test(11-07): cover flare VAPID, allowlist, statuses and config

- TestVAPIDHeader (origin rules, exp, subject), TestVAPIDKeys,
  TestSendAllowlist (T-11-22 host table), TestSendStatuses (2xx, 404/410,
  StatusError without body, disabled, host-only transport errors),
  TestFlareConfig, TestAgo, TestEncryptRejects (coverage 90.0%)
This commit is contained in:
Jakub Zych
2026-09-30 14:22:44 +02:00
parent 33194a1f98
commit 6dadbf6957
2 changed files with 388 additions and 0 deletions

View File

@@ -4,6 +4,7 @@ import (
"bytes"
"crypto/ecdh"
"encoding/base64"
"errors"
"strings"
"testing"
)
@@ -110,3 +111,35 @@ func TestRFC8291AppendixA(t *testing.T) {
t.Fatalf("3993-byte payload: %v", err)
}
}
// TestEncryptRejects covers the RFC 8291 input checks: a payload over
// 3993 bytes, a p256dh that is not a 65-byte P-256 point, an auth secret
// that is not 16 bytes and non-base64url input are refused.
func TestEncryptRejects(t *testing.T) {
sub := newTestSubscriber(t, "https://fcm.googleapis.com/fcm/send/x").sub
if _, err := Encrypt(make([]byte, MaxPayloadSize+1), sub); !errors.Is(err, ErrPayloadTooLarge) {
t.Fatalf("oversized payload: %v", err)
}
if _, err := Encrypt(make([]byte, MaxPayloadSize), sub); err != nil {
t.Fatalf("payload at the limit: %v", err)
}
short := sub
short.P256dh = base64.RawURLEncoding.EncodeToString(make([]byte, 33))
offCurve := sub
offCurve.P256dh = base64.RawURLEncoding.EncodeToString(append([]byte{4}, make([]byte, 64)...))
badAuth := sub
badAuth.Auth = base64.RawURLEncoding.EncodeToString(make([]byte, 8))
notB64 := sub
notB64.Auth = "***"
for name, s := range map[string]Subscription{"short_key": short, "off_curve": offCurve, "short_auth": badAuth, "auth_not_base64": notB64} {
if _, err := Encrypt([]byte("x"), s); err == nil {
t.Errorf("%s accepted", name)
}
}
if b, err := decodeBase64URL("YWJj"); err != nil || string(b) != "abc" {
t.Fatalf("decode unpadded: %q %v", b, err)
}
if b, err := decodeBase64URL("YQ=="); err != nil || string(b) != "a" {
t.Fatalf("decode padded: %q %v", b, err)
}
}