Repository navigation
Expand file tree
/
Copy pathQuick.Core.Security.Tests.pas
More file actions
256 lines (227 loc) · 6.79 KB
/
Copy pathQuick.Core.Security.Tests.pas
File metadata and controls
256 lines (227 loc) · 6.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
unit Quick.Core.Security.Tests;
{ Tests: T-SEC-01..08
T-SEC-01 TClaimsPrincipal can be created with an identity and Name is accessible
T-SEC-02 TClaimsIdentity.AddClaim / HasClaim round-trip
T-SEC-03 TClaimsPrincipal.IsInRole returns True for a role claim
T-SEC-04 TClaimsPrincipal.FindFirst predicate finds the expected claim
T-SEC-05 TJwtTokenService.GenerateToken produces a three-part dot-separated token
T-SEC-06 ValidateToken returns True and a valid principal for a freshly generated token
T-SEC-07 ValidateToken returns False for a token signed with a different secret
T-SEC-08 GetUserFromToken decodes the subject (name) without signature check
}
interface
uses
DUnitX.TestFramework,
Quick.Options,
Quick.Core.Security.Claims,
Quick.Core.Security.Jwt;
type
[TestFixture]
TSecurityTests = class
private
function MakeOptions(const ASecret, AIssuer, AAudience: string;
AExpiry: Integer = 60; AValidateLifetime: Boolean = True): IOptions<TJwtOptions>;
function MakePrincipal(const AName, ARole: string): TClaimsPrincipal;
public
{ Claims Tests }
[Test]
procedure T_SEC_01_Principal_Name;
[Test]
procedure T_SEC_02_ClaimsIdentity_HasClaim;
[Test]
procedure T_SEC_03_IsInRole;
[Test]
procedure T_SEC_04_FindFirst;
{ JWT Tests }
[Test]
procedure T_SEC_05_GenerateToken_ThreeParts;
[Test]
procedure T_SEC_06_ValidateToken_ValidToken;
[Test]
procedure T_SEC_07_ValidateToken_WrongSecret;
[Test]
procedure T_SEC_08_GetUserFromToken_DecodesSubject;
end;
implementation
uses
System.SysUtils;
{ TSecurityTests – helpers }
function TSecurityTests.MakeOptions(const ASecret, AIssuer, AAudience: string;
AExpiry: Integer; AValidateLifetime: Boolean): IOptions<TJwtOptions>;
var
opts: TJwtOptions;
begin
opts := TJwtOptions.Create;
opts.Secret := ASecret;
opts.Issuer := AIssuer;
opts.Audience := AAudience;
opts.ExpiryMinutes := AExpiry;
opts.ValidateLifetime := AValidateLifetime;
opts.ValidateIssuer := AIssuer <> '';
opts.ValidateAudience := AAudience <> '';
Result := TOptionValue<TJwtOptions>.Create(opts);
end;
function TSecurityTests.MakePrincipal(const AName, ARole: string): TClaimsPrincipal;
var
identity: TClaimsIdentity;
begin
identity := TClaimsIdentity.Create;
identity.AuthenticationType := TAuthenticationTypes.Password;
identity.Name := AName;
if ARole <> '' then
identity.AddClaim(TClaim.Create(TClaimTypes.Role, ARole));
Result := TClaimsPrincipal.Create(identity as IIdentity);
end;
{ T-SEC-01 }
procedure TSecurityTests.T_SEC_01_Principal_Name;
var
principal: TClaimsPrincipal;
begin
principal := MakePrincipal('alice', '');
try
Assert.AreEqual('alice', (principal.Identity as TClaimsIdentity).Name);
finally
principal.Free;
end;
end;
{ T-SEC-02 }
procedure TSecurityTests.T_SEC_02_ClaimsIdentity_HasClaim;
var
identity: TClaimsIdentity;
begin
identity := TClaimsIdentity.Create;
try
identity.AddClaim(TClaim.Create(TClaimTypes.Email, 'alice@example.com'));
Assert.IsTrue(identity.HasClaim(TClaimTypes.Email, 'alice@example.com'));
Assert.IsFalse(identity.HasClaim(TClaimTypes.Email, 'other@example.com'));
finally
identity.Free;
end;
