fix(09): WR-11 reject ambiguous admin logins and cross-field login or email collisions
This commit is contained in:
@@ -553,3 +553,26 @@ func itoa(id uint) string {
|
||||
func adminAPI(rel string) string {
|
||||
return cabana.DefaultAdminPrefix + "/api/v1" + rel
|
||||
}
|
||||
|
||||
// TestLoginAmbiguousIdentifier pins WR-11: an identifier that is one admin's
|
||||
// login and another's email resolves to nobody (a plain 401), so neither admin
|
||||
// is silently locked out by the other; each can still sign in by the
|
||||
// unambiguous field.
|
||||
func TestLoginAmbiguousIdentifier(t *testing.T) {
|
||||
gdb := adminGorm(t)
|
||||
h := adminHandler(t, gdb, nil)
|
||||
insertAdmin(t, gdb, "ambig@amb.test", "owner-a@amb.test", "password-of-a", true, false)
|
||||
insertAdmin(t, gdb, "owner-b", "ambig@amb.test", "password-of-b", true, false)
|
||||
for _, password := range []string{"password-of-a", "password-of-b"} {
|
||||
rec := postJSON(t, h, adminAPI("/auth/login"), map[string]string{"login": "ambig@amb.test", "password": password})
|
||||
if rec.Code != http.StatusUnauthorized {
|
||||
t.Fatalf("ambiguous identifier with %q = %d %s, want 401", password, rec.Code, rec.Body.String())
|
||||
}
|
||||
}
|
||||
if rec := postJSON(t, h, adminAPI("/auth/login"), map[string]string{"login": "owner-a@amb.test", "password": "password-of-a"}); rec.Code != http.StatusOK {
|
||||
t.Fatalf("admin A by email = %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
if rec := postJSON(t, h, adminAPI("/auth/login"), map[string]string{"login": "owner-b", "password": "password-of-b"}); rec.Code != http.StatusOK {
|
||||
t.Fatalf("admin B by login = %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user