mirror of
				https://github.com/superseriousbusiness/gotosocial.git
				synced 2025-10-31 00:32:25 -05:00 
			
		
		
		
	* Update push subscription API model to be Mastodon 4.0 compatible * Add webpush-go dependency # Conflicts: # go.sum * Single-row table for storing instance's VAPID key pair * Generate VAPID key pair during startup * Add VAPID public key to instance info API * Return VAPID public key when registering an app * Store Web Push subscriptions in DB * Add Web Push sender (similar to email sender) * Add no-op push senders to most processor tests * Test Web Push notifications from workers * Delete Web Push subscriptions when account is deleted * Implement push subscription API * Linter fixes * Update Swagger * Fix enum to int migration * Fix GetVAPIDKeyPair * Create web push subscriptions table with indexes * Log Web Push server error messages * Send instance URL as Web Push JWT subject * Accept any 2xx code as a success * Fix malformed VAPID sub claim * Use packed notification flags * Remove unused date columns * Add notification type for update notifications Not used yet * Make GetVAPIDKeyPair idempotent and remove PutVAPIDKeyPair * Post-rebase fixes * go mod tidy * Special-case 400 errors other than 408/429 Most client errors should remove the subscription. * Improve titles, trim body to reasonable length * Disallow cleartext HTTP for Web Push servers * Fix lint * Remove redundant index on unique column Also removes redundant unique and notnull tags on ID column since these are implied by pk * Make realsender.go more readable * Use Tobi's style for wrapping errors * Restore treating all 5xx codes as temporary problems * Always load target account settings * Stub `policy` and `standard` * webpush.Sender: take type converter as ctor param * Move webpush.MockSender and noopSender into testrig
		
			
				
	
	
		
			140 lines
		
	
	
	
		
			5 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
			
		
		
	
	
			140 lines
		
	
	
	
		
