summaryrefslogtreecommitdiffstats
path: root/modules/auth/password/pwn/pwn_test.go
blob: e5108150ae3f22189bc405a0f57c9f3ed14f1142 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
// Copyright 2023 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT

package pwn

import (
	"net/http"
	"testing"
	"time"

	"github.com/h2non/gock"
	"github.com/stretchr/testify/assert"
	"github.com/stretchr/testify/require"
)

var client = New(WithHTTP(&http.Client{
	Timeout: time.Second * 2,
}))

func TestPassword(t *testing.T) {
	defer gock.Off()

	count, err := client.CheckPassword("", false)
	require.ErrorIs(t, err, ErrEmptyPassword, "blank input should return ErrEmptyPassword")
	assert.Equal(t, -1, count)

	gock.New("https://api.pwnedpasswords.com").Get("/range/5c1d8").Times(1).Reply(200).BodyString("EAF2F254732680E8AC339B84F3266ECCBB5:1\r\nFC446EB88938834178CB9322C1EE273C2A7:2")
	count, err = client.CheckPassword("pwned", false)
	require.NoError(t, err)
	assert.Equal(t, 1, count)

	gock.New("https://api.pwnedpasswords.com").Get("/range/ba189").Times(1).Reply(200).BodyString("FD4CB34F0378BCB15D23F6FFD28F0775C9E:3\r\nFDF342FCD8C3611DAE4D76E8A992A3E4169:4")
	count, err = client.CheckPassword("notpwned", false)
	require.NoError(t, err)
	assert.Equal(t, 0, count)

	gock.New("https://api.pwnedpasswords.com").Get("/range/a1733").Times(1).Reply(200).BodyString("C4CE0F1F0062B27B9E2F41AF0C08218017C:1\r\nFC446EB88938834178CB9322C1EE273C2A7:2\r\nFE81480327C992FE62065A827429DD1318B:0")
	count, err = client.CheckPassword("paddedpwned", true)
	require.NoError(t, err)
	assert.Equal(t, 1, count)

	gock.New("https://api.pwnedpasswords.com").Get("/range/5617b").Times(1).Reply(200).BodyString("FD4CB34F0378BCB15D23F6FFD28F0775C9E:3\r\nFDF342FCD8C3611DAE4D76E8A992A3E4169:4\r\nFE81480327C992FE62065A827429DD1318B:0")
	count, err = client.CheckPassword("paddednotpwned", true)
	require.NoError(t, err)
	assert.Equal(t, 0, count)

	gock.New("https://api.pwnedpasswords.com").Get("/range/79082").Times(1).Reply(200).BodyString("FDF342FCD8C3611DAE4D76E8A992A3E4169:4\r\nFE81480327C992FE62065A827429DD1318B:0\r\nAFEF386F56EB0B4BE314E07696E5E6E6536:0")
	count, err = client.CheckPassword("paddednotpwnedzero", true)
	require.NoError(t, err)
	assert.Equal(t, 0, count)
}