fix: cookie secret related test cases

Signed-off-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
Jan Larwig
2026-03-26 22:24:21 +01:00
parent bb30b83c6f
commit d0c125d173
22 changed files with 115 additions and 100 deletions
+3 -3
View File
@@ -49,12 +49,12 @@ func validateCookieName(name string) []string {
return msgs
}
func validateCookieSecret(secret options.SecretSource) []string {
if len(secret.Value) == 0 && secret.FromFile == "" {
func validateCookieSecret(secret *options.SecretSource) []string {
if secret == nil || len(secret.Value) == 0 && secret.FromFile == "" {
return []string{"missing setting: cookie-secret or cookie-secret-file"}
}
value, err := secret.GetSecretValue()
value, err := secret.GetRawSecretValue()
if err != nil {
return []string{fmt.Sprintf("error retrieving cookie secret: %v", err)}
}
+8 -8
View File
@@ -18,11 +18,11 @@ func TestValidateCookie(t *testing.T) {
invalidName := "_oauth2;proxy" // Separater character not allowed
// 10 times the alphabet should be longer than 256 characters
longName := strings.Repeat(alphabet, 10)
validSecret := options.SecretSource{
validSecret := &options.SecretSource{
Value: []byte("secretthirtytwobytes+abcdefghijk"),
}
// 6 bytes is not a valid size
invalidSecret := options.SecretSource{
invalidSecret := &options.SecretSource{
Value: []byte("abcdef"),
}
@@ -90,7 +90,7 @@ func TestValidateCookie(t *testing.T) {
name: "with no cookie secret",
cookie: options.Cookie{
Name: validName,
Secret: options.SecretSource{
Secret: &options.SecretSource{
Value: nil,
FromFile: "",
},
@@ -127,7 +127,7 @@ func TestValidateCookie(t *testing.T) {
name: "with a valid Base64 secret",
cookie: options.Cookie{
Name: validName,
Secret: validBase64Secret,
Secret: &validBase64Secret,
Domains: emptyDomains,
Path: "",
Expire: time.Hour,
@@ -142,7 +142,7 @@ func TestValidateCookie(t *testing.T) {
name: "with an invalid Base64 secret",
cookie: options.Cookie{
Name: validName,
Secret: invalidBase64Secret,
Secret: &invalidBase64Secret,
Domains: emptyDomains,
Path: "",
Expire: time.Hour,
@@ -307,7 +307,7 @@ func TestValidateCookie(t *testing.T) {
name: "with valid secret file",
cookie: options.Cookie{
Name: validName,
Secret: options.SecretSource{
Secret: &options.SecretSource{
FromFile: tmpfile.Name(),
},
Domains: domains,
@@ -324,7 +324,7 @@ func TestValidateCookie(t *testing.T) {
name: "with nonexistent secret file",
cookie: options.Cookie{
Name: validName,
Secret: options.SecretSource{
Secret: &options.SecretSource{
FromFile: "/nonexistent/file.txt",
},
Domains: domains,
@@ -335,7 +335,7 @@ func TestValidateCookie(t *testing.T) {
SameSite: "",
},
refresh: 0,
errStrings: []string{"could not read cookie secret file: /nonexistent/file.txt"},
errStrings: []string{"error retrieving cookie secret: error reading secret from file \"/nonexistent/file.txt\": open /nonexistent/file.txt: no such file or directory"},
},
}
+3 -9
View File
@@ -1,8 +1,6 @@
package validation
import (
"encoding/base64"
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/apis/options"
. "github.com/onsi/ginkgo/v2"
. "github.com/onsi/gomega"
@@ -29,9 +27,7 @@ var _ = Describe("Headers", func() {
Name: "X-Forwarded-Auth",
Values: []options.HeaderValue{
{
SecretSource: &options.SecretSource{
Value: []byte(base64.RawStdEncoding.EncodeToString([]byte("secret"))),
},
SecretSource: options.NewSecretSourceFromString("secret"),
},
},
}
@@ -41,10 +37,8 @@ var _ = Describe("Headers", func() {
Values: []options.HeaderValue{
{
ClaimSource: &options.ClaimSource{
Claim: "email",
BasicAuthPassword: &options.SecretSource{
Value: []byte(base64.RawStdEncoding.EncodeToString([]byte("secret"))),
},
Claim: "email",
BasicAuthPassword: options.NewSecretSourceFromString("secret"),
},
},
},
+7 -7
View File
@@ -20,7 +20,7 @@ const (
)
var (
cookieSecret = options.NewSecretSourceFromString("secretthirtytwobytes+abcdefghijk")
cookieSecret = &options.SecretSource{Value: []byte("secretthirtytwobytes+abcdefghijk")}
)
func testOptions() *options.Options {
@@ -128,7 +128,7 @@ func TestCookieRefreshMustBeLessThanCookieExpire(t *testing.T) {
o := testOptions()
assert.Equal(t, nil, Validate(o))
o.Cookie.Secret = options.NewSecretSourceFromString("0123456789abcdef")
o.Cookie.Secret = &options.SecretSource{Value: []byte("0123456789abcdef")}
o.Session.Refresh = o.Cookie.Expire
assert.NotEqual(t, nil, Validate(o))
@@ -141,23 +141,23 @@ func TestBase64CookieSecret(t *testing.T) {
assert.Equal(t, nil, Validate(o))
// 32 byte, base64 (urlsafe) encoded key
o.Cookie.Secret = options.NewSecretSourceFromString("yHBw2lh2Cvo6aI_jn_qMTr-pRAjtq0nzVgDJNb36jgQ=")
o.Cookie.Secret = &options.SecretSource{Value: []byte("yHBw2lh2Cvo6aI_jn_qMTr-pRAjtq0nzVgDJNb36jgQ=")}
assert.Equal(t, nil, Validate(o))
// 32 byte, base64 (urlsafe) encoded key, w/o padding
o.Cookie.Secret = options.NewSecretSourceFromString("yHBw2lh2Cvo6aI_jn_qMTr-pRAjtq0nzVgDJNb36jgQ")
o.Cookie.Secret = &options.SecretSource{Value: []byte("yHBw2lh2Cvo6aI_jn_qMTr-pRAjtq0nzVgDJNb36jgQ")}
assert.Equal(t, nil, Validate(o))
// 24 byte, base64 (urlsafe) encoded key
o.Cookie.Secret = options.NewSecretSourceFromString("Kp33Gj-GQmYtz4zZUyUDdqQKx5_Hgkv3")
o.Cookie.Secret = &options.SecretSource{Value: []byte("Kp33Gj-GQmYtz4zZUyUDdqQKx5_Hgkv3")}
assert.Equal(t, nil, Validate(o))
// 16 byte, base64 (urlsafe) encoded key
o.Cookie.Secret = options.NewSecretSourceFromString("LFEqZYvYUwKwzn0tEuTpLA==")
o.Cookie.Secret = &options.SecretSource{Value: []byte("LFEqZYvYUwKwzn0tEuTpLA==")}
assert.Equal(t, nil, Validate(o))
// 16 byte, base64 (urlsafe) encoded key, w/o padding
o.Cookie.Secret = options.NewSecretSourceFromString("LFEqZYvYUwKwzn0tEuTpLA")
o.Cookie.Secret = &options.SecretSource{Value: []byte("LFEqZYvYUwKwzn0tEuTpLA")}
assert.Equal(t, nil, Validate(o))
}