Mercurial
diff auth/test/auth_http_test.c @ 279:b3b547563ec7
Add Google connector service and agent wiki
Implement the C/Seobeo Google Drive and Gmail connector with encrypted OAuth storage, Zenbu authentication, browser testing, AI tool discovery, chunked HTTP decoding, and Bazel coverage. Consolidate repository guidance into progressive wiki documentation and enforce arena-first allocation for new first-party C code.
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 84c338fd-0939-4bb3-b7f3-1062eb213e5d
| author | MrJuneJune <me@mrjunejune.com> |
|---|---|
| date | Mon, 17 Aug 2026 22:22:36 -0700 |
| parents | |
| children |
line wrap: on
line diff
--- /dev/null Thu Jan 01 00:00:00 1970 +0000 +++ b/auth/test/auth_http_test.c Mon Aug 17 22:22:36 2026 -0700 @@ -0,0 +1,123 @@ +#include "auth/auth_http.h" + +#include <assert.h> +#include <stdio.h> +#include <string.h> +#include <time.h> +#include <unistd.h> + +static const uint8 k_secret[] = + "0123456789abcdef0123456789abcdef"; + +static Seobeo_Request_Entry *make_request( + Dowa_Arena *p_arena, + const char *host, + const char *origin, + const char *cookie, + const char *csrf) +{ + Seobeo_Request_Entry *request = NULL; + if (host) + Dowa_HashMap_Push_Arena(request, "Host", (char *)host, p_arena); + if (origin) + Dowa_HashMap_Push_Arena(request, "Origin", (char *)origin, p_arena); + if (cookie) + Dowa_HashMap_Push_Arena(request, "Cookie", (char *)cookie, p_arena); + if (csrf) + Dowa_HashMap_Push_Arena( + request, "X-CSRF-Token", (char *)csrf, p_arena); + return request; +} + +int main(void) +{ + Dowa_Arena *p_arena = Dowa_Arena_Create(16 * 1024); + assert(p_arena); + + char cookie_value[16]; + assert(Auth_HTTP_Parse_Cookie( + "other=x; mjj_session=token; final=y", + AUTH_HTTP_SESSION_COOKIE_NAME, cookie_value, sizeof(cookie_value))); + assert(strcmp(cookie_value, "token") == 0); + assert(!Auth_HTTP_Parse_Cookie( + "not_mjj_session=token", AUTH_HTTP_SESSION_COOKIE_NAME, + cookie_value, sizeof(cookie_value))); + + Seobeo_Request_Entry *same_origin = make_request( + p_arena, "localhost:6969", "http://localhost:6969", NULL, NULL); + Seobeo_Request_Entry *wrong_origin = make_request( + p_arena, "localhost:6969", "https://example.com", NULL, NULL); + assert(Auth_HTTP_Same_Origin(same_origin)); + assert(!Auth_HTTP_Same_Origin(wrong_origin)); + + char csrf[AUTH_CRYPTO_TOKEN_SIZE] = {0}; + assert(Auth_HTTP_Derive_CSRF( + k_secret, sizeof(k_secret) - 1, "binding", csrf, sizeof(csrf))); + Seobeo_Request_Entry *csrf_request = make_request( + p_arena, "localhost", "https://localhost", NULL, csrf); + assert(Auth_HTTP_Verify_CSRF( + csrf_request, k_secret, sizeof(k_secret) - 1, "binding")); + assert(!Auth_HTTP_Verify_CSRF_Token( + k_secret, sizeof(k_secret) - 1, "binding", "wrong-token")); + assert(!Auth_HTTP_Verify_CSRF( + wrong_origin, k_secret, sizeof(k_secret) - 1, "binding")); + + char database_path[256]; + snprintf(database_path, sizeof(database_path), + "auth_http_test_%ld_%ld.db", (long)getpid(), (long)time(NULL)); + unlink(database_path); + Auth_Store *p_store = Auth_Store_Create(database_path); + assert(p_store); + + char password_hash[AUTH_CRYPTO_PASSWORD_HASH_ENCODED_SIZE]; + assert(Auth_Crypto_Password_Hash( + "test-password", password_hash, sizeof(password_hash)) == + AUTH_CRYPTO_OK); + char user_id[37]; + assert(Auth_Store_Create_User( + p_store, "httpuser", password_hash, "member", FALSE, user_id) == + AUTH_STORE_OK); + + char token[AUTH_CRYPTO_TOKEN_SIZE]; + char token_digest[AUTH_CRYPTO_TOKEN_DIGEST_SIZE]; + char stored_csrf_digest[AUTH_CRYPTO_TOKEN_DIGEST_SIZE]; + assert(Auth_Crypto_Token_Generate(token, sizeof(token)) == AUTH_CRYPTO_OK); + assert(Auth_Crypto_Token_Digest( + token, token_digest, sizeof(token_digest)) == AUTH_CRYPTO_OK); + assert(Auth_Crypto_Token_Digest( + csrf, stored_csrf_digest, sizeof(stored_csrf_digest)) == AUTH_CRYPTO_OK); + int64 now = (int64)time(NULL); + Auth_Session_Record session; + assert(Auth_Store_Create_Session( + p_store, user_id, token_digest, stored_csrf_digest, + 3600, 86400, now, &session) == AUTH_STORE_OK); + + char cookie_header[AUTH_CRYPTO_TOKEN_SIZE + 32]; + snprintf(cookie_header, sizeof(cookie_header), "%s=%s", + AUTH_HTTP_SESSION_COOKIE_NAME, token); + Seobeo_Request_Entry *user_request = make_request( + p_arena, "localhost", NULL, cookie_header, NULL); + Auth_HTTP_Authenticated_User user; + assert(Auth_HTTP_Resolve_Authenticated_User( + user_request, p_store, k_secret, sizeof(k_secret) - 1, + now + 1, 3600, &user) == AUTH_HTTP_RESOLVE_OK); + assert(strcmp(user.user.id, user_id) == 0); + assert(strcmp(user.token_digest, token_digest) == 0); + assert(user.csrf_token[0] != '\0'); + assert(Auth_Store_Revoke_Session(p_store, token_digest) == AUTH_STORE_OK); + assert(Auth_HTTP_Resolve_Authenticated_User( + user_request, p_store, k_secret, sizeof(k_secret) - 1, + now + 2, 3600, &user) == AUTH_HTTP_RESOLVE_NOT_FOUND); + + Seobeo_Request_Entry *anonymous_request = make_request( + p_arena, "localhost", NULL, NULL, NULL); + assert(Auth_HTTP_Resolve_Authenticated_User( + anonymous_request, p_store, k_secret, sizeof(k_secret) - 1, + now + 1, 3600, &user) == AUTH_HTTP_RESOLVE_NOT_FOUND); + + Auth_Store_Destroy(p_store); + unlink(database_path); + Dowa_Arena_Free(p_arena); + puts("auth_http_test: PASS"); + return 0; +}