getId().toString()) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(ca.second->getId().toString())
== dhtnet::tls::TrustStore::PermissionStatus::BANNED); == dhtnet::tls::TrustStore::PermissionStatus::BANNED);
// Test unpin // Test unpin
aliceAccount->certStore().unpinCertificate(id); aliceCertStore->unpinCertificate(id);
pinned = aliceAccount->certStore().getPinnedCertificates(); pinned = aliceCertStore->getPinnedCertificates();
CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; }) CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; })
== pinned.end()); == pinned.end());
// Test statusToStr // Test statusToStr
CPPUNIT_ASSERT(strcmp(dhtnet::tls::statusToStr(dhtnet::tls::TrustStatus::TRUSTED), /*CPPUNIT_ASSERT(strcmp(dhtnet::tls::statusToStr(dhtnet::tls::TrustStatus::TRUSTED),
libdhtnet::Certificate::TrustStatus::TRUSTED) libdhtnet::Certificate::TrustStatus::TRUSTED)
== 0); == 0);
CPPUNIT_ASSERT(strcmp(dhtnet::tls::statusToStr(dhtnet::tls::TrustStatus::UNTRUSTED), CPPUNIT_ASSERT(strcmp(dhtnet::tls::statusToStr(dhtnet::tls::TrustStatus::UNTRUSTED),
...@@ -181,7 +180,6 @@ CertStoreTest::trustStoreTest() ...@@ -181,7 +180,6 @@ CertStoreTest::trustStoreTest()
void void
CertStoreTest::getCertificateWithSplitted() CertStoreTest::getCertificateWithSplitted()
{ {
//auto aliceAccount = Manager::instance().getAccount<JamiAccount>(aliceId);
auto ca = dht::crypto::generateIdentity("test CA"); auto ca = dht::crypto::generateIdentity("test CA");
auto account = dht::crypto::generateIdentity("test account", ca, 4096, true); auto account = dht::crypto::generateIdentity("test account", ca, 4096, true);
auto device = dht::crypto::generateIdentity("test device", account); auto device = dht::crypto::generateIdentity("test device", account);
...@@ -191,37 +189,35 @@ CertStoreTest::getCertificateWithSplitted() ...@@ -191,37 +189,35 @@ CertStoreTest::getCertificateWithSplitted()
auto devicePartialCert = std::make_shared<dht::crypto::Certificate>( auto devicePartialCert = std::make_shared<dht::crypto::Certificate>(
device.second->toString(false)); device.second->toString(false));
/*aliceAccount->certStore().pinCertificate(caCert); aliceCertStore->pinCertificate(caCert);
aliceAccount->certStore().pinCertificate(accountCert); aliceCertStore->pinCertificate(accountCert);
aliceAccount->certStore().pinCertificate(devicePartialCert); aliceCertStore->pinCertificate(devicePartialCert);
auto fullCert = aliceAccount->certStore().getCertificate(device.second->getId().toString()); auto fullCert = aliceCertStore->getCertificate(device.second->getId().toString());
CPPUNIT_ASSERT(fullCert->issuer && fullCert->issuer->getUID() == accountCert->getUID()); CPPUNIT_ASSERT(fullCert->issuer && fullCert->issuer->getUID() == accountCert->getUID());
CPPUNIT_ASSERT(fullCert->issuer->issuer CPPUNIT_ASSERT(fullCert->issuer->issuer
&& fullCert->issuer->issuer->getUID() == caCert->getUID());*/ && fullCert->issuer->issuer->getUID() == caCert->getUID());
} }
void void
CertStoreTest::testBannedParent() CertStoreTest::testBannedParent()
{ {
/*auto aliceAccount = Manager::instance().getAccount<JamiAccount>(aliceId);
auto ca = dht::crypto::generateIdentity("test CA"); auto ca = dht::crypto::generateIdentity("test CA");
auto account = dht::crypto::generateIdentity("test account", ca, 4096, true); auto account = dht::crypto::generateIdentity("test account", ca, 4096, true);
auto device = dht::crypto::generateIdentity("test device", account); auto device = dht::crypto::generateIdentity("test device", account);
auto device2 = dht::crypto::generateIdentity("test device 2", account); auto device2 = dht::crypto::generateIdentity("test device 2", account);
auto id = ca.second->getId().toString(); auto id = ca.second->getId().toString();
auto pinned = aliceAccount->certStore().getPinnedCertificates(); auto pinned = aliceCertStore ->getPinnedCertificates();
CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; }) CPPUNIT_ASSERT(std::find_if(pinned.begin(), pinned.end(), [&](auto v) { return v == id; })
== pinned.end()); == pinned.end());
// Ban account // Ban account
aliceAccount->setCertificateStatus(account.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED); aliceTrustStore->setCertificateStatus(account.second, dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(aliceAccount->accountManager()->getCertificateStatus(account.second->getId().toString()) CPPUNIT_ASSERT(aliceTrustStore->getCertificateStatus(account.second->getId().toString())
== dhtnet::tls::TrustStore::PermissionStatus::BANNED); == dhtnet::tls::TrustStore::PermissionStatus::BANNED);
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*account.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*account.second));
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*device2.second)); CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*device2.second));
CPPUNIT_ASSERT(not aliceAccount->accountManager()->isAllowed(*device.second));*/ CPPUNIT_ASSERT(not aliceTrustStore->isAllowed(*device.second));
} }
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment