2014-12-28 23:24:41 +03:00
|
|
|
package jwt_test
|
2012-04-18 03:49:21 +04:00
|
|
|
|
|
|
|
import (
|
2015-07-20 20:23:11 +03:00
|
|
|
"crypto/rsa"
|
2015-11-03 02:22:08 +03:00
|
|
|
"encoding/json"
|
2012-04-18 23:35:16 +04:00
|
|
|
"fmt"
|
2012-04-18 23:59:37 +04:00
|
|
|
"reflect"
|
|
|
|
"testing"
|
2014-03-08 02:43:11 +04:00
|
|
|
"time"
|
2015-07-17 20:28:08 +03:00
|
|
|
|
|
|
|
"github.com/dgrijalva/jwt-go"
|
2016-04-08 23:01:55 +03:00
|
|
|
"github.com/dgrijalva/jwt-go/test"
|
2012-04-18 03:49:21 +04:00
|
|
|
)
|
|
|
|
|
2014-10-12 00:54:16 +04:00
|
|
|
var (
|
2015-07-20 20:23:11 +03:00
|
|
|
jwtTestDefaultKey *rsa.PublicKey
|
2014-12-28 23:24:41 +03:00
|
|
|
defaultKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { return jwtTestDefaultKey, nil }
|
|
|
|
emptyKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { return nil, nil }
|
|
|
|
errorKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { return nil, fmt.Errorf("error loading key") }
|
|
|
|
nilKeyFunc jwt.Keyfunc = nil
|
2014-10-12 00:54:16 +04:00
|
|
|
)
|
|
|
|
|
2016-04-08 23:01:55 +03:00
|
|
|
func init() {
|
|
|
|
jwtTestDefaultKey = test.LoadRSAPublicKeyFromDisk("test/sample_key.pub")
|
|
|
|
}
|
|
|
|
|
2012-04-18 23:59:37 +04:00
|
|
|
var jwtTestData = []struct {
|
2014-12-28 23:24:41 +03:00
|
|
|
name string
|
|
|
|
tokenString string
|
|
|
|
keyfunc jwt.Keyfunc
|
2016-04-13 00:32:24 +03:00
|
|
|
claims jwt.Claims
|
2014-12-28 23:24:41 +03:00
|
|
|
valid bool
|
|
|
|
errors uint32
|
2015-11-03 02:22:08 +03:00
|
|
|
parser *jwt.Parser
|
2012-04-18 23:18:31 +04:00
|
|
|
}{
|
|
|
|
{
|
2012-04-18 23:35:16 +04:00
|
|
|
"basic",
|
2012-04-18 23:18:31 +04:00
|
|
|
"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg",
|
2014-10-12 00:54:16 +04:00
|
|
|
defaultKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar"},
|
2012-04-18 23:18:31 +04:00
|
|
|
true,
|
2014-12-28 23:24:41 +03:00
|
|
|
0,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
2014-03-08 02:43:11 +04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"basic expired",
|
|
|
|
"", // autogen
|
2014-10-12 00:54:16 +04:00
|
|
|
defaultKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar", "exp": float64(time.Now().Unix() - 100)},
|
2014-03-08 02:43:11 +04:00
|
|
|
false,
|
2014-12-28 23:24:41 +03:00
|
|
|
jwt.ValidationErrorExpired,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
2014-03-08 02:43:11 +04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"basic nbf",
|
|
|
|
"", // autogen
|
2014-10-12 00:54:16 +04:00
|
|
|
defaultKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar", "nbf": float64(time.Now().Unix() + 100)},
|
2014-03-08 02:43:11 +04:00
|
|
|
false,
|
2014-12-28 23:24:41 +03:00
|
|
|
jwt.ValidationErrorNotValidYet,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
2014-03-09 23:24:51 +04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"expired and nbf",
|
|
|
|
"", // autogen
|
2014-10-12 00:54:16 +04:00
|
|
|
defaultKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar", "nbf": float64(time.Now().Unix() + 100), "exp": float64(time.Now().Unix() - 100)},
|
2014-03-09 23:24:51 +04:00
|
|
|
false,
|
2014-12-28 23:24:41 +03:00
|
|
|
jwt.ValidationErrorNotValidYet | jwt.ValidationErrorExpired,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
2012-04-18 23:18:31 +04:00
|
|
|
},
|
|
|
|
{
|
2012-04-18 23:35:16 +04:00
|
|
|
"basic invalid",
|
2012-04-18 23:18:31 +04:00
|
|
|
"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.EhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg",
|
2014-10-12 00:54:16 +04:00
|
|
|
defaultKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar"},
|
2014-10-12 00:54:16 +04:00
|
|
|
false,
|
2014-12-28 23:24:41 +03:00
|
|
|
jwt.ValidationErrorSignatureInvalid,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
2014-10-12 00:54:16 +04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"basic nokeyfunc",
|
|
|
|
"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg",
|
|
|
|
nilKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar"},
|
2014-10-12 00:54:16 +04:00
|
|
|
false,
|
2014-12-28 23:24:41 +03:00
|
|
|
jwt.ValidationErrorUnverifiable,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
2014-10-12 00:54:16 +04:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"basic nokey",
|
|
|
|
"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg",
|
|
|
|
emptyKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar"},
|
2012-04-18 23:18:31 +04:00
|
|
|
false,
|
2014-12-28 23:24:41 +03:00
|
|
|
jwt.ValidationErrorSignatureInvalid,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
2012-04-18 23:18:31 +04:00
|
|
|
},
|
2014-10-12 00:54:16 +04:00
|
|
|
{
|
|
|
|
"basic errorkey",
|
|
|
|
"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg",
|
|
|
|
errorKeyFunc,
|
2015-08-18 20:18:57 +03:00
|
|
|
jwt.MapClaims{"foo": "bar"},
|
2014-10-12 00:54:16 +04:00
|
|
|
false,
|
2014-12-28 23:24:41 +03:00
|
|
|
jwt.ValidationErrorUnverifiable,
|
2015-11-03 02:22:08 +03:00
|
|
|
nil,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"invalid signing method",
|
|
|
|
"",
|
|
|
|
defaultKeyFunc,
|
2016-04-13 00:32:24 +03:00
|
|
|
jwt.MapClaims{"foo": "bar"},
|
2015-11-03 02:22:08 +03:00
|
|
|
false,
|
|
|
|
jwt.ValidationErrorSignatureInvalid,
|
|
|
|
&jwt.Parser{ValidMethods: []string{"HS256"}},
|
|
|
|
},
|
2015-11-03 02:24:32 +03:00
|
|
|
{
|
|
|
|
"valid signing method",
|
|
|
|
"",
|
|
|
|
defaultKeyFunc,
|
2016-04-13 00:32:24 +03:00
|
|
|
jwt.MapClaims{"foo": "bar"},
|
2015-11-03 02:24:32 +03:00
|
|
|
true,
|
|
|
|
0,
|
|
|
|
&jwt.Parser{ValidMethods: []string{"RS256", "HS256"}},
|
|
|
|
},
|
2015-11-03 02:22:08 +03:00
|
|
|
{
|
|
|
|
"JSON Number",
|
|
|
|
"",
|
|
|
|
defaultKeyFunc,
|
2016-04-13 00:32:24 +03:00
|
|
|
jwt.MapClaims{"foo": json.Number("123.4")},
|
|
|
|
true,
|
|
|
|
0,
|
|
|
|
&jwt.Parser{UseJSONNumber: true},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"Standard Claims",
|
|
|
|
"",
|
|
|
|
defaultKeyFunc,
|
|
|
|
&jwt.StandardClaims{
|
|
|
|
ExpiresAt: time.Now().Add(time.Second * 10).Unix(),
|
|
|
|
},
|
2015-11-03 02:22:08 +03:00
|
|
|
true,
|
|
|
|
0,
|
|
|
|
&jwt.Parser{UseJSONNumber: true},
|
2014-10-12 00:54:16 +04:00
|
|
|
},
|
2016-04-05 00:42:10 +03:00
|
|
|
{
|
|
|
|
"JSON Number - basic expired",
|
|
|
|
"", // autogen
|
|
|
|
defaultKeyFunc,
|
2016-04-13 02:19:20 +03:00
|
|
|
jwt.MapClaims{"foo": "bar", "exp": json.Number(fmt.Sprintf("%v", time.Now().Unix()-100))},
|
2016-04-05 00:42:10 +03:00
|
|
|
false,
|
|
|
|
jwt.ValidationErrorExpired,
|
|
|
|
&jwt.Parser{UseJSONNumber: true},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"JSON Number - basic nbf",
|
|
|
|
"", // autogen
|
|
|
|
defaultKeyFunc,
|
2016-04-13 02:19:20 +03:00
|
|
|
jwt.MapClaims{"foo": "bar", "nbf": json.Number(fmt.Sprintf("%v", time.Now().Unix()+100))},
|
2016-04-05 00:42:10 +03:00
|
|
|
false,
|
|
|
|
jwt.ValidationErrorNotValidYet,
|
|
|
|
&jwt.Parser{UseJSONNumber: true},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"JSON Number - expired and nbf",
|
|
|
|
"", // autogen
|
|
|
|
defaultKeyFunc,
|
2016-04-13 02:19:20 +03:00
|
|
|
jwt.MapClaims{"foo": "bar", "nbf": json.Number(fmt.Sprintf("%v", time.Now().Unix()+100)), "exp": json.Number(fmt.Sprintf("%v", time.Now().Unix()-100))},
|
2016-04-05 00:42:10 +03:00
|
|
|
false,
|
|
|
|
jwt.ValidationErrorNotValidYet | jwt.ValidationErrorExpired,
|
|
|
|
