|
@@ -3,6 +3,7 @@ package webdavd_test
|
|
|
import (
|
|
|
"bytes"
|
|
|
"crypto/rand"
|
|
|
+ "crypto/tls"
|
|
|
"encoding/json"
|
|
|
"fmt"
|
|
|
"io"
|
|
@@ -36,15 +37,17 @@ import (
|
|
|
)
|
|
|
|
|
|
const (
|
|
|
- logSender = "webavdTesting"
|
|
|
- webDavServerAddr = "127.0.0.1:9090"
|
|
|
- webDavServerPort = 9090
|
|
|
- sftpServerAddr = "127.0.0.1:9022"
|
|
|
- defaultUsername = "test_user_dav"
|
|
|
- defaultPassword = "test_password"
|
|
|
- configDir = ".."
|
|
|
- osWindows = "windows"
|
|
|
- webDavCert = `-----BEGIN CERTIFICATE-----
|
|
|
+ logSender = "webavdTesting"
|
|
|
+ webDavServerAddr = "localhost:9090"
|
|
|
+ webDavTLSServerAddr = "localhost:9443"
|
|
|
+ webDavServerPort = 9090
|
|
|
+ webDavTLSServerPort = 9443
|
|
|
+ sftpServerAddr = "127.0.0.1:9022"
|
|
|
+ defaultUsername = "test_user_dav"
|
|
|
+ defaultPassword = "test_password"
|
|
|
+ configDir = ".."
|
|
|
+ osWindows = "windows"
|
|
|
+ webDavCert = `-----BEGIN CERTIFICATE-----
|
|
|
MIICHTCCAaKgAwIBAgIUHnqw7QnB1Bj9oUsNpdb+ZkFPOxMwCgYIKoZIzj0EAwIw
|
|
|
RTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoMGElu
|
|
|
dGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMDAyMDQwOTUzMDRaFw0zMDAyMDEw
|
|
@@ -67,8 +70,161 @@ UM2lmBLIXpGgBwYFK4EEACKhZANiAARCjRMqJ85rzMC998X5z761nJ+xL3bkmGVq
|
|
|
WvrJ51t5OxV0v25NsOgR82CANXUgvhVYs7vNFN+jxtb2aj6Xg+/2G/BNxkaFspIV
|
|
|
CzgWkxiz7XE4lgUwX44FCXZM3+JeUbI=
|
|
|
-----END EC PRIVATE KEY-----`
|
|
|
- testFileName = "test_file_dav.dat"
|
|
|
- testDLFileName = "test_download_dav.dat"
|
|
|
+ caCRT = `-----BEGIN CERTIFICATE-----
|
|
|
+MIIE5jCCAs6gAwIBAgIBATANBgkqhkiG9w0BAQsFADATMREwDwYDVQQDEwhDZXJ0
|
|
|
+QXV0aDAeFw0yMTAxMDIyMTIwNTVaFw0yMjA3MDIyMTMwNTJaMBMxETAPBgNVBAMT
|
|
|
+CENlcnRBdXRoMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA4Tiho5xW
|
|
|
+AC15JRkMwfp3/TJwI2As7MY5dele5cmdr5bHAE+sRKqC+Ti88OJWCV5saoyax/1S
|
|
|
+CjxJlQMZMl169P1QYJskKjdG2sdv6RLWLMgwSNRRjxp/Bw9dHdiEb9MjLgu28Jro
|
|
|
+9peQkHcRHeMf5hM9WvlIJGrdzbC4hUehmqggcqgARainBkYjf0SwuWxHeu4nMqkp
|
|
|
+Ak5tcSTLCjHfEFHZ9Te0TIPG5YkWocQKyeLgu4lvuU+DD2W2lym+YVUtRMGs1Env
|
|
|
+k7p+N0DcGU26qfzZ2sF5ZXkqm7dBsGQB9pIxwc2Q8T1dCIyP9OQCKVILdc5aVFf1
|
|
|
+cryQFHYzYNNZXFlIBims5VV5Mgfp8ESHQSue+v6n6ykecLEyKt1F1Y/MWY/nWUSI
|
|
|
+8zdq83jdBAZVjo9MSthxVn57/06s/hQca65IpcTZV2gX0a+eRlAVqaRbAhL3LaZe
|
|
|
+bYsW3WHKoUOftwemuep3nL51TzlXZVL7Oz/ClGaEOsnGG9KFO6jh+W768qC0zLQI
|
|
|
+CdE7v2Zex98sZteHCg9fGJHIaYoF0aJG5P3WI5oZf2fy7UIYN9ADLFZiorCXAZEh
|
|
|
+CSU6mDoRViZ4RGR9GZxbDZ9KYn7O8M/KCR72bkQg73TlMsk1zSXEw0MKLUjtsw6c
|
|
|
+rZ0Jt8t3sRatHO3JrYHALMt9vZfyNCZp0IsCAwEAAaNFMEMwDgYDVR0PAQH/BAQD
|
|
|
+AgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFO1yCNAGr/zQTJIi8lw3
|
|
|
+w5OiuBvMMA0GCSqGSIb3DQEBCwUAA4ICAQA6gCNuM7r8mnx674dm31GxBjQy5ZwB
|
|
|
+7CxDzYEvL/oiZ3Tv3HlPfN2LAAsJUfGnghh9DOytenL2CTZWjl/emP5eijzmlP+9
|
|
|
+zva5I6CIMCf/eDDVsRdO244t0o4uG7+At0IgSDM3bpVaVb4RHZNjEziYChsEYY8d
|
|
|
+HK6iwuRSvFniV6yhR/Vj1Ymi9yZ5xclqseLXiQnUB0PkfIk23+7s42cXB16653fH
|
|
|
+O/FsPyKBLiKJArizLYQc12aP3QOrYoYD9+fAzIIzew7A5C0aanZCGzkuFpO6TRlD
|
|
|
+Tb7ry9Gf0DfPpCgxraH8tOcmnqp/ka3hjqo/SRnnTk0IFrmmLdarJvjD46rKwBo4
|
|
|
+MjyAIR1mQ5j8GTlSFBmSgETOQ/EYvO3FPLmra1Fh7L+DvaVzTpqI9fG3TuyyY+Ri
|
|
|
+Fby4ycTOGSZOe5Fh8lqkX5Y47mCUJ3zHzOA1vUJy2eTlMRGpu47Eb1++Vm6EzPUP
|
|
|
+2EF5aD+zwcssh+atZvQbwxpgVqVcyLt91RSkKkmZQslh0rnlTb68yxvUnD3zw7So
|
|
|
+o6TAf9UvwVMEvdLT9NnFd6hwi2jcNte/h538GJwXeBb8EkfpqLKpTKyicnOdkamZ
|
|
|
+7E9zY8SHNRYMwB9coQ/W8NvufbCgkvOoLyMXk5edbXofXl3PhNGOlraWbghBnzf5
|
|
|
+r3rwjFsQOoZotA==
|
|
|
+-----END CERTIFICATE-----`
|
|
|
+ caCRL = `-----BEGIN X509 CRL-----
|
|
|
+MIICpzCBkAIBATANBgkqhkiG9w0BAQsFADATMREwDwYDVQQDEwhDZXJ0QXV0aBcN
|
|
|
+MjEwMTAyMjEzNDA1WhcNMjMwMTAyMjEzNDA1WjAkMCICEQC+l04DbHWMyC3fG09k
|
|
|
+VXf+Fw0yMTAxMDIyMTM0MDVaoCMwITAfBgNVHSMEGDAWgBTtcgjQBq/80EySIvJc
|
|
|
+N8OTorgbzDANBgkqhkiG9w0BAQsFAAOCAgEAEJ7z+uNc8sqtxlOhSdTGDzX/xput
|
|
|
+E857kFQkSlMnU2whQ8c+XpYrBLA5vIZJNSSwohTpM4+zVBX/bJpmu3wqqaArRO9/
|
|
|
+YcW5mQk9Anvb4WjQW1cHmtNapMTzoC9AiYt/OWPfy+P6JCgCr4Hy6LgQyIRL6bM9
|
|
|
+VYTalolOm1qa4Y5cIeT7iHq/91mfaqo8/6MYRjLl8DOTROpmw8OS9bCXkzGKdCat
|
|
|
+AbAzwkQUSauyoCQ10rpX+Y64w9ng3g4Dr20aCqPf5osaqplEJ2HTK8ljDTidlslv
|
|
|
+9anQj8ax3Su89vI8+hK+YbfVQwrThabgdSjQsn+veyx8GlP8WwHLAQ379KjZjWg+
|
|
|
+OlOSwBeU1vTdP0QcB8X5C2gVujAyuQekbaV86xzIBOj7vZdfHZ6ee30TZ2FKiMyg
|
|
|
+7/N2OqW0w77ChsjB4MSHJCfuTgIeg62GzuZXLM+Q2Z9LBdtm4Byg+sm/P52adOEg
|
|
|
+gVb2Zf4KSvsAmA0PIBlu449/QXUFcMxzLFy7mwTeZj2B4Ln0Hm0szV9f9R8MwMtB
|
|
|
+SyLYxVH+mgqaR6Jkk22Q/yYyLPaELfafX5gp/AIXG8n0zxfVaTvK3auSgb1Q6ZLS
|
|
|
+5QH9dSIsmZHlPq7GoSXmKpMdjUL8eaky/IMteioyXgsBiATzl5L2dsw6MTX3MDF0
|
|
|
+QbDK+MzhmbKfDxs=
|
|
|
+-----END X509 CRL-----`
|
|
|
+ client1Crt = `-----BEGIN CERTIFICATE-----
|
|
|
+MIIEITCCAgmgAwIBAgIRAIppZHoj1hM80D7WzTEKLuAwDQYJKoZIhvcNAQELBQAw
|
|
|
+EzERMA8GA1UEAxMIQ2VydEF1dGgwHhcNMjEwMTAyMjEyMzEwWhcNMjIwNzAyMjEz
|
|
|
+MDUxWjASMRAwDgYDVQQDEwdjbGllbnQxMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
|
|
|
+MIIBCgKCAQEAoKbYY9MdF2kF/nhBESIiZTdVYtA8XL9xrIZyDj9EnCiTxHiVbJtH
|
|
|
