github.com/livekit/protocol@v1.16.1-0.20240517185851-47e4c6bba773/auth/verifier_test.go (about)

     1  // Copyright 2023 LiveKit, Inc.
     2  //
     3  // Licensed under the Apache License, Version 2.0 (the "License");
     4  // you may not use this file except in compliance with the License.
     5  // You may obtain a copy of the License at
     6  //
     7  //     http://www.apache.org/licenses/LICENSE-2.0
     8  //
     9  // Unless required by applicable law or agreed to in writing, software
    10  // distributed under the License is distributed on an "AS IS" BASIS,
    11  // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    12  // See the License for the specific language governing permissions and
    13  // limitations under the License.
    14  
    15  package auth_test
    16  
    17  import (
    18  	"testing"
    19  	"time"
    20  
    21  	"github.com/go-jose/go-jose/v3/json"
    22  	"github.com/stretchr/testify/require"
    23  
    24  	"github.com/livekit/protocol/auth"
    25  )
    26  
    27  func TestVerifier(t *testing.T) {
    28  	apiKey := "APID3B67uxk4Nj2GKiRPibAZ9"
    29  	secret := "YHC-CUhbQhGeVCaYgn1BNA++"
    30  	accessToken := "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MDg5MzAzMDgsImlzcyI6IkFQSUQzQjY3dXhrNE5qMkdLaVJQaWJBWjkiLCJuYmYiOjE2MDg5MjY3MDgsInJvb21fam9pbiI6dHJ1ZSwicm9vbV9zaWQiOiJteWlkIiwic3ViIjoiQVBJRDNCNjd1eGs0TmoyR0tpUlBpYkFaOSJ9.cmHEBq0MLyRqphmVLM2cLXg5ao5Sro7am8yXhcYKcwE"
    31  	t.Run("cannot decode with incorrect key", func(t *testing.T) {
    32  		v, err := auth.ParseAPIToken(accessToken)
    33  		require.NoError(t, err)
    34  
    35  		require.Equal(t, apiKey, v.APIKey())
    36  		_, err = v.Verify("")
    37  		require.Error(t, err)
    38  
    39  		_, err = v.Verify("anothersecret")
    40  		require.Error(t, err)
    41  	})
    42  
    43  	t.Run("key has expired", func(t *testing.T) {
    44  		v, err := auth.ParseAPIToken(accessToken)
    45  		require.NoError(t, err)
    46  
    47  		_, err = v.Verify(secret)
    48  		require.Error(t, err)
    49  	})
    50  
    51  	t.Run("unexpired token is verified", func(t *testing.T) {
    52  		claim := auth.VideoGrant{RoomCreate: true}
    53  		at := auth.NewAccessToken(apiKey, secret).
    54  			AddGrant(&claim).
    55  			SetValidFor(time.Minute).
    56  			SetIdentity("me")
    57  		authToken, err := at.ToJWT()
    58  		require.NoError(t, err)
    59  
    60  		v, err := auth.ParseAPIToken(authToken)
    61  		require.NoError(t, err)
    62  		require.Equal(t, apiKey, v.APIKey())
    63  		require.Equal(t, "me", v.Identity())
    64  
    65  		decoded, err := v.Verify(secret)
    66  		require.NoError(t, err)
    67  		require.Equal(t, &claim, decoded.Video)
    68  	})
    69  
    70  	t.Run("ensure metadata can be passed through", func(t *testing.T) {
    71  		metadata := map[string]interface{}{
    72  			"user":   "value",
    73  			"number": float64(3),
    74  		}
    75  		md, _ := json.Marshal(metadata)
    76  		at := auth.NewAccessToken(apiKey, secret).
    77  			AddGrant(&auth.VideoGrant{
    78  				RoomAdmin: true,
    79  				Room:      "myroom",
    80  			}).
    81  			SetMetadata(string(md))
    82  
    83  		authToken, err := at.ToJWT()
    84  		require.NoError(t, err)
    85  
    86  		v, err := auth.ParseAPIToken(authToken)
    87  		require.NoError(t, err)
    88  
    89  		decoded, err := v.Verify(secret)
    90  		require.NoError(t, err)
    91  
    92  		require.EqualValues(t, string(md), decoded.Metadata)
    93  	})
    94  
    95  	t.Run("nil permissions are handled", func(t *testing.T) {
    96  		grant := &auth.VideoGrant{
    97  			Room:     "myroom",
    98  			RoomJoin: true,
    99  		}
   100  		grant.SetCanPublishData(false)
   101  		at := auth.NewAccessToken(apiKey, secret).
   102  			AddGrant(grant)
   103  		token, err := at.ToJWT()
   104  		require.NoError(t, err)
   105  
   106  		v, err := auth.ParseAPIToken(token)
   107  		require.NoError(t, err)
   108  		decoded, err := v.Verify(secret)
   109  		require.NoError(t, err)
   110  
   111  		require.Nil(t, decoded.Video.CanSubscribe)
   112  		require.Nil(t, decoded.Video.CanPublish)
   113  		require.False(t, *decoded.Video.CanPublishData)
   114  	})
   115  }