67 lines
1.8 KiB
JavaScript
67 lines
1.8 KiB
JavaScript
import assert from "node:assert/strict"
|
|
import test from "node:test"
|
|
|
|
import {isProtectedFragmentTokenForForm} from "./protected_token_fragment.mjs"
|
|
|
|
const rawToken = "a".repeat(43)
|
|
const signedToken = `SFMyNTY.${"b".repeat(64)}.${"c".repeat(43)}`
|
|
|
|
test("raw account tokens remain limited to one 43-character segment", () => {
|
|
assert.equal(
|
|
isProtectedFragmentTokenForForm("magic-link-fragment-form", rawToken),
|
|
true
|
|
)
|
|
assert.equal(
|
|
isProtectedFragmentTokenForForm("email-change-fragment-form", rawToken),
|
|
true
|
|
)
|
|
assert.equal(
|
|
isProtectedFragmentTokenForForm("magic-link-fragment-form", signedToken),
|
|
false
|
|
)
|
|
})
|
|
|
|
test("support and removal forms accept Phoenix SHA-256 signed tokens", () => {
|
|
assert.equal(
|
|
isProtectedFragmentTokenForForm("support-confirmation-fragment-form", signedToken),
|
|
true
|
|
)
|
|
assert.equal(
|
|
isProtectedFragmentTokenForForm(
|
|
"content-removal-confirmation-fragment-form",
|
|
signedToken
|
|
),
|
|
true
|
|
)
|
|
assert.equal(
|
|
isProtectedFragmentTokenForForm("support-confirmation-fragment-form", rawToken),
|
|
false
|
|
)
|
|
})
|
|
|
|
test("malformed signed tokens are rejected", () => {
|
|
const candidates = [
|
|
`SFMyNTY.${"b".repeat(64)}.${"c".repeat(42)}`,
|
|
`SFMyNTY.${"b".repeat(64)}.${"c".repeat(44)}`,
|
|
`SFMyNTY.${"b".repeat(64)}.${"c".repeat(42)}+`,
|
|
`SFMyNTY..${"c".repeat(43)}`,
|
|
`SFMyNTY.${"b".repeat(64)}.${"c".repeat(43)}?extra=1`,
|
|
`token=${signedToken}`
|
|
]
|
|
|
|
for (const candidate of candidates) {
|
|
assert.equal(
|
|
isProtectedFragmentTokenForForm(
|
|
"support-confirmation-fragment-form",
|
|
candidate
|
|
),
|
|
false
|
|
)
|
|
}
|
|
})
|
|
|
|
test("unknown forms do not inherit a token format", () => {
|
|
assert.equal(isProtectedFragmentTokenForForm("unknown-form", rawToken), false)
|
|
assert.equal(isProtectedFragmentTokenForForm("unknown-form", signedToken), false)
|
|
})
|