+XVwszqSl5TRrotPmnmAQcX3r8OCk+z+RQZ0QQj257P3kG6q4rNnOcWCS5xEd20jP
|
|
|
+yhQ3m+hMGfZsotNTQze1ochuQgLUN6IPyPxZkH22ia3jX4iu1eo/QxeLYHj1UHw4
|
|
|
+3Cii9yE+j5kPUC21xmnrGKdUrB55NYLXHx6yTIqYR5znSOVB8oJi18/hwdZmH859
|
|
|
+DHhm0Hx1HrS+jbjI3+CMorZJ3WUyNf+CkiVLD3xYutPbxzEpwiqkG/XYzLH0habT
|
|
|
+cDcILo18n+o3jvem2KWBrDhyairjIDscwQIDAQABo3EwbzAOBgNVHQ8BAf8EBAMC
|
|
|
+A7gwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBSJ5GIv
|
|
|
+zIrE4ZSQt2+CGblKTDswizAfBgNVHSMEGDAWgBTtcgjQBq/80EySIvJcN8OTorgb
|
|
|
+zDANBgkqhkiG9w0BAQsFAAOCAgEALh4f5GhvNYNou0Ab04iQBbLEdOu2RlbK1B5n
|
|
|
+K9P/umYenBHMY/z6HT3+6tpcHsDuqE8UVdq3f3Gh4S2Gu9m8PRitT+cJ3gdo9Plm
|
|
|
+3rD4ufn/s6rGg3ppydXcedm17492tbccUDWOBZw3IO/ASVq13WPgT0/Kev7cPq0k
|
|
|
+sSdSNhVeXqx8Myc2/d+8GYyzbul2Kpfa7h9i24sK49E9ftnSmsIvngONo08eT1T0
|
|
|
+3wAOyK2981LIsHaAWcneShKFLDB6LeXIT9oitOYhiykhFlBZ4M1GNlSNfhQ8IIQP
|
|
|
+xbqMNXCLkW4/BtLhGEEcg0QVso6Kudl9rzgTfQknrdF7pHp6rS46wYUjoSyIY6dl
|
|
|
+oLmnoAVJX36J3QPWelePI9e07X2wrTfiZWewwgw3KNRWjd6/zfPLe7GoqXnK1S2z
|
|
|
+PT8qMfCaTwKTtUkzXuTFvQ8bAo2My/mS8FOcpkt2oQWeOsADHAUX7fz5BCoa2DL3
|
|
|
+k/7Mh4gVT+JYZEoTwCFuYHgMWFWe98naqHi9lB4yR981p1QgXgxO7qBeipagKY1F
|
|
|
+LlH1iwXUqZ3MZnkNA+4e1Fglsw3sa/rC+L98HnznJ/YbTfQbCP6aQ1qcOymrjMud
|
|
|
+7MrFwqZjtd/SK4Qx1VpK6jGEAtPgWBTUS3p9ayg6lqjMBjsmySWfvRsDQbq6P5Ct
|
|
|
+O/e3EH8=
|
|
|
+-----END CERTIFICATE-----`
|
|
|
+ client1Key = `-----BEGIN RSA PRIVATE KEY-----
|
|
|
+MIIEpAIBAAKCAQEAoKbYY9MdF2kF/nhBESIiZTdVYtA8XL9xrIZyDj9EnCiTxHiV
|
|
|
+bJtHXVwszqSl5TRrotPmnmAQcX3r8OCk+z+RQZ0QQj257P3kG6q4rNnOcWCS5xEd
|
|
|
+20jPyhQ3m+hMGfZsotNTQze1ochuQgLUN6IPyPxZkH22ia3jX4iu1eo/QxeLYHj1
|
|
|
+UHw43Cii9yE+j5kPUC21xmnrGKdUrB55NYLXHx6yTIqYR5znSOVB8oJi18/hwdZm
|
|
|
+H859DHhm0Hx1HrS+jbjI3+CMorZJ3WUyNf+CkiVLD3xYutPbxzEpwiqkG/XYzLH0
|
|
|
+habTcDcILo18n+o3jvem2KWBrDhyairjIDscwQIDAQABAoIBAEBSjVFqtbsp0byR
|
|
|
+aXvyrtLX1Ng7h++at2jca85Ihq//jyqbHTje8zPuNAKI6eNbmb0YGr5OuEa4pD9N
|
|
|
+ssDmMsKSoG/lRwwcm7h4InkSvBWpFShvMgUaohfHAHzsBYxfnh+TfULsi0y7c2n6
|
|
|
+t/2OZcOTRkkUDIITnXYiw93ibHHv2Mv2bBDu35kGrcK+c2dN5IL5ZjTjMRpbJTe2
|
|
|
+44RBJbdTxHBVSgoGBnugF+s2aEma6Ehsj70oyfoVpM6Aed5kGge0A5zA1JO7WCn9
|
|
|
+Ay/DzlULRXHjJIoRWd2NKvx5n3FNppUc9vJh2plRHalRooZ2+MjSf8HmXlvG2Hpb
|
|
|
+ScvmWgECgYEA1G+A/2KnxWsr/7uWIJ7ClcGCiNLdk17Pv3DZ3G4qUsU2ITftfIbb
|
|
|
+tU0Q/b19na1IY8Pjy9ptP7t74/hF5kky97cf1FA8F+nMj/k4+wO8QDI8OJfzVzh9
|
|
|
+PwielA5vbE+xmvis5Hdp8/od1Yrc/rPSy2TKtPFhvsqXjqoUmOAjDP8CgYEAwZjH
|
|
|
+9dt1sc2lx/rMxihlWEzQ3JPswKW9/LJAmbRBoSWF9FGNjbX7uhWtXRKJkzb8ZAwa
|
|
|
+88azluNo2oftbDD/+jw8b2cDgaJHlLAkSD4O1D1RthW7/LKD15qZ/oFsRb13NV85
|
|
|
+ZNKtwslXGbfVNyGKUVFm7fVA8vBAOUey+LKDFj8CgYEAg8WWstOzVdYguMTXXuyb
|
|
|
+ruEV42FJaDyLiSirOvxq7GTAKuLSQUg1yMRBIeQEo2X1XU0JZE3dLodRVhuO4EXP
|
|
|
+g7Dn4X7Th9HSvgvNuIacowWGLWSz4Qp9RjhGhXhezUSx2nseY6le46PmFavJYYSR
|
|
|
+4PBofMyt4PcyA6Cknh+KHmkCgYEAnTriG7ETE0a7v4DXUpB4TpCEiMCy5Xs2o8Z5
|
|
|
+ZNva+W+qLVUWq+MDAIyechqeFSvxK6gRM69LJ96lx+XhU58wJiFJzAhT9rK/g+jS
|
|
|
+bsHH9WOfu0xHkuHA5hgvvV2Le9B2wqgFyva4HJy82qxMxCu/VG/SMqyfBS9OWbb7
|
|
|
+ibQhdq0CgYAl53LUWZsFSZIth1vux2LVOsI8C3X1oiXDGpnrdlQ+K7z57hq5EsRq
|
|
|
+GC+INxwXbvKNqp5h0z2MvmKYPDlGVTgw8f8JjM7TkN17ERLcydhdRrMONUryZpo8
|
|
|
+1xTob+8blyJgfxZUIAKbMbMbIiU0WAF0rfD/eJJwS4htOW/Hfv4TGA==
|
|
|
+-----END RSA PRIVATE KEY-----`
|
|
|
+ // client 2 crt is revoked
|
|
|
+ client2Crt = `-----BEGIN CERTIFICATE-----
|
|
|
+MIIEITCCAgmgAwIBAgIRAL6XTgNsdYzILd8bT2RVd/4wDQYJKoZIhvcNAQELBQAw
|
|
|
+EzERMA8GA1UEAxMIQ2VydEF1dGgwHhcNMjEwMTAyMjEyMzIwWhcNMjIwNzAyMjEz
|
|
|
+MDUxWjASMRAwDgYDVQQDEwdjbGllbnQyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
|
|
|
+MIIBCgKCAQEA6xjW5KQR3/OFQtV5M75WINqQ4AzXSu6DhSz/yumaaQZP/UxY+6hi
|
|
|
+jcrFzGo9MMie/Sza8DhkXOFAl2BelUubrOeB2cl+/Gr8OCyRi2Gv6j3zCsuN/4jQ
|
|
|
+tNaoez/IbkDvI3l/ZpzBtnuNY2RiemGgHuORXHRVf3qVlsw+npBIRW5rM2HkO/xG
|
|
|
+oZjeBErWVu390Lyn+Gvk2TqQDnkutWnxUC60/zPlHhXZ4BwaFAekbSnjsSDB1YFM
|
|
|
+s8HwW4oBryoxdj3/+/qLrBHt75IdLw3T7/V1UDJQM3EvSQOr12w4egpldhtsC871
|
|
|
+nnBQZeY6qA5feffIwwg/6lJm70o6S6OX6wIDAQABo3EwbzAOBgNVHQ8BAf8EBAMC
|
|
|
+A7gwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTB84v5
|
|
|
+t9HqhLhMODbn6oYkEQt3KzAfBgNVHSMEGDAWgBTtcgjQBq/80EySIvJcN8OTorgb
|
|
|
+zDANBgkqhkiG9w0BAQsFAAOCAgEALGtBCve5k8tToL3oLuXp/oSik6ovIB/zq4I/
|
|
|
+4zNMYPU31+ZWz6aahysgx1JL1yqTa3Qm8o2tu52MbnV10dM7CIw7c/cYa+c+OPcG
|
|
|
+5LF97kp13X+r2axy+CmwM86b4ILaDGs2Qyai6VB6k7oFUve+av5o7aUrNFpqGCJz
|
|
|
+HWdtHZSVA3JMATzy0TfWanwkzreqfdw7qH0yZ9bDURlBKAVWrqnCstva9jRuv+AI
|
|
|
+eqxr/4Ro986TFjJdoAP3Vr16CPg7/B6GA/KmsBWJrpeJdPWq4i2gpLKvYZoy89qD
|
|
|
+mUZf34RbzcCtV4NvV1DadGnt4us0nvLrvS5rL2+2uWD09kZYq9RbLkvgzF/cY0fz
|
|
|
+i7I1bi5XQ+alWe0uAk5ZZL/D+GTRYUX1AWwCqwJxmHrMxcskMyO9pXvLyuSWRDLo
|
|
|
+YNBrbX9nLcfJzVCp+X+9sntTHjs4l6Cw+fLepJIgtgqdCHtbhTiv68vSM6cgb4br
|
|
|
+6n2xrXRKuioiWFOrTSRr+oalZh8dGJ/xvwY8IbWknZAvml9mf1VvfE7Ma5P777QM
|
|
|
+fsbYVTq0Y3R/5hIWsC3HA5z6MIM8L1oRe/YyhP3CTmrCHkVKyDOosGXpGz+JVcyo
|
|
|
+cfYkY5A3yFKB2HaCwZSfwFmRhxkrYWGEbHv3Cd9YkZs1J3hNhGFZyVMC9Uh0S85a
|
|
|
+6zdDidU=
|
|
|
+-----END CERTIFICATE-----`
|
|
|
+ client2Key = `-----BEGIN RSA PRIVATE KEY-----
|
|
|
+MIIEpAIBAAKCAQEA6xjW5KQR3/OFQtV5M75WINqQ4AzXSu6DhSz/yumaaQZP/UxY
|
|
|
++6hijcrFzGo9MMie/Sza8DhkXOFAl2BelUubrOeB2cl+/Gr8OCyRi2Gv6j3zCsuN
|
|
|
+/4jQtNaoez/IbkDvI3l/ZpzBtnuNY2RiemGgHuORXHRVf3qVlsw+npBIRW5rM2Hk
|
|
|
+O/xGoZjeBErWVu390Lyn+Gvk2TqQDnkutWnxUC60/zPlHhXZ4BwaFAekbSnjsSDB
|
|
|
+1YFMs8HwW4oBryoxdj3/+/qLrBHt75IdLw3T7/V1UDJQM3EvSQOr12w4egpldhts
|
|
|
+C871nnBQZeY6qA5feffIwwg/6lJm70o6S6OX6wIDAQABAoIBAFatstVb1KdQXsq0
|
|
|
+cFpui8zTKOUiduJOrDkWzTygAmlEhYtrccdfXu7OWz0x0lvBLDVGK3a0I/TGrAzj
|
|
|
+4BuFY+FM/egxTVt9in6fmA3et4BS1OAfCryzUdfK6RV//8L+t+zJZ/qKQzWnugpy
|
|
|
+QYjDo8ifuMFwtvEoXizaIyBNLAhEp9hnrv+Tyi2O2gahPvCHsD48zkyZRCHYRstD
|
|
|
+NH5cIrwz9/RJgPO1KI+QsJE7Nh7stR0sbr+5TPU4fnsL2mNhMUF2TJrwIPrc1yp+
|
|
|
+YIUjdnh3SO88j4TQT3CIrWi8i4pOy6N0dcVn3gpCRGaqAKyS2ZYUj+yVtLO4KwxZ
|
|
|
+SZ1lNvECgYEA78BrF7f4ETfWSLcBQ3qxfLs7ibB6IYo2x25685FhZjD+zLXM1AKb
|
|
|
+FJHEXUm3mUYrFJK6AFEyOQnyGKBOLs3S6oTAswMPbTkkZeD1Y9O6uv0AHASLZnK6
|
|
|
+pC6ub0eSRF5LUyTQ55Jj8D7QsjXJueO8v+G5ihWhNSN9tB2UA+8NBmkCgYEA+weq
|
|
|
+cvoeMIEMBQHnNNLy35bwfqrceGyPIRBcUIvzQfY1vk7KW6DYOUzC7u+WUzy/hA52
|
|
|
+DjXVVhua2eMQ9qqtOav7djcMc2W9RbLowxvno7K5qiCss013MeWk64TCWy+WMp5A
|
|
|
+AVAtOliC3hMkIKqvR2poqn+IBTh1449agUJQqTMCgYEAu06IHGq1GraV6g9XpGF5
|
|
|
+wqoAlMzUTdnOfDabRilBf/YtSr+J++ThRcuwLvXFw7CnPZZ4TIEjDJ7xjj3HdxeE
|
|
|
+fYYjineMmNd40UNUU556F1ZLvJfsVKizmkuCKhwvcMx+asGrmA+tlmds4p3VMS50
|
|
|
+KzDtpKzLWlmU/p/RINWlRmkCgYBy0pHTn7aZZx2xWKqCDg+L2EXPGqZX6wgZDpu7
|
|
|
+OBifzlfM4ctL2CmvI/5yPmLbVgkgBWFYpKUdiujsyyEiQvWTUKhn7UwjqKDHtcsk
|
|
|
+G6p7xS+JswJrzX4885bZJ9Oi1AR2yM3sC9l0O7I4lDbNPmWIXBLeEhGMmcPKv/Kc
|
|
|
+91Ff4wKBgQCF3ur+Vt0PSU0ucrPVHjCe7tqazm0LJaWbPXL1Aw0pzdM2EcNcW/MA
|
|
|
+w0kqpr7MgJ94qhXCBcVcfPuFN9fBOadM3UBj1B45Cz3pptoK+ScI8XKno6jvVK/p
|
|
|
+xr5cb9VBRBtB9aOKVfuRhpatAfS2Pzm2Htae9lFn7slGPUmu2hkjDw==
|
|
|
+-----END RSA PRIVATE KEY-----`
|
|
|
+ testFileName = "test_file_dav.dat"
|
|
|
+ testDLFileName = "test_download_dav.dat"
|
|
|
+ tlsClient1Username = "client1"
|
|
|
+ tlsClient2Username = "client2"
|
|
|
)
|
|
|
|
|
|
var (
|
|
@@ -81,6 +237,8 @@ var (
|
|
|
logFilePath string
|
|
|
certPath string
|
|
|
keyPath string
|
|
|
+ caCrtPath string
|
|
|
+ caCRLPath string
|
|
|
)
|
|
|
|
|
|
func TestMain(m *testing.M) {
|
|
@@ -108,6 +266,8 @@ func TestMain(m *testing.M) {
|
|
|
|
|
|
certPath = filepath.Join(os.TempDir(), "test_dav.crt")
|
|
|
keyPath = filepath.Join(os.TempDir(), "test_dav.key")
|
|
|
+ caCrtPath = filepath.Join(os.TempDir(), "test_dav_ca.crt")
|
|
|
+ caCRLPath = filepath.Join(os.TempDir(), "test_dav_crl.crt")
|
|
|
err = os.WriteFile(certPath, []byte(webDavCert), os.ModePerm)
|
|
|
if err != nil {
|
|
|
logger.ErrorToConsole("error writing WebDAV certificate: %v", err)
|
|
@@ -118,6 +278,16 @@ func TestMain(m *testing.M) {
|
|
|
logger.ErrorToConsole("error writing WebDAV private key: %v", err)
|
|
|
os.Exit(1)
|
|
|
}
|
|
|
+ err = os.WriteFile(caCrtPath, []byte(caCRT), os.ModePerm)
|
|
|
+ if err != nil {
|
|
|
+ logger.ErrorToConsole("error writing WebDAV CA crt: %v", err)
|
|
|
+ os.Exit(1)
|
|
|
+ }
|
|
|
+ err = os.WriteFile(caCRLPath, []byte(caCRL), os.ModePerm)
|
|
|
+ if err != nil {
|
|
|
+ logger.ErrorToConsole("error writing WebDAV CRL: %v", err)
|
|
|
+ os.Exit(1)
|
|
|
+ }
|
|
|
|
|
|
err = common.Initialize(commonConf)
|
|
|
if err != nil {
|
|
@@ -155,10 +325,19 @@ func TestMain(m *testing.M) {
|
|
|
sftpdConf.HostKeys = []string{hostKeyPath}
|
|
|
|
|
|
webDavConf := config.GetWebDAVDConfig()
|
|
|
+ webDavConf.CertificateFile = certPath
|
|
|
+ webDavConf.CertificateKeyFile = keyPath
|
|
|
+ webDavConf.CACertificates = []string{caCrtPath}
|
|
|
+ webDavConf.CARevocationLists = []string{caCRLPath}
|
|
|
webDavConf.Bindings = []webdavd.Binding{
|
|
|
{
|
|
|
Port: webDavServerPort,
|
|
|
},
|
|
|
+ {
|
|
|
+ Port: webDavTLSServerPort,
|
|
|
+ EnableHTTPS: true,
|
|
|
+ ClientAuthType: 2,
|
|
|
+ },
|
|
|
}
|
|
|
webDavConf.Cors = webdavd.Cors{
|
|
|
Enabled: true,
|
|
@@ -209,6 +388,7 @@ func TestMain(m *testing.M) {
|
|
|
}()
|
|
|
|
|
|
waitTCPListening(webDavConf.Bindings[0].GetAddress())
|
|
|
+ waitTCPListening(webDavConf.Bindings[1].GetAddress())
|
|
|
waitTCPListening(httpdConf.Bindings[0].GetAddress())
|
|
|
waitTCPListening(sftpdConf.Bindings[0].GetAddress())
|
|
|
webdavd.ReloadCertificateMgr() //nolint:errcheck
|
|
@@ -220,6 +400,8 @@ func TestMain(m *testing.M) {
|
|
|
os.Remove(postConnectPath)
|
|
|
os.Remove(certPath)
|
|
|
os.Remove(keyPath)
|
|
|
+ os.Remove(caCrtPath)
|
|
|
+ os.Remove(caCRLPath)
|
|
|
os.Remove(hostKeyPath)
|
|
|
os.Remove(hostKeyPath + ".pub")
|
|
|
os.Exit(exitCode)
|
|
@@ -281,6 +463,13 @@ func TestInitialization(t *testing.T) {
|
|
|
cfg.CARevocationLists = nil
|
|
|
err = cfg.Initialize(configDir)
|
|
|
assert.Error(t, err)
|
|
|
+
|
|
|
+ cfg.CertificateFile = certPath
|
|
|
+ cfg.CertificateKeyFile = keyPath
|
|
|
+ cfg.CACertificates = []string{caCrtPath}
|
|
|
+ cfg.CARevocationLists = []string{caCRLPath}
|
|
|
+ err = cfg.Initialize(configDir)
|
|
|
+ assert.Error(t, err)
|
|
|
}
|
|
|
|
|
|
func TestBasicHandling(t *testing.T) {
|
|
@@ -293,7 +482,7 @@ func TestBasicHandling(t *testing.T) {
|
|
|
sftpUser, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
for _, user := range []dataprovider.User{localUser, sftpUser} {
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
testFilePath := filepath.Join(homeBasePath, testFileName)
|
|
|
testFileSize := int64(65535)
|
|
@@ -378,7 +567,7 @@ func TestBasicHandlingCryptFs(t *testing.T) {
|
|
|
u.QuotaSize = 6553600
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
|
|
|
testFilePath := filepath.Join(homeBasePath, testFileName)
|
|
@@ -459,7 +648,7 @@ func TestPropPatch(t *testing.T) {
|
|
|
for _, u := range []dataprovider.User{getTestUser(), getTestUserWithCryptFs(), sftpUser} {
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client), sftpUser.Username)
|
|
|
|
|
|
testFilePath := filepath.Join(homeBasePath, testFileName)
|
|
@@ -500,10 +689,10 @@ func TestLoginInvalidPwd(t *testing.T) {
|
|
|
u := getTestUser()
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
user.Password = "wrong"
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, false, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
_, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
|
assert.NoError(t, err)
|
|
@@ -511,7 +700,7 @@ func TestLoginInvalidPwd(t *testing.T) {
|
|
|
|
|
|
func TestLoginNonExistentUser(t *testing.T) {
|
|
|
user := getTestUser()
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
}
|
|
|
|
|
@@ -527,17 +716,17 @@ func TestDefender(t *testing.T) {
|
|
|
|
|
|
user, _, err := httpdtest.AddUser(getTestUser(), http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
|
|
|
for i := 0; i < 3; i++ {
|
|
|
user.Password = "wrong_pwd"
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, false, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
}
|
|
|
|
|
|
user.Password = defaultPassword
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, true, nil)
|
|
|
err = checkBasicFunc(client)
|
|
|
if assert.Error(t, err) {
|
|
|
assert.Contains(t, err.Error(), "403")
|
|
@@ -568,10 +757,10 @@ func TestLoginExternalAuth(t *testing.T) {
|
|
|
providerConf.ExternalAuthScope = 0
|
|
|
err = dataprovider.Initialize(providerConf, configDir, true)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(u)
|
|
|
+ client := getWebDavClient(u, false, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
u.Username = defaultUsername + "1"
|
|
|
- client = getWebDavClient(u)
|
|
|
+ client = getWebDavClient(u, false, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
user, _, err := httpdtest.GetUserByUsername(defaultUsername, http.StatusOK)
|
|
|
assert.NoError(t, err)
|
|
@@ -608,20 +797,20 @@ func TestPreLoginHook(t *testing.T) {
|
|
|
assert.NoError(t, err)
|
|
|
_, _, err = httpdtest.GetUserByUsername(defaultUsername, http.StatusNotFound)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(u)
|
|
|
+ client := getWebDavClient(u, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
|
|
|
user, _, err := httpdtest.GetUserByUsername(defaultUsername, http.StatusOK)
|
|
|
assert.NoError(t, err)
|
|
|
// test login with an existing user
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
err = os.WriteFile(preLoginPath, getPreLoginScriptContent(user, true), os.ModePerm)
|
|
|
assert.NoError(t, err)
|
|
|
// update the user to remove it from the cache
|
|
|
user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
assert.NoError(t, err)
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, true, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
// update the user to remove it from the cache
|
|
|
user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
@@ -629,7 +818,7 @@ func TestPreLoginHook(t *testing.T) {
|
|
|
user.Status = 0
|
|
|
err = os.WriteFile(preLoginPath, getPreLoginScriptContent(user, false), os.ModePerm)
|
|
|
assert.NoError(t, err)
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, true, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
|
|
|
_, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
@@ -658,7 +847,7 @@ func TestPostConnectHook(t *testing.T) {
|
|
|
assert.NoError(t, err)
|
|
|
err = os.WriteFile(postConnectPath, getPostConnectScriptContent(0), os.ModePerm)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
err = os.WriteFile(postConnectPath, getPostConnectScriptContent(1), os.ModePerm)
|
|
|
assert.NoError(t, err)
|
|
@@ -684,7 +873,7 @@ func TestMaxConnections(t *testing.T) {
|
|
|
|
|
|
user, _, err := httpdtest.AddUser(getTestUser(), http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
// now add a fake connection
|
|
|
fs := vfs.NewOsFs("id", os.TempDir(), nil)
|
|
@@ -708,7 +897,7 @@ func TestMaxSessions(t *testing.T) {
|
|
|
u.MaxSessions = 1
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
// now add a fake connection
|
|
|
fs := vfs.NewOsFs("id", os.TempDir(), nil)
|
|
@@ -731,7 +920,7 @@ func TestLoginWithIPilters(t *testing.T) {
|
|
|
u.Filters.AllowedIP = []string{"172.19.0.0/16"}
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
|
|
|
_, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
@@ -765,7 +954,7 @@ func TestDownloadErrors(t *testing.T) {
|
|
|
}
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
testFilePath1 := filepath.Join(user.HomeDir, subDir1, "file.zipp")
|
|
|
testFilePath2 := filepath.Join(user.HomeDir, subDir2, "file.zipp")
|
|
|
testFilePath3 := filepath.Join(user.HomeDir, subDir2, "file.jpg")
|
|
@@ -815,7 +1004,7 @@ func TestUploadErrors(t *testing.T) {
|
|
|
}
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
testFilePath := filepath.Join(homeBasePath, testFileName)
|
|
|
testFileSize := user.QuotaSize
|
|
|
err = createTestFile(testFilePath, testFileSize)
|
|
@@ -859,13 +1048,13 @@ func TestDeniedLoginMethod(t *testing.T) {
|
|
|
u.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodPassword}
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
|
|
|
user.Filters.DeniedLoginMethods = []string{dataprovider.SSHLoginMethodPublicKey, dataprovider.SSHLoginMethodKeyAndKeyboardInt}
|
|
|
user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
assert.NoError(t, err)
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
|
|
|
_, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
@@ -879,13 +1068,13 @@ func TestDeniedProtocols(t *testing.T) {
|
|
|
u.Filters.DeniedProtocols = []string{common.ProtocolWebDAV}
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
|
|
|
user.Filters.DeniedProtocols = []string{common.ProtocolSSH, common.ProtocolFTP}
|
|
|
user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
assert.NoError(t, err)
|
|
|
- client = getWebDavClient(user)
|
|
|
+ client = getWebDavClient(user, false, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
|
|
|
_, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
@@ -918,7 +1107,7 @@ func TestQuotaLimits(t *testing.T) {
|
|
|
testFilePath2 := filepath.Join(homeBasePath, testFileName2)
|
|
|
err = createTestFile(testFilePath2, testFileSize2)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
// test quota files
|
|
|
err = uploadFile(testFilePath, testFileName+".quota", testFileSize, client)
|
|
|
assert.NoError(t, err)
|
|
@@ -1001,7 +1190,7 @@ func TestUploadMaxSize(t *testing.T) {
|
|
|
testFilePath1 := filepath.Join(homeBasePath, testFileName1)
|
|
|
err = createTestFile(testFilePath1, testFileSize1)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
err = uploadFile(testFilePath1, testFileName1, testFileSize1, client)
|
|
|
assert.Error(t, err)
|
|
|
err = uploadFile(testFilePath, testFileName, testFileSize, client)
|
|
@@ -1048,7 +1237,7 @@ func TestClientClose(t *testing.T) {
|
|
|
testFilePath := filepath.Join(homeBasePath, testFileName)
|
|
|
err = createTestFile(testFilePath, testFileSize)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.NoError(t, checkBasicFunc(client))
|
|
|
|
|
|
var wg sync.WaitGroup
|
|
@@ -1149,7 +1338,7 @@ func TestLoginWithDatabaseCredentials(t *testing.T) {
|
|
|
|
|
|
assert.NoFileExists(t, credentialsFile)
|
|
|
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
|
|
|
err = client.Connect()
|
|
|
assert.NoError(t, err)
|
|
@@ -1183,7 +1372,7 @@ func TestLoginInvalidFs(t *testing.T) {
|
|
|
err = os.Remove(credentialsFile)
|
|
|
assert.NoError(t, err)
|
|
|
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
assert.Error(t, checkBasicFunc(client))
|
|
|
|
|
|
_, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
@@ -1208,7 +1397,7 @@ func TestBytesRangeRequests(t *testing.T) {
|
|
|
fileContent := []byte("test file contents")
|
|
|
err = os.WriteFile(testFilePath, fileContent, os.ModePerm)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
err = uploadFile(testFilePath, testFileName, int64(len(fileContent)), client)
|
|
|
assert.NoError(t, err)
|
|
|
remotePath := fmt.Sprintf("http://%v/%v", webDavServerAddr, testFileName)
|
|
@@ -1290,7 +1479,7 @@ func TestGETAsPROPFIND(t *testing.T) {
|
|
|
resp.Body.Close()
|
|
|
}
|
|
|
}
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
err = client.MkdirAll(path.Join(subDir1, "sub", "sub1"), os.ModePerm)
|
|
|
assert.NoError(t, err)
|
|
|
subPath := fmt.Sprintf("http://%v/%v", webDavServerAddr, subDir1)
|
|
@@ -1341,7 +1530,7 @@ func TestStat(t *testing.T) {
|
|
|
u.Permissions["/subdir"] = []string{dataprovider.PermUpload, dataprovider.PermListItems, dataprovider.PermDownload}
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
subDir := "subdir"
|
|
|
testFilePath := filepath.Join(homeBasePath, testFileName)
|
|
|
testFileSize := int64(65535)
|
|
@@ -1387,7 +1576,7 @@ func TestUploadOverwriteVfolder(t *testing.T) {
|
|
|
assert.NoError(t, err)
|
|
|
user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
assert.NoError(t, err)
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, false, nil)
|
|
|
files, err := client.ReadDir(".")
|
|
|
assert.NoError(t, err)
|
|
|
vdirFound := false
|
|
@@ -1442,7 +1631,7 @@ func TestMiscCommands(t *testing.T) {
|
|
|
assert.NoError(t, err)
|
|
|
for _, user := range []dataprovider.User{localUser, sftpUser} {