&jwt.Parser{UseJSONNumber: true},
|
|
|
|
},
|
2014-10-12 00:54:16 +04:00
|
|
|
}
|
|
|
|
|
2015-11-03 02:22:08 +03:00
|
|
|
func TestParser_Parse(t *testing.T) {
|
2016-04-08 23:01:55 +03:00
|
|
|
privateKey := test.LoadRSAPrivateKeyFromDisk("test/sample_key")
|
|
|
|
|
2016-04-13 00:32:24 +03:00
|
|
|
// Iterate over test data set and run tests
|
2012-04-18 23:18:31 +04:00
|
|
|
for _, data := range jwtTestData {
|
2016-04-13 00:32:24 +03:00
|
|
|
// If the token string is blank, use helper function to generate string
|
2014-03-08 02:43:11 +04:00
|
|
|
if data.tokenString == "" {
|
2016-04-08 23:01:55 +03:00
|
|
|
data.tokenString = test.MakeSampleToken(data.claims, privateKey)
|
2014-03-08 02:43:11 +04:00
|
|
|
}
|
2015-11-03 02:22:08 +03:00
|
|
|
|
2016-04-13 00:32:24 +03:00
|
|
|
// Parse the token
|
2015-11-03 02:22:08 +03:00
|
|
|
var token *jwt.Token
|
|
|
|
var err error
|
2016-04-13 00:32:24 +03:00
|
|
|
var parser = data.parser
|
|
|
|
if parser == nil {
|
|
|
|
parser = new(jwt.Parser)
|
|
|
|
}
|
|
|
|
// Figure out correct claims type
|
|
|
|
switch data.claims.(type) {
|
|
|
|
case jwt.MapClaims:
|
2016-04-13 02:25:25 +03:00
|
|
|
token, err = parser.ParseWithClaims(data.tokenString, jwt.MapClaims{}, data.keyfunc)
|
2016-04-13 00:32:24 +03:00
|
|
|
case *jwt.StandardClaims:
|
2016-04-13 02:25:25 +03:00
|
|
|
token, err = parser.ParseWithClaims(data.tokenString, &jwt.StandardClaims{}, data.keyfunc)
|
2015-11-03 02:22:08 +03:00
|
|
|
}
|
2012-04-18 23:59:37 +04:00
|
|
|
|
2016-04-13 00:32:24 +03:00
|
|
|
// Verify result matches expectation
|
|
|
|
if !reflect.DeepEqual(data.claims, token.Claims) {
|
2012-04-18 23:18:31 +04:00
|
|
|
t.Errorf("[%v] Claims mismatch. Expecting: %v Got: %v", data.name, data.claims, token.Claims)
|
|
|
|
}
|
2015-07-17 20:28:08 +03:00
|
|
|
|
2012-04-18 23:18:31 +04:00
|
|
|
if data.valid && err != nil {
|
2014-03-08 02:43:11 +04:00
|
|
|
t.Errorf("[%v] Error while verifying token: %T:%v", data.name, err, err)
|
2012-04-18 23:18:31 +04:00
|
|
|
}
|
2015-07-17 20:28:08 +03:00
|
|
|
|
2012-04-18 23:18:31 +04:00
|
|
|
if !data.valid && err == nil {
|
|
|
|
t.Errorf("[%v] Invalid token passed validation", data.name)
|
|
|
|
}
|
2015-07-17 20:28:08 +03:00
|
|
|
|
2016-04-13 00:52:39 +03:00
|
|
|
if (err == nil && !token.Valid) || (err != nil && token.Valid) {
|
|
|
|
t.Errorf("[%v] Inconsistent behavior between returned error and token.Valid")
|
|
|
|
}
|
|
|
|
|
2014-12-28 23:24:41 +03:00
|
|
|
if data.errors != 0 {
|
2014-03-08 02:43:11 +04:00
|
|
|
if err == nil {
|
|
|
|
t.Errorf("[%v] Expecting error. Didn't get one.", data.name)
|
|
|
|
} else {
|
2014-12-28 23:24:41 +03:00
|
|
|
// compare the bitfield part of the error
|
2015-11-03 02:22:08 +03:00
|
|
|
if e := err.(*jwt.ValidationError).Errors; e != data.errors {
|
|
|
|
t.Errorf("[%v] Errors don't match expectation. %v != %v", data.name, e, data.errors)
|
2014-03-08 02:43:11 +04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2015-11-16 23:42:37 +03:00
|
|
|
if data.valid && token.Signature == "" {
|
|
|
|
t.Errorf("[%v] Signature is left unpopulated after parsing", data.name)
|
|
|
|
}
|
2012-04-18 23:18:31 +04:00
|
|
|
}
|
2012-04-18 03:49:21 +04:00
|
|
|
}
|
2012-04-18 23:35:16 +04:00
|
|
|
|
2015-04-11 23:53:09 +03:00
|
|
|
// Helper method for benchmarking various methods
|
|
|
|
func benchmarkSigning(b *testing.B, method jwt.SigningMethod, key interface{}) {
|
|
|
|
t := jwt.New(method)
|
|
|
|
b.RunParallel(func(pb *testing.PB) {
|
|
|
|
for pb.Next() {
|
2015-04-12 00:04:22 +03:00
|
|
|
if _, err := t.SignedString(key); err != nil {
|
|
|
|
b.Fatal(err)
|
|
|
|
}
|
2015-04-11 23:53:09 +03:00
|
|
|
}
|
|
|
|
})
|
|
|
|
|
|
|
|
}
|