You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

45 lines
1.4 KiB

​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
​
  1. <?php
  2. namespace p3k\WebSub\Tests;
  3. use PHPUnit\Framework\TestCase;
  4. use PHPUnit\Framework\Attributes\DataProvider;
  5. use p3k\WebSub\Client;
  6. class VerifySignatureTest extends TestCase {
  7. public static function signatureAlgorithms() {
  8. return [['sha1'], ['sha256'], ['sha384'], ['sha512']];
  9. }
  10. /**
  11. * @dataProvider signatureAlgorithms
  12. */
  13. #[DataProvider('signatureAlgorithms')]
  14. public function testAcceptsValidSignature($alg) {
  15. $body = '{"hello":"world"}';
  16. $header = $alg.'='.hash_hmac($alg, $body, 's3cret');
  17. $this->assertTrue(Client::verify_signature($body, $header, 's3cret'));
  18. }
  19. public function testRejectsWrongSecret() {
  20. $body = '{"hello":"world"}';
  21. $header = 'sha256='.hash_hmac('sha256', $body, 's3cret');
  22. $this->assertFalse(Client::verify_signature($body, $header, 'wrong'));
  23. }
  24. public function testRejectsModifiedBody() {
  25. $header = 'sha256='.hash_hmac('sha256', 'original', 's3cret');
  26. $this->assertFalse(Client::verify_signature('modified', $header, 's3cret'));
  27. }
  28. public function testRejectsMissingOrMalformedHeader() {
  29. $this->assertFalse(Client::verify_signature('body', null, 's3cret'));
  30. $this->assertFalse(Client::verify_signature('body', '', 's3cret'));
  31. $this->assertFalse(Client::verify_signature('body', 'md5=abc', 's3cret'));
  32. $this->assertFalse(Client::verify_signature('body', ['sha256=abc'], 's3cret'));
  33. }
  34. }