|
|
|
dir := "testDir"
|
|
|
- client := getWebDavClient(user)
|
|
|
+ client := getWebDavClient(user, true, nil)
|
|
|
err = client.MkdirAll(path.Join(dir, "sub1", "sub2"), os.ModePerm)
|
|
|
assert.NoError(t, err)
|
|
|
testFilePath := filepath.Join(homeBasePath, testFileName)
|
|
@@ -1504,6 +1693,319 @@ func TestMiscCommands(t *testing.T) {
|
|
|
assert.NoError(t, err)
|
|
|
}
|
|
|
|
|
|
+func TestClientCertificateAuthRevokedCert(t *testing.T) {
|
|
|
+ u := getTestUser()
|
|
|
+ u.Username = tlsClient2Username
|
|
|
+ u.Filters.TLSUsername = dataprovider.TLSUsernameCN
|
|
|
+ user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig := &tls.Config{
|
|
|
+ ServerName: "localhost",
|
|
|
+ InsecureSkipVerify: true, // use this for tests only
|
|
|
+ MinVersion: tls.VersionTLS12,
|
|
|
+ }
|
|
|
+ tlsCert, err := tls.X509KeyPair([]byte(client2Crt), []byte(client2Key))
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig.Certificates = append(tlsConfig.Certificates, tlsCert)
|
|
|
+ client := getWebDavClient(user, true, tlsConfig)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ if assert.Error(t, err) {
|
|
|
+ assert.Contains(t, err.Error(), "bad certificate")
|
|
|
+ }
|
|
|
+
|
|
|
+ _, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.RemoveAll(user.GetHomeDir())
|
|
|
+ assert.NoError(t, err)
|
|
|
+}
|
|
|
+
|
|
|
+func TestClientCertificateAuth(t *testing.T) {
|
|
|
+ u := getTestUser()
|
|
|
+ u.Username = tlsClient1Username
|
|
|
+ u.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodPassword, dataprovider.LoginMethodTLSCertificateAndPwd}
|
|
|
+ user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig := &tls.Config{
|
|
|
+ ServerName: "localhost",
|
|
|
+ InsecureSkipVerify: true, // use this for tests only
|
|
|
+ MinVersion: tls.VersionTLS12,
|
|
|
+ }
|
|
|
+ tlsCert, err := tls.X509KeyPair([]byte(client1Crt), []byte(client1Key))
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig.Certificates = append(tlsConfig.Certificates, tlsCert)
|
|
|
+ // TLS username is not enabled, mutual TLS should fail
|
|
|
+ resp, err := getTLSHTTPClient(tlsConfig).Get(fmt.Sprintf("https://%v/", webDavTLSServerAddr))
|
|
|
+ if assert.NoError(t, err) {
|
|
|
+ defer resp.Body.Close()
|
|
|
+ body, err := io.ReadAll(resp.Body)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ assert.Equal(t, http.StatusUnauthorized, resp.StatusCode, string(body))
|
|
|
+ }
|
|
|
+
|
|
|
+ user.Filters.TLSUsername = dataprovider.TLSUsernameCN
|
|
|
+ user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ client := getWebDavClient(user, true, tlsConfig)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ user.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodPassword, dataprovider.LoginMethodTLSCertificate}
|
|
|
+ user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ client = getWebDavClient(user, true, tlsConfig)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ _, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.RemoveAll(user.GetHomeDir())
|
|
|
+ assert.NoError(t, err)
|
|
|
+}
|
|
|
+
|
|
|
+func TestWrongClientCertificate(t *testing.T) {
|
|
|
+ u := getTestUser()
|
|
|
+ u.Username = tlsClient2Username
|
|
|
+ u.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodTLSCertificateAndPwd}
|
|
|
+ u.Filters.TLSUsername = dataprovider.TLSUsernameCN
|
|
|
+ user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig := &tls.Config{
|
|
|
+ ServerName: "localhost",
|
|
|
+ InsecureSkipVerify: true, // use this for tests only
|
|
|
+ MinVersion: tls.VersionTLS12,
|
|
|
+ }
|
|
|
+ tlsCert, err := tls.X509KeyPair([]byte(client1Crt), []byte(client1Key))
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig.Certificates = append(tlsConfig.Certificates, tlsCert)
|
|
|
+
|
|
|
+ // the certificate common name is client1 and it does not exists
|
|
|
+ resp, err := getTLSHTTPClient(tlsConfig).Get(fmt.Sprintf("https://%v/", webDavTLSServerAddr))
|
|
|
+ if assert.NoError(t, err) {
|
|
|
+ defer resp.Body.Close()
|
|
|
+ body, err := io.ReadAll(resp.Body)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ assert.Equal(t, http.StatusUnauthorized, resp.StatusCode, string(body))
|
|
|
+ }
|
|
|
+
|
|
|
+ user.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodPassword, dataprovider.LoginMethodTLSCertificate}
|
|
|
+ user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ // now create client1
|
|
|
+ u = getTestUser()
|
|
|
+ u.Username = tlsClient1Username
|
|
|
+ u.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodPassword, dataprovider.LoginMethodTLSCertificate}
|
|
|
+ u.Filters.TLSUsername = dataprovider.TLSUsernameCN
|
|
|
+ user1, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ resp, err = getTLSHTTPClient(tlsConfig).Get(fmt.Sprintf("https://%v:%v@%v/", tlsClient2Username, defaultPassword,
|
|
|
+ webDavTLSServerAddr))
|
|
|
+ if assert.NoError(t, err) {
|
|
|
+ defer resp.Body.Close()
|
|
|