			5 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
| // GoToSocial
 | |
| // Copyright (C) GoToSocial Authors admin@gotosocial.org
 | |
| // SPDX-License-Identifier: AGPL-3.0-or-later
 | |
| //
 | |
| // This program is free software: you can redistribute it and/or modify
 | |
| // it under the terms of the GNU Affero General Public License as published by
 | |
| // the Free Software Foundation, either version 3 of the License, or
 | |
| // (at your option) any later version.
 | |
| //
 | |
| // This program is distributed in the hope that it will be useful,
 | |
| // but WITHOUT ANY WARRANTY; without even the implied warranty of
 | |
| // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | |
| // GNU Affero General Public License for more details.
 | |
| //
 | |
| // You should have received a copy of the GNU Affero General Public License
 | |
| // along with this program.  If not, see <http://www.gnu.org/licenses/>.
 | |
| 
 | |
| package auth_test
 | |
| 
 | |
| import (
 | |
| 	"bytes"
 | |
| 	"fmt"
 | |
| 	"net/http/httptest"
 | |
| 
 | |
| 	"github.com/gin-contrib/sessions"
 | |
| 	"github.com/gin-contrib/sessions/memstore"
 | |
| 	"github.com/gin-gonic/gin"
 | |
| 	"github.com/stretchr/testify/suite"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/admin"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/api/auth"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/config"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/db"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/email"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/federation"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/gtsmodel"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/media"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/middleware"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/oidc"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/processing"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/state"
 | |
| 	"github.com/superseriousbusiness/gotosocial/internal/storage"
 | |
| 	"github.com/superseriousbusiness/gotosocial/testrig"
 | |
| )
 | |
| 
 | |
| type AuthStandardTestSuite struct {
 | |
| 	suite.Suite
 | |
| 	db           db.DB
 | |
| 	storage      *storage.Driver
 | |
| 	state        state.State
 | |
| 	mediaManager *media.Manager
 | |
| 	federator    *federation.Federator
 | |
| 	processor    *processing.Processor
 | |
| 	emailSender  email.Sender
 | |
| 	idp          oidc.IDP
 | |
| 
 | |
| 	// standard suite models
 | |
| 	testTokens       map[string]*gtsmodel.Token
 | |
| 	testClients      map[string]*gtsmodel.Client
 | |
| 	testApplications map[string]*gtsmodel.Application
 | |
| 	testUsers        map[string]*gtsmodel.User
 | |
| 	testAccounts     map[string]*gtsmodel.Account
 | |
| 
 | |
| 	// module being tested
 | |
| 	authModule *auth.Module
 | |
| }
 | |
| 
 | |
| const (
 | |
| 	sessionUserID   = "userid"
 | |
| 	sessionClientID = "client_id"
 | |
| )
 | |
| 
 | |
| func (suite *AuthStandardTestSuite) SetupSuite() {
 | |
| 	suite.testTokens = testrig.NewTestTokens()
 | |
| 	suite.testClients = testrig.NewTestClients()
 | |
| 	suite.testApplications = testrig.NewTestApplications()
 | |
| 	suite.testUsers = testrig.NewTestUsers()
 | |
| 	suite.testAccounts = testrig.NewTestAccounts()
 | |
| }
 | |
| 
 | |
| func (suite *AuthStandardTestSuite) SetupTest() {
 | |
| 	suite.state.Caches.Init()
 | |
| 
 | |
| 	testrig.InitTestConfig()
 | |
| 	testrig.InitTestLog()
 | |
| 
 | |
| 	suite.db = testrig.NewTestDB(&suite.state)
 | |
| 	suite.state.DB = suite.db
 | |
| 	suite.state.AdminActions = admin.New(suite.state.DB, &suite.state.Workers)
 | |
| 	suite.storage = testrig.NewInMemoryStorage()
 | |
| 	suite.state.Storage = suite.storage
 | |
| 	suite.mediaManager = testrig.NewTestMediaManager(&suite.state)
 | |
| 	suite.federator = testrig.NewTestFederator(&suite.state, testrig.NewTestTransportController(&suite.state, testrig.NewMockHTTPClient(nil, "../../../testrig/media")), suite.mediaManager)
 | |
| 	suite.emailSender = testrig.NewEmailSender("../../../web/template/", nil)
 | |
| 	suite.processor = testrig.NewTestProcessor(
 | |
| 		&suite.state,
 | |
| 		suite.federator,
 | |
| 		suite.emailSender,
 | |
| 		testrig.NewNoopWebPushSender(),
 | |
| 		suite.mediaManager,
 | |
| 	)
 | |
| 	suite.authModule = auth.New(suite.db, suite.processor, suite.idp)
 | |
| 
 | |
| 	testrig.StandardDBSetup(suite.db, suite.testAccounts)
 | |
| 	testrig.StartNoopWorkers(&suite.state)
 | |
| }
 | |
| 
 | |
| func (suite *AuthStandardTestSuite) TearDownTest() {
 | |
| 	testrig.StandardDBTeardown(suite.db)
 | |
| 	testrig.StopWorkers(&suite.state)
 | |
| }
 | |
| 
 | |
| func (suite *AuthStandardTestSuite) newContext(requestMethod string, requestPath string, requestBody []byte, bodyContentType string) (*gin.Context, *httptest.ResponseRecorder) {
 | |
| 	// create the recorder and gin test context
 | |
| 	recorder := httptest.NewRecorder()
 | |
| 	ctx, engine := testrig.CreateGinTestContext(recorder, nil)
 | |
| 
 | |
| 	// load templates into the engine
 | |
| 	testrig.ConfigureTemplatesWithGin(engine, "../../../web/template")
 | |
| 
 | |
| 	// create the request
 | |
| 	protocol := config.GetProtocol()
 | |
| 	host := config.GetHost()
 | |
| 	baseURI := fmt.Sprintf("%s://%s", protocol, host)
 | |
| 	requestURI := fmt.Sprintf("%s/%s", baseURI, requestPath)
 | |
| 
 | |
| 	ctx.Request = httptest.NewRequest(requestMethod, requestURI, bytes.NewReader(requestBody)) // the endpoint we're hitting
 | |
| 	ctx.Request.Header.Set("accept", "text/html")
 | |
| 
 | |
| 	if bodyContentType != "" {
 | |
| 		ctx.Request.Header.Set("Content-Type", bodyContentType)
 | |
| 	}
 | |
| 
 | |
| 	// trigger the session middleware on the context
 | |
| 	store := memstore.NewStore(make([]byte, 32), make([]byte, 32))
 | |
| 	store.Options(middleware.SessionOptions())
 | |
| 	sessionMiddleware := sessions.Sessions("gotosocial-localhost", store)
 | |
| 	sessionMiddleware(ctx)
 | |
| 
 | |
| 	return ctx, recorder
 | |
| }
 |