github.com/livekit/protocol@v1.39.3/auth/verifier_test.go (about)

     1  // Copyright 2023 LiveKit, Inc.
     2  //
     3  // Licensed under the Apache License, Version 2.0 (the "License");
     4  // you may not use this file except in compliance with the License.
     5  // You may obtain a copy of the License at
     6  //
     7  //     http://www.apache.org/licenses/LICENSE-2.0
     8  //
     9  // Unless required by applicable law or agreed to in writing, software
    10  // distributed under the License is distributed on an "AS IS" BASIS,
    11  // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    12  // See the License for the specific language governing permissions and
    13  // limitations under the License.
    14  
    15  package auth_test
    16  
    17  import (
    18  	"testing"
    19  	"time"
    20  
    21  	"github.com/go-jose/go-jose/v3/json"
    22  	"github.com/stretchr/testify/require"
    23  
    24  	"github.com/livekit/protocol/auth"
    25  )
    26  
    27  func TestVerifier(t *testing.T) {
    28  	apiKey := "APID3B67uxk4Nj2GKiRPibAZ9"
    29  	secret := "YHC-CUhbQhGeVCaYgn1BNA++"
    30  	accessToken := "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MDg5MzAzMDgsImlzcyI6IkFQSUQzQjY3dXhrNE5qMkdLaVJQaWJBWjkiLCJuYmYiOjE2MDg5MjY3MDgsInJvb21fam9pbiI6dHJ1ZSwicm9vbV9zaWQiOiJteWlkIiwic3ViIjoiQVBJRDNCNjd1eGs0TmoyR0tpUlBpYkFaOSJ9.cmHEBq0MLyRqphmVLM2cLXg5ao5Sro7am8yXhcYKcwE"
    31  	t.Run("cannot decode with incorrect key", func(t *testing.T) {
    32  		v, err := auth.ParseAPIToken(accessToken)
    33  		require.NoError(t, err)
    34  
    35  		require.Equal(t, apiKey, v.APIKey())
    36  		_, err = v.Verify("")
    37  		require.Error(t, err)
    38  
    39  		_, err = v.Verify("anothersecret")
    40  		require.Error(t, err)
    41  	})
    42  
    43  	t.Run("key has expired", func(t *testing.T) {
    44  		v, err := auth.ParseAPIToken(accessToken)
    45  		require.NoError(t, err)
    46  
    47  		_, err = v.Verify(secret)
    48  		require.Error(t, err)
    49  	})
    50  
    51  	t.Run("unexpired token is verified", func(t *testing.T) {
    52  		claim := auth.VideoGrant{RoomCreate: true}
    53  		at := auth.NewAccessToken(apiKey, secret).
    54  			SetVideoGrant(&claim).
    55  			SetValidFor(time.Minute).
    56  			SetIdentity("me")
    57  		authToken, err := at.ToJWT()
    58  		require.NoError(t, err)
    59  
    60  		v, err := auth.ParseAPIToken(authToken)
    61  		require.NoError(t, err)
    62  		require.Equal(t, apiKey, v.APIKey())
    63  		require.Equal(t, "me", v.Identity())
    64  
    65  		decoded, err := v.Verify(secret)
    66  		require.NoError(t, err)
    67  		require.Equal(t, &claim, decoded.Video)
    68  	})
    69  
    70  	t.Run("ensure metadata can be passed through", func(t *testing.T) {
    71  		metadata := map[string]interface{}{
    72  			"user":   "value",
    73  			"number": float64(3),
    74  		}
    75  		md, _ := json.Marshal(metadata)
    76  		attrs := map[string]string{"mykey": "myval", "secondkey": "secondval"}
    77  		at := auth.NewAccessToken(apiKey, secