2016-07-30 16:26:49 -05:00
|
|
|
<?php
|
2019-10-05 10:26:10 -05:00
|
|
|
|
2017-10-12 03:13:20 -05:00
|
|
|
declare(strict_types=1);
|
|
|
|
|
2016-07-30 16:26:49 -05:00
|
|
|
namespace ShlinkioTest\Shlink\Rest\Middleware;
|
|
|
|
|
2018-09-28 15:08:01 -05:00
|
|
|
use Fig\Http\Message\RequestMethodInterface;
|
2020-01-01 14:11:53 -06:00
|
|
|
use Laminas\Diactoros\Response;
|
|
|
|
use Laminas\Diactoros\ServerRequest;
|
2020-11-07 05:53:14 -06:00
|
|
|
use Laminas\Diactoros\ServerRequestFactory;
|
2020-01-01 14:11:53 -06:00
|
|
|
use Mezzio\Router\Route;
|
|
|
|
use Mezzio\Router\RouteResult;
|
2023-02-09 13:42:18 -06:00
|
|
|
use PHPUnit\Framework\Attributes\DataProvider;
|
|
|
|
use PHPUnit\Framework\Attributes\Test;
|
2022-10-23 15:40:14 -05:00
|
|
|
use PHPUnit\Framework\MockObject\MockObject;
|
2017-03-24 14:34:18 -05:00
|
|
|
use PHPUnit\Framework\TestCase;
|
2018-09-28 15:08:01 -05:00
|
|
|
use Psr\Http\Message\ServerRequestInterface;
|
|
|
|
use Psr\Http\Server\MiddlewareInterface;
|
2018-03-26 12:02:41 -05:00
|
|
|
use Psr\Http\Server\RequestHandlerInterface;
|
2019-12-31 08:38:37 -06:00
|
|
|
use Shlinkio\Shlink\Rest\Action\HealthAction;
|
2020-11-08 04:28:27 -06:00
|
|
|
use Shlinkio\Shlink\Rest\Entity\ApiKey;
|
2020-11-07 05:53:14 -06:00
|
|
|
use Shlinkio\Shlink\Rest\Exception\MissingAuthenticationException;
|
|
|
|
use Shlinkio\Shlink\Rest\Exception\VerifyAuthenticationException;
|
2018-09-24 12:24:23 -05:00
|
|
|
use Shlinkio\Shlink\Rest\Middleware\AuthenticationMiddleware;
|
2020-11-08 04:28:27 -06:00
|
|
|
use Shlinkio\Shlink\Rest\Service\ApiKeyCheckResult;
|
2020-11-07 05:53:14 -06:00
|
|
|
use Shlinkio\Shlink\Rest\Service\ApiKeyServiceInterface;
|
2019-02-26 15:56:43 -06:00
|
|
|
|
2020-01-01 14:11:53 -06:00
|
|
|
use function Laminas\Stratigility\middleware;
|
2018-03-20 19:05:55 -05:00
|
|
|
|
2018-09-24 12:24:23 -05:00
|
|
|
class AuthenticationMiddlewareTest extends TestCase
|
2016-07-30 16:26:49 -05:00
|
|
|
{
|
2019-12-29 15:48:40 -06:00
|
|
|
private AuthenticationMiddleware $middleware;
|
2022-10-24 12:59:03 -05:00
|
|
|
private MockObject & ApiKeyServiceInterface $apiKeyService;
|
|
|
|
private MockObject & RequestHandlerInterface $handler;
|
2018-03-21 05:13:03 -05:00
|
|
|
|
2022-09-11 05:02:49 -05:00
|
|
|
protected function setUp(): void
|
2016-07-30 16:26:49 -05:00
|
|
|
{
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->apiKeyService = $this->createMock(ApiKeyServiceInterface::class);
|
2021-01-21 12:26:19 -06:00
|
|
|
$this->middleware = new AuthenticationMiddleware(
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->apiKeyService,
|
2021-01-21 12:26:19 -06:00
|
|
|
[HealthAction::class],
|
|
|
|
['with_query_api_key'],
|
|
|
|
);
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->handler = $this->createMock(RequestHandlerInterface::class);
|
2016-07-30 16:26:49 -05:00
|
|
|
}
|
|
|
|
|
2023-02-09 13:42:18 -06:00
|
|
|
#[Test, DataProvider('provideRequestsWithoutAuth')]
|
2021-02-16 08:28:03 -06:00
|
|
|
public function someSituationsFallbackToNextMiddleware(ServerRequestInterface $request): void
|
2016-07-30 16:26:49 -05:00
|
|
|
{