+ body, err := io.ReadAll(resp.Body)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ assert.Equal(t, http.StatusUnauthorized, resp.StatusCode, string(body))
|
|
|
+ assert.Contains(t, string(body), "CN \"client1\" does not match username \"client2\"")
|
|
|
+ }
|
|
|
+
|
|
|
+ _, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.RemoveAll(user.GetHomeDir())
|
|
|
+ assert.NoError(t, err)
|
|
|
+ _, err = httpdtest.RemoveUser(user1, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.RemoveAll(user1.GetHomeDir())
|
|
|
+ assert.NoError(t, err)
|
|
|
+}
|
|
|
+
|
|
|
+func TestClientCertificateAuthCachedUser(t *testing.T) {
|
|
|
+ u := getTestUser()
|
|
|
+ u.Username = tlsClient1Username
|
|
|
+ u.Filters.TLSUsername = dataprovider.TLSUsernameCN
|
|
|
+ u.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodTLSCertificateAndPwd}
|
|
|
+ user, _, err := httpdtest.AddUser(u, http.StatusCreated)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig := &tls.Config{
|
|
|
+ ServerName: "localhost",
|
|
|
+ InsecureSkipVerify: true, // use this for tests only
|
|
|
+ MinVersion: tls.VersionTLS12,
|
|
|
+ }
|
|
|
+ tlsCert, err := tls.X509KeyPair([]byte(client1Crt), []byte(client1Key))
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig.Certificates = append(tlsConfig.Certificates, tlsCert)
|
|
|
+ client := getWebDavClient(user, true, tlsConfig)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ // the user is now cached without a password, try a simple password login with and without TLS
|
|
|
+ client = getWebDavClient(user, true, nil)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ client = getWebDavClient(user, false, nil)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ // and now with a wrong password
|
|
|
+ user.Password = "wrong"
|
|
|
+ client = getWebDavClient(user, false, nil)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.Error(t, err)
|
|
|
+
|
|
|
+ // allow cert+password only
|
|
|
+ user.Password = ""
|
|
|
+ user.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodTLSCertificate}
|
|
|
+ user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ client = getWebDavClient(user, true, tlsConfig)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ // the user is now cached
|
|
|
+ client = getWebDavClient(user, true, tlsConfig)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ // password auth should work too
|
|
|
+ client = getWebDavClient(user, false, nil)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ client = getWebDavClient(user, true, nil)
|
|
|
+ err = checkBasicFunc(client)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ _, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.RemoveAll(user.GetHomeDir())
|
|
|
+ assert.NoError(t, err)
|
|
|
+}
|
|
|
+
|
|
|
+func TestExternatAuthWithClientCert(t *testing.T) {
|
|
|
+ if runtime.GOOS == osWindows {
|
|
|
+ t.Skip("this test is not available on Windows")
|
|
|
+ }
|
|
|
+ u := getTestUser()
|
|
|
+ u.Username = tlsClient1Username
|
|
|
+ u.Filters.TLSUsername = dataprovider.TLSUsernameCN
|
|
|
+ u.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodTLSCertificate, dataprovider.LoginMethodPassword}
|
|
|
+ err := dataprovider.Close()
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = config.LoadConfig(configDir, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ providerConf := config.GetProviderConf()
|
|
|
+ err = os.WriteFile(extAuthPath, getExtAuthScriptContent(u, false, ""), os.ModePerm)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ providerConf.ExternalAuthHook = extAuthPath
|
|
|
+ providerConf.ExternalAuthScope = 0
|
|
|
+ err = dataprovider.Initialize(providerConf, configDir, true)
|
|
|
+ assert.NoError(t, err)
|
|
|
+
|
|
|
+ tlsConfig := &tls.Config{
|
|
|
+ ServerName: "localhost",
|
|
|
+ InsecureSkipVerify: true, // use this for tests only
|
|
|
+ MinVersion: tls.VersionTLS12,
|
|
|
+ }
|
|
|
+ tlsCert, err := tls.X509KeyPair([]byte(client1Crt), []byte(client1Key))
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig.Certificates = append(tlsConfig.Certificates, tlsCert)
|
|
|
+ client := getWebDavClient(u, true, tlsConfig)
|
|
|
+ assert.NoError(t, checkBasicFunc(client))
|
|
|
+
|
|
|
+ resp, err := getTLSHTTPClient(tlsConfig).Get(fmt.Sprintf("https://%v:%v@%v/", tlsClient2Username, defaultPassword,
|
|
|
+ webDavTLSServerAddr))
|
|
|
+ if assert.NoError(t, err) {
|
|
|
+ defer resp.Body.Close()
|
|
|
+ body, err := io.ReadAll(resp.Body)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ assert.Equal(t, http.StatusUnauthorized, resp.StatusCode, string(body))
|
|
|
+ assert.Contains(t, string(body), "invalid credentials")
|
|
|
+ }
|
|
|
+
|
|
|
+ user, _, err := httpdtest.GetUserByUsername(tlsClient1Username, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ assert.Equal(t, tlsClient1Username, user.Username)
|
|
|
+ _, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.RemoveAll(user.GetHomeDir())
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = dataprovider.Close()
