2020-01-31 16:56:52 +01:00
|
|
|
/* eslint-disable @typescript-eslint/no-unused-expressions,@typescript-eslint/require-await */
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
import 'mocha'
|
|
|
|
import { expect } from 'chai'
|
|
|
|
import { cloneDeep } from 'lodash'
|
2021-12-17 11:58:15 +01:00
|
|
|
import { buildRequestStub } from '@server/tests/shared'
|
|
|
|
import { buildAbsoluteFixturePath } from '@shared/core-utils'
|
2018-10-23 11:38:48 +02:00
|
|
|
import { buildSignedActivity } from '../../../helpers/activitypub'
|
2021-07-13 09:43:59 +02:00
|
|
|
import { isHTTPSignatureVerified, isJsonLDSignatureVerified, parseHTTPSignature } from '../../../helpers/peertube-crypto'
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
describe('Test activity pub helpers', function () {
|
|
|
|
describe('When checking the Linked Signature', function () {
|
|
|
|
|
|
|
|
it('Should fail with an invalid Mastodon signature', async function () {
|
2021-06-14 16:52:22 +02:00
|
|
|
const body = require(buildAbsoluteFixturePath('./ap-json/mastodon/create-bad-signature.json'))
|
|
|
|
const publicKey = require(buildAbsoluteFixturePath('./ap-json/mastodon/public-key.json')).publicKey
|
2018-10-23 11:38:48 +02:00
|
|
|
const fromActor = { publicKey, url: 'http://localhost:9002/accounts/peertube' }
|
|
|
|
|
|
|
|
const result = await isJsonLDSignatureVerified(fromActor as any, body)
|
|
|
|
|
|
|
|
expect(result).to.be.false
|
|
|
|
})
|
|
|
|
|
|
|
|
it('Should fail with an invalid public key', async function () {
|
2021-06-14 16:52:22 +02:00
|
|
|
const body = require(buildAbsoluteFixturePath('./ap-json/mastodon/create.json'))
|
|
|
|
const publicKey = require(buildAbsoluteFixturePath('./ap-json/mastodon/bad-public-key.json')).publicKey
|
2018-10-23 11:38:48 +02:00
|
|
|
const fromActor = { publicKey, url: 'http://localhost:9002/accounts/peertube' }
|
|
|
|
|
|
|
|
const result = await isJsonLDSignatureVerified(fromActor as any, body)
|
|
|
|
|
|
|
|
expect(result).to.be.false
|
|
|
|
})
|
|
|
|
|
|
|
|
it('Should succeed with a valid Mastodon signature', async function () {
|
2021-06-14 16:52:22 +02:00
|
|
|
const body = require(buildAbsoluteFixturePath('./ap-json/mastodon/create.json'))
|
|
|
|
const publicKey = require(buildAbsoluteFixturePath('./ap-json/mastodon/public-key.json')).publicKey
|
2018-10-23 11:38:48 +02:00
|
|
|
const fromActor = { publicKey, url: 'http://localhost:9002/accounts/peertube' }
|
|
|
|
|
|
|
|
const result = await isJsonLDSignatureVerified(fromActor as any, body)
|
|
|
|
|
|
|
|
expect(result).to.be.true
|
|
|
|
})
|
|
|
|
|
|
|
|
it('Should fail with an invalid PeerTube signature', async function () {
|
2021-06-14 16:52:22 +02:00
|
|
|
const keys = require(buildAbsoluteFixturePath('./ap-json/peertube/invalid-keys.json'))
|
|
|
|
const body = require(buildAbsoluteFixturePath('./ap-json/peertube/announce-without-context.json'))
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
const actorSignature = { url: 'http://localhost:9002/accounts/peertube', privateKey: keys.privateKey }
|
|
|
|
const signedBody = await buildSignedActivity(actorSignature as any, body)
|
|
|
|
|
|
|
|
const fromActor = { publicKey: keys.publicKey, url: 'http://localhost:9002/accounts/peertube' }
|
|
|
|
const result = await isJsonLDSignatureVerified(fromActor as any, signedBody)
|
|
|
|
|
|
|
|
expect(result).to.be.false
|
|
|
|
})
|
|
|
|
|
|
|
|
it('Should succeed with a valid PeerTube signature', async function () {
|
2021-06-14 16:52:22 +02:00
|
|
|
const keys = require(buildAbsoluteFixturePath('./ap-json/peertube/keys.json'))
|
|
|
|
const body = require(buildAbsoluteFixturePath('./ap-json/peertube/announce-without-context.json'))
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
const actorSignature = { url: 'http://localhost:9002/accounts/peertube', privateKey: keys.privateKey }
|
|
|
|
const signedBody = await buildSignedActivity(actorSignature as any, body)
|
|
|
|
|
|
|
|
const fromActor = { publicKey: keys.publicKey, url: 'http://localhost:9002/accounts/peertube' }
|
|
|
|
const result = await isJsonLDSignatureVerified(fromActor as any, signedBody)
|
|
|
|
|
|
|
|
expect(result).to.be.true
|
|
|
|
})
|
|
|
|
})
|
|
|
|
|
|
|
|
describe('When checking HTTP signature', function () {