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->handler->expects($this->once())->method('handle')->with($request)->willReturn(new Response());
|
|
|
|
$this->apiKeyService->expects($this->never())->method('check');
|
2016-07-30 16:26:49 -05:00
|
|
|
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->middleware->process($request, $this->handler);
|
2016-07-30 16:26:49 -05:00
|
|
|
}
|
2016-07-31 06:01:08 -05:00
|
|
|
|
2023-02-09 02:32:38 -06:00
|
|
|
public static function provideRequestsWithoutAuth(): iterable
|
2016-07-31 06:01:08 -05:00
|
|
|
{
|
2023-02-09 02:32:38 -06:00
|
|
|
$dummyMiddleware = self::getDummyMiddleware();
|
2018-09-28 15:08:01 -05:00
|
|
|
|
2021-02-16 08:28:03 -06:00
|
|
|
yield 'no route result' => [new ServerRequest()];
|
|
|
|
yield 'failure route result' => [(new ServerRequest())->withAttribute(
|
2019-02-17 13:28:34 -06:00
|
|
|
RouteResult::class,
|
2020-01-01 13:48:31 -06:00
|
|
|
RouteResult::fromRouteFailure([RequestMethodInterface::METHOD_GET]),
|
2019-02-17 13:28:34 -06:00
|
|
|
)];
|
2021-02-16 08:28:03 -06:00
|
|
|
yield 'route without API key required' => [(new ServerRequest())->withAttribute(
|
2019-02-17 13:28:34 -06:00
|
|
|
RouteResult::class,
|
|
|
|
RouteResult::fromRoute(
|
2020-01-01 13:48:31 -06:00
|
|
|
new Route('foo', $dummyMiddleware, Route::HTTP_METHOD_ANY, HealthAction::class),
|
|
|
|
),
|
2019-02-17 13:28:34 -06:00
|
|
|
)];
|
2021-02-16 08:28:03 -06:00
|
|
|
yield 'OPTIONS method' => [(new ServerRequest())->withAttribute(
|
2019-02-17 13:28:34 -06:00
|
|
|
RouteResult::class,
|
2020-01-01 13:48:31 -06:00
|
|
|
RouteResult::fromRoute(new Route('bar', $dummyMiddleware), []),
|
2019-02-17 13:28:34 -06:00
|
|
|
)->withMethod(RequestMethodInterface::METHOD_OPTIONS)];
|
2016-07-31 06:01:08 -05:00
|
|
|
}
|
|
|
|
|
2023-02-09 13:42:18 -06:00
|
|
|
#[Test, DataProvider('provideRequestsWithoutApiKey')]
|
2021-01-21 12:26:19 -06:00
|
|
|
public function throwsExceptionWhenNoApiKeyIsProvided(
|
|
|
|
ServerRequestInterface $request,
|
2021-05-23 05:31:10 -05:00
|
|
|
string $expectedMessage,
|
2021-01-21 12:26:19 -06:00
|
|
|
): void {
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->apiKeyService->expects($this->never())->method('check');
|
|
|
|
$this->handler->expects($this->never())->method('handle');
|
2020-11-07 05:53:14 -06:00
|
|
|
$this->expectException(MissingAuthenticationException::class);
|
2021-01-21 12:26:19 -06:00
|
|
|
$this->expectExceptionMessage($expectedMessage);
|
2020-11-07 05:53:14 -06:00
|
|
|
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->middleware->process($request, $this->handler);
|
2020-11-07 05:53:14 -06:00
|
|
|
}
|
|
|
|
|
2023-02-09 02:32:38 -06:00
|
|
|
public static function provideRequestsWithoutApiKey(): iterable
|
2016-07-31 06:01:08 -05:00
|
|
|
{
|
2021-01-21 12:26:19 -06:00
|
|
|
$baseRequest = fn (string $routeName) => ServerRequestFactory::fromGlobals()->withAttribute(
|
2016-07-31 06:01:08 -05:00
|
|
|
RouteResult::class,
|
2023-02-09 02:32:38 -06:00
|
|
|
RouteResult::fromRoute(new Route($routeName, self::getDummyMiddleware())), // @phpstan-ignore-line
|
2018-09-29 01:16:40 -05:00
|
|
|
);
|
2021-01-21 12:26:19 -06:00
|
|
|
$apiKeyMessage = 'Expected one of the following authentication headers, ["X-Api-Key"], but none were provided';