end;
{ T-SEC-03 }
procedure TSecurityTests.T_SEC_03_IsInRole;
var
principal: TClaimsPrincipal;
begin
principal := MakePrincipal('bob', 'admin');
try
Assert.IsTrue(principal.IsInRole('admin'));
Assert.IsFalse(principal.IsInRole('user'));
finally
principal.Free;
end;
end;
{ T-SEC-04 }
procedure TSecurityTests.T_SEC_04_FindFirst;
var
principal: TClaimsPrincipal;
claim: TClaim;
begin
principal := MakePrincipal('carol', 'editor');
try
principal.Identities[0].AddClaim(TClaim.Create(TClaimTypes.Email, 'carol@example.com'));
claim := principal.FindFirst(
function(c: TClaim): Boolean
begin
Result := c.&Type = TClaimTypes.Email;
end);
Assert.IsNotNull(claim);
Assert.AreEqual('carol@example.com', claim.Value);
finally
principal.Free;
end;
end;
{ T-SEC-05 }
procedure TSecurityTests.T_SEC_05_GenerateToken_ThreeParts;
var
svc: TJwtTokenService;
principal: TClaimsPrincipal;
token: string;
parts: TArray<string>;
begin
svc := TJwtTokenService.Create(MakeOptions('supersecret', '', ''));
principal := MakePrincipal('dave', '');
try
token := svc.GenerateToken(principal);
parts := token.Split(['.']);
Assert.AreEqual(NativeInt(3), NativeInt(Length(parts)), 'JWT must have 3 dot-separated parts');
Assert.IsTrue(parts[0] <> '', 'Header must not be empty');
Assert.IsTrue(parts[1] <> '', 'Payload must not be empty');
Assert.IsTrue(parts[2] <> '', 'Signature must not be empty');
finally
principal.Free;
svc.Free;
end;
end;
{ T-SEC-06 }
procedure TSecurityTests.T_SEC_06_ValidateToken_ValidToken;
var
svc: TJwtTokenService;
principal, outPrincipal: TClaimsPrincipal;
token: string;
ok: Boolean;
begin
svc := TJwtTokenService.Create(MakeOptions('mysecret42', 'myapp', ''));
principal := MakePrincipal('eve', 'user');
try
token := svc.GenerateToken(principal);
ok := svc.ValidateToken(token, outPrincipal);
try
Assert.IsTrue(ok, 'ValidateToken must return True for a freshly-issued token');
Assert.IsNotNull(outPrincipal);
Assert.AreEqual('eve', (outPrincipal.Identity as TClaimsIdentity).Name);
finally
if ok then outPrincipal.Free;
end;
finally
principal.Free;
svc.Free;
end;
end;
{ T-SEC-07 }
procedure TSecurityTests.T_SEC_07_ValidateToken_WrongSecret;
var
svcIssuer, svcValidator: TJwtTokenService;
principal, outPrincipal: TClaimsPrincipal;
token: string;
begin
svcIssuer := TJwtTokenService.Create(MakeOptions('correctsecret', '', ''));
svcValidator := TJwtTokenService.Create(MakeOptions('wrongsecret', '', ''));
principal := MakePrincipal('frank', '');
try
token := svcIssuer.GenerateToken(principal);
Assert.IsFalse(svcValidator.ValidateToken(token, outPrincipal),
'ValidateToken must return False when secret does not match');
Assert.IsNull(outPrincipal);
finally
principal.Free;
svcIssuer.Free;
svcValidator.Free;
end;
end;
{ T-SEC-08 }
procedure TSecurityTests.T_SEC_08_GetUserFromToken_DecodesSubject;
var
svc: TJwtTokenService;
principal, decoded: TClaimsPrincipal;
token: string;
begin
svc := TJwtTokenService.Create(MakeOptions('anysecret', '', ''));
principal := MakePrincipal('grace', '');
try
token := svc.GenerateToken(principal);
decoded := svc.GetUserFromToken(token);
try
Assert.IsNotNull(decoded);
Assert.AreEqual('grace', (decoded.Identity as TClaimsIdentity).Name);
finally
decoded.Free;
end;
finally
principal.Free;
svc.Free;
end;
end;
initialization
TDUnitX.RegisterTestFixture(TSecurityTests);
end.