|
|
|
|
it('Should fail with an invalid http signature', async function () {
|
|
|
|
const req = buildRequestStub()
|
|
|
|
req.method = 'POST'
|
|
|
|
req.url = '/accounts/ronan/inbox'
|
|
|
|
|
2021-06-14 16:52:22 +02:00
|
|
|
const mastodonObject = cloneDeep(require(buildAbsoluteFixturePath('./ap-json/mastodon/bad-http-signature.json')))
|
2018-10-23 11:38:48 +02:00
|
|
|
req.body = mastodonObject.body
|
|
|
|
req.headers = mastodonObject.headers
|
|
|
|
|
2018-12-07 14:23:05 +01:00
|
|
|
const parsed = parseHTTPSignature(req, 3600 * 1000 * 365 * 10)
|
2021-06-14 16:52:22 +02:00
|
|
|
const publicKey = require(buildAbsoluteFixturePath('./ap-json/mastodon/public-key.json')).publicKey
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
const actor = { publicKey }
|
|
|
|
const verified = isHTTPSignatureVerified(parsed, actor as any)
|
|
|
|
|
|
|
|
expect(verified).to.be.false
|
|
|
|
})
|
|
|
|
|
|
|
|
it('Should fail with an invalid public key', async function () {
|
|
|
|
const req = buildRequestStub()
|
|
|
|
req.method = 'POST'
|
|
|
|
req.url = '/accounts/ronan/inbox'
|
|
|
|
|
2021-06-14 16:52:22 +02:00
|
|
|
const mastodonObject = cloneDeep(require(buildAbsoluteFixturePath('./ap-json/mastodon/http-signature.json')))
|
2018-10-23 11:38:48 +02:00
|
|
|
req.body = mastodonObject.body
|
|
|
|
req.headers = mastodonObject.headers
|
|
|
|
|
2018-12-07 14:23:05 +01:00
|
|
|
const parsed = parseHTTPSignature(req, 3600 * 1000 * 365 * 10)
|
2021-06-14 16:52:22 +02:00
|
|
|
const publicKey = require(buildAbsoluteFixturePath('./ap-json/mastodon/bad-public-key.json')).publicKey
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
const actor = { publicKey }
|
|
|
|
const verified = isHTTPSignatureVerified(parsed, actor as any)
|
|
|
|
|
|
|
|
expect(verified).to.be.false
|
|
|
|
})
|
|
|
|
|
|
|
|
it('Should fail because of clock skew', async function () {
|
|
|
|
const req = buildRequestStub()
|
|
|
|
req.method = 'POST'
|
|
|
|
req.url = '/accounts/ronan/inbox'
|
|
|
|
|
2021-06-14 16:52:22 +02:00
|
|
|
const mastodonObject = cloneDeep(require(buildAbsoluteFixturePath('./ap-json/mastodon/http-signature.json')))
|
2018-10-23 11:38:48 +02:00
|
|
|
req.body = mastodonObject.body
|
|
|
|
req.headers = mastodonObject.headers
|
|
|
|
|
|
|
|
let errored = false
|
|
|
|
try {
|
|
|
|
parseHTTPSignature(req)
|
|
|
|
} catch {
|
|
|
|
errored = true
|
|
|
|
}
|
|
|
|
|
|
|
|
expect(errored).to.be.true
|
|
|
|
})
|
|
|
|
|
2020-01-08 15:11:38 +01:00
|
|
|
it('Should with a scheme', async function () {
|
2018-10-23 11:38:48 +02:00
|
|
|
const req = buildRequestStub()
|
|
|
|
req.method = 'POST'
|
|
|
|
req.url = '/accounts/ronan/inbox'
|
|
|
|
|
2021-06-14 16:52:22 +02:00
|
|
|
const mastodonObject = cloneDeep(require(buildAbsoluteFixturePath('./ap-json/mastodon/http-signature.json')))
|
2018-10-23 11:38:48 +02:00
|
|
|
req.body = mastodonObject.body
|
|
|
|
req.headers = mastodonObject.headers
|
2020-01-08 15:11:38 +01:00
|
|
|
req.headers = 'Signature ' + mastodonObject.headers
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
let errored = false
|
|
|
|
try {
|
2018-12-07 14:23:05 +01:00
|
|
|
parseHTTPSignature(req, 3600 * 1000 * 365 * 10)
|
2018-10-23 11:38:48 +02:00
|
|
|
} catch {
|
|
|
|
errored = true
|
|
|
|
}
|
|
|
|
|
|
|
|
expect(errored).to.be.true
|
|
|
|
})
|
|
|
|
|
|
|
|
it('Should succeed with a valid signature', async function () {
|
|
|
|
const req = buildRequestStub()
|
|
|
|
req.method = 'POST'
|
|
|
|
req.url = '/accounts/ronan/inbox'
|
|
|
|
|
2021-06-14 16:52:22 +02:00
|
|
|
const mastodonObject = cloneDeep(require(buildAbsoluteFixturePath('./ap-json/mastodon/http-signature.json')))
|
2018-10-23 11:38:48 +02:00
|
|
|
req.body = mastodonObject.body
|
|
|
|
req.headers = mastodonObject.headers
|
|
|
|
|
2018-12-07 14:23:05 +01:00
|
|
|
const parsed = parseHTTPSignature(req, 3600 * 1000 * 365 * 10)
|
2021-06-14 16:52:22 +02:00
|
|
|
const publicKey = require(buildAbsoluteFixturePath('./ap-json/mastodon/public-key.json')).publicKey
|
2018-10-23 11:38:48 +02:00
|
|
|
|
|
|
|
const actor = { publicKey }
|
|
|
|
const verified = isHTTPSignatureVerified(parsed, actor as any)
|
|
|
|
|
|
|
|
expect(verified).to.be.true
|
|
|
|
})
|
|
|
|
|
|
|
|
})
|
|
|
|
|
|
|
|
})
|