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = config.LoadConfig(configDir, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ providerConf = config.GetProviderConf()
|
|
|
+ err = dataprovider.Initialize(providerConf, configDir, true)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.Remove(extAuthPath)
|
|
|
+ assert.NoError(t, err)
|
|
|
+}
|
|
|
+
|
|
|
+func TestPreLoginHookWithClientCert(t *testing.T) {
|
|
|
+ if runtime.GOOS == osWindows {
|
|
|
+ t.Skip("this test is not available on Windows")
|
|
|
+ }
|
|
|
+ u := getTestUser()
|
|
|
+ u.Username = tlsClient1Username
|
|
|
+ u.Filters.TLSUsername = dataprovider.TLSUsernameCN
|
|
|
+ u.Filters.DeniedLoginMethods = []string{dataprovider.LoginMethodTLSCertificate, dataprovider.LoginMethodPassword}
|
|
|
+ err := dataprovider.Close()
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = config.LoadConfig(configDir, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ providerConf := config.GetProviderConf()
|
|
|
+ err = os.WriteFile(preLoginPath, getPreLoginScriptContent(u, false), os.ModePerm)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ providerConf.PreLoginHook = preLoginPath
|
|
|
+ err = dataprovider.Initialize(providerConf, configDir, true)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ _, _, err = httpdtest.GetUserByUsername(tlsClient1Username, http.StatusNotFound)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig := &tls.Config{
|
|
|
+ ServerName: "localhost",
|
|
|
+ InsecureSkipVerify: true, // use this for tests only
|
|
|
+ MinVersion: tls.VersionTLS12,
|
|
|
+ }
|
|
|
+ tlsCert, err := tls.X509KeyPair([]byte(client1Crt), []byte(client1Key))
|
|
|
+ assert.NoError(t, err)
|
|
|
+ tlsConfig.Certificates = append(tlsConfig.Certificates, tlsCert)
|
|
|
+ client := getWebDavClient(u, true, tlsConfig)
|
|
|
+ assert.NoError(t, checkBasicFunc(client))
|
|
|
+
|
|
|
+ user, _, err := httpdtest.GetUserByUsername(tlsClient1Username, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ // test login with an existing user
|
|
|
+ client = getWebDavClient(user, true, tlsConfig)
|
|
|
+ assert.NoError(t, checkBasicFunc(client))
|
|
|
+ err = os.WriteFile(preLoginPath, getPreLoginScriptContent(user, true), os.ModePerm)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ // update the user to remove it from the cache
|
|
|
+ user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ client = getWebDavClient(user, true, tlsConfig)
|
|
|
+ assert.Error(t, checkBasicFunc(client))
|
|
|
+ // update the user to remove it from the cache
|
|
|
+ user, _, err = httpdtest.UpdateUser(user, http.StatusOK, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ user.Status = 0
|
|
|
+ err = os.WriteFile(preLoginPath, getPreLoginScriptContent(user, false), os.ModePerm)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ client = getWebDavClient(user, true, tlsConfig)
|
|
|
+ assert.Error(t, checkBasicFunc(client))
|
|
|
+
|
|
|
+ _, err = httpdtest.RemoveUser(user, http.StatusOK)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.RemoveAll(user.GetHomeDir())
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = dataprovider.Close()
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = config.LoadConfig(configDir, "")
|
|
|
+ assert.NoError(t, err)
|
|
|
+ providerConf = config.GetProviderConf()
|
|
|
+ err = dataprovider.Initialize(providerConf, configDir, true)
|
|
|
+ assert.NoError(t, err)
|
|
|
+ err = os.Remove(preLoginPath)
|
|
|
+ assert.NoError(t, err)
|
|
|
+}
|
|
|
+
|
|
|
func checkBasicFunc(client *gowebdav.Client) error {
|
|
|
err := client.Connect()
|
|
|
if err != nil {
|
|
@@ -1557,14 +2059,39 @@ func downloadFile(remoteSourcePath string, localDestPath string, expectedSize in
|
|
|
return nil
|
|
|
}
|
|
|
|
|
|
-func getWebDavClient(user dataprovider.User) *gowebdav.Client {
|
|
|
+func getTLSHTTPClient(tlsConfig *tls.Config) *http.Client {
|
|
|
+ customTransport := http.DefaultTransport.(*http.Transport).Clone()
|
|
|
+ customTransport.TLSClientConfig = tlsConfig
|
|
|
+
|
|
|
+ return &http.Client{
|
|
|
+ Timeout: 5 * time.Second,
|
|
|
+ Transport: customTransport,
|
|
|
+ }
|
|
|
+}
|
|
|
+
|
|
|
+func getWebDavClient(user dataprovider.User, useTLS bool, tlsConfig *tls.Config) *gowebdav.Client {
|
|
|
rootPath := fmt.Sprintf("http://%v/", webDavServerAddr)
|
|
|
+ if useTLS {
|
|
|
+ rootPath = fmt.Sprintf("https://%v/", webDavTLSServerAddr)
|
|
|
+ if tlsConfig == nil {
|
|
|
+ tlsConfig = &tls.Config{
|
|
|
+ ServerName: "localhost",
|
|
|
+ InsecureSkipVerify: true, // use this for tests only
|
|
|
+ MinVersion: tls.VersionTLS12,
|
|
|
+ }
|
|
|
+ }
|
|
|
+ }
|
|
|
pwd := defaultPassword
|
|
|
if user.Password != "" {
|
|
|
pwd = user.Password
|
|
|
}
|
|
|
client := gowebdav.NewClient(rootPath, user.Username, pwd)
|
|
|
client.SetTimeout(5 * time.Second)
|
|
|
+ if tlsConfig != nil {
|
|
|
+ customTransport := http.DefaultTransport.(*http.Transport).Clone()
|
|
|
+ customTransport.TLSClientConfig = tlsConfig
|
|
|
+ client.SetTransport(customTransport)
|
|
|
+ }
|
|
|
return client
|
|
|
}
|
|
|
|