|
|
|
|
$queryMessage = 'Expected authentication to be provided in "apiKey" query param';
|
|
|
|
|
|
|
|
yield 'no api key in header' => [$baseRequest('bar'), $apiKeyMessage];
|
|
|
|
yield 'empty api key in header' => [$baseRequest('bar')->withHeader('X-Api-Key', ''), $apiKeyMessage];
|
|
|
|
yield 'no api key in query' => [$baseRequest('with_query_api_key'), $queryMessage];
|
|
|
|
yield 'empty api key in query' => [
|
|
|
|
$baseRequest('with_query_api_key')->withQueryParams(['apiKey' => '']),
|
|
|
|
$queryMessage,
|
|
|
|
];
|
2020-11-07 05:53:14 -06:00
|
|
|
}
|
|
|
|
|
2023-02-09 13:42:18 -06:00
|
|
|
#[Test]
|
2020-11-07 05:53:14 -06:00
|
|
|
public function throwsExceptionWhenProvidedApiKeyIsInvalid(): void
|
|
|
|
{
|
|
|
|
$apiKey = 'abc123';
|
|
|
|
$request = ServerRequestFactory::fromGlobals()
|
|
|
|
->withAttribute(
|
|
|
|
RouteResult::class,
|
2023-02-09 02:32:38 -06:00
|
|
|
RouteResult::fromRoute(new Route('bar', self::getDummyMiddleware()), []),
|
2020-11-07 05:53:14 -06:00
|
|
|
)
|
|
|
|
->withHeader('X-Api-Key', $apiKey);
|
|
|
|
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->apiKeyService->expects($this->once())->method('check')->with($apiKey)->willReturn(
|
|
|
|
new ApiKeyCheckResult(),
|
|
|
|
);
|
|
|
|
$this->handler->expects($this->never())->method('handle');
|
2020-11-07 05:53:14 -06:00
|
|
|
$this->expectException(VerifyAuthenticationException::class);
|
|
|
|
$this->expectExceptionMessage('Provided API key does not exist or is invalid');
|
|
|
|
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->middleware->process($request, $this->handler);
|
2020-11-07 05:53:14 -06:00
|
|
|
}
|
|
|
|
|
2023-02-09 13:42:18 -06:00
|
|
|
#[Test]
|
2020-11-07 05:53:14 -06:00
|
|
|
public function validApiKeyFallsBackToNextMiddleware(): void
|
|
|
|
{
|
2021-03-14 03:59:35 -05:00
|
|
|
$apiKey = ApiKey::create();
|
2020-11-08 04:28:27 -06:00
|
|
|
$key = $apiKey->toString();
|
2020-11-07 05:53:14 -06:00
|
|
|
$request = ServerRequestFactory::fromGlobals()
|
|
|
|
->withAttribute(
|
|
|
|
RouteResult::class,
|
2023-02-09 02:32:38 -06:00
|
|
|
RouteResult::fromRoute(new Route('bar', self::getDummyMiddleware()), []),
|
2020-11-07 05:53:14 -06:00
|
|
|
)
|
2020-11-08 04:28:27 -06:00
|
|
|
->withHeader('X-Api-Key', $key);
|
2020-11-07 05:53:14 -06:00
|
|
|
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->handler->expects($this->once())->method('handle')->with(
|
|
|
|
$request->withAttribute(ApiKey::class, $apiKey),
|
|
|
|
)->willReturn(new Response());
|
|
|
|
$this->apiKeyService->expects($this->once())->method('check')->with($key)->willReturn(
|
|
|
|
new ApiKeyCheckResult($apiKey),
|
|
|
|
);
|
2018-09-28 15:08:01 -05:00
|
|
|
|
2022-10-23 15:40:14 -05:00
|
|
|
$this->middleware->process($request, $this->handler);
|
2016-07-31 06:01:08 -05:00
|
|
|
}
|
|
|
|
|
2023-02-09 02:32:38 -06:00
|
|
|
private static function getDummyMiddleware(): MiddlewareInterface
|
2016-07-31 06:01:08 -05:00
|
|
|
{
|
2019-12-29 16:16:55 -06:00
|
|
|
return middleware(fn () => new Response\EmptyResponse());
|
2016-07-31 06:01:08 -05:00
|
|
|
}
|
2016-07-30 16:26:49 -05:00
|
|
|
}
|