visionA/visionA-backend/internal/auth/session_token_test.go
jim800121chen 22f0837ba8 feat(visionA-backend): Phase 0 → 0.7 雲端後端(雙 binary + OIDC BFF + stage 部署)
從 edge-ai-platform POC 轉為正式產品的雲端後端,含以下整合階段:

- Phase 0:雛形骨架 — `cmd/api-server` (REST :3721) + `cmd/remote-proxy`
  (tunnel :3800 / internal :3801) 雙 binary 共用 internal/,沿用 POC 的
  WebSocket+yamux tunnel 協定但解耦 relay 與 API
- Phase 0.6:OIDC BFF 接 Innovedus Member Center
  - internal/oidc package(coreos/go-oidc + PKCE S256 + state + nonce)
  - internal/usersession package(HMAC-SHA256 cookie + RotateSessionID
    防 session fixation, OWASP ASVS V3.2.1)
  - 4 個 OIDC handler(/api/auth/login|callback|me|logout)+ AuthMiddleware
  - 完全拔除 StaticAuthProvider,OIDC 是唯一認證路徑
  - 9 個 ADR(含 ADR-010 BFF / ADR-011 取代 static auth /
    ADR-012 pending session shared cookie / ADR-013 PKCE-only public client)
- Phase 0.7:A1 改造 + security audit 修復
  - OIDC ClientSecret 變選填,支援 stage MC 的 public PKCE-only client
    (AuthStyleInParams 強制 token endpoint 不送 client_secret)
  - 預留 ServiceClient* 欄位給未來 client_credentials grant
  - 移除 13+ 處 resolveUserID(uc, StaticUserID) fallback 改 strict mode
    (Audit C1:multi-tenant 隔離破口)
  - Pairing exchange MarkUsed 失敗 abort + revoke session token(Audit M3)
  - 新增 all_endpoints_require_auth_test 整合測試(51 endpoint × 401)

驗證:go test -race -count=3 ./... 17 packages 全綠 / go vet 0 warning

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-01 11:21:20 +08:00

110 lines
3.6 KiB
Go
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

package auth
import (
"context"
"errors"
"testing"
"time"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
)
// TestInMemorySessionTokenStore_CreateAndGet 驗證一次完整的建立 → 查詢循環。
func TestInMemorySessionTokenStore_CreateAndGet(t *testing.T) {
s := NewInMemorySessionTokenStore()
ctx := context.Background()
plain, info, err := s.Create(ctx, "user-1", "dev-1", "parent-hash", SessionTokenTTL)
require.NoError(t, err)
assert.True(t, IsValidSessionToken(plain), "產出 token 應通過格式驗證:%s", plain)
require.NotNil(t, info)
assert.Equal(t, "user-1", info.UserID)
assert.Equal(t, "dev-1", info.DeviceID)
assert.Equal(t, "parent-hash", info.ParentTokenHash)
require.NotNil(t, info.ExpiresAt)
assert.WithinDuration(t, time.Now().UTC().Add(SessionTokenTTL), *info.ExpiresAt, 2*time.Second)
got, err := s.Get(ctx, plain)
require.NoError(t, err)
assert.Equal(t, "user-1", got.UserID)
assert.Equal(t, info.TokenHash, got.TokenHash)
}
// TestInMemorySessionTokenStore_Get_NotFound 驗證查詢不存在 token 回 ErrInvalidToken。
func TestInMemorySessionTokenStore_Get_NotFound(t *testing.T) {
s := NewInMemorySessionTokenStore()
_, err := s.Get(context.Background(), "vAs_deadbeef")
assert.ErrorIs(t, err, ErrInvalidToken)
}
// TestInMemorySessionTokenStore_Get_Expired 驗證過期 token 回 ErrTokenExpired。
func TestInMemorySessionTokenStore_Get_Expired(t *testing.T) {
s := NewInMemorySessionTokenStore()
ctx := context.Background()
// TTL 設 1ns 確保立即過期
plain, _, err := s.Create(ctx, "u", "d", "", 1*time.Nanosecond)
require.NoError(t, err)
time.Sleep(5 * time.Millisecond)
_, err = s.Get(ctx, plain)
assert.True(t, errors.Is(err, ErrTokenExpired), "應回 ErrTokenExpired實際%v", err)
}
// TestInMemorySessionTokenStore_Revoke 驗證撤銷後 Get 回 ErrTokenRevoked。
func TestInMemorySessionTokenStore_Revoke(t *testing.T) {
s := NewInMemorySessionTokenStore()
ctx := context.Background()
plain, _, err := s.Create(ctx, "u", "d", "", SessionTokenTTL)
require.NoError(t, err)
require.NoError(t, s.Revoke(ctx, plain))
_, err = s.Get(ctx, plain)
assert.ErrorIs(t, err, ErrTokenRevoked)
// 冪等:再撤一次不該報錯
assert.NoError(t, s.Revoke(ctx, plain))
}
// TestInMemorySessionTokenStore_Revoke_NotFound 驗證撤銷不存在 token 回 ErrInvalidToken。
func TestInMemorySessionTokenStore_Revoke_NotFound(t *testing.T) {
s := NewInMemorySessionTokenStore()
err := s.Revoke(context.Background(), "vAs_nope")
assert.ErrorIs(t, err, ErrInvalidToken)
}
// TestInMemorySessionTokenStore_CleanupExpired 驗證過期 token 會被清掉。
func TestInMemorySessionTokenStore_CleanupExpired(t *testing.T) {
s := NewInMemorySessionTokenStore()
ctx := context.Background()
// 一個會過期、一個長效
expiredTok, _, err := s.Create(ctx, "u1", "d1", "", 1*time.Nanosecond)
require.NoError(t, err)
freshTok, _, err := s.Create(ctx, "u2", "d2", "", SessionTokenTTL)
require.NoError(t, err)
time.Sleep(5 * time.Millisecond)
removed, err := s.CleanupExpired(ctx, time.Now().UTC())
require.NoError(t, err)
assert.Equal(t, 1, removed)
// 過期的應查不到
_, err = s.Get(ctx, expiredTok)
assert.ErrorIs(t, err, ErrInvalidToken)
// 新鮮的仍在
_, err = s.Get(ctx, freshTok)
assert.NoError(t, err)
}
// TestInMemorySessionTokenStore_NeverExpires 驗證 ttl <= 0 時 ExpiresAt 為 nil。
func TestInMemorySessionTokenStore_NeverExpires(t *testing.T) {
s := NewInMemorySessionTokenStore()
_, info, err := s.Create(context.Background(), "u", "d", "", 0)
require.NoError(t, err)
assert.Nil(t, info.ExpiresAt, "ttl=0 時 ExpiresAt 應為 nil")
}