test(05-03): add failing tests for Encrypted, key:generate, Laravel decrypt

- Round-trip, fresh nonce, redaction, previous_keys fallback
- LoadAppKey rejects empty/short/undecodable keys
- key:generate prints 32-byte base64; DecryptLaravelPayload fixture
This commit is contained in:
Jakub Zych
2026-09-18 19:32:30 +02:00
parent a46c153480
commit 06bad37c24
3 changed files with 245 additions and 0 deletions

View File

@@ -0,0 +1,21 @@
package lagoon
import (
"bytes"
"testing"
)
// Fixture produced by PHP openssl_encrypt AES-256-CBC + HMAC-SHA256 over iv+value,
// matching Laravel's Encrypter payload (base64 JSON {iv,value,mac}) with serialize=false.
const laravelTestPayload = "eyJpdiI6IlNVbEpTVWxKU1VsSlNVbEpTVWxKU1E9PSIsInZhbHVlIjoiYVJ6ODYrRitUM25oVFNoR0o5WGMxbUJtSW5DeWdaVWN6WktYR3RFV3liZz0iLCJtYWMiOiI4YmI4NTRmZDk0ZmQ0NDYzNjk3ZDhmYmQ3M2QyNzFhYzI1MGI1YjFhNzk2ZDdiOWVjN2YyYmQ3YzJjOTk4MzBiIn0="
func TestEncryptedDecryptLaravelPayload(t *testing.T) {
key := bytes.Repeat([]byte("K"), 32)
got, err := DecryptLaravelPayload(laravelTestPayload, key)
if err != nil {
t.Fatal(err)
}
if string(got) != "sk-test-super-secret-api-key" {
t.Fatalf("decrypted = %q", got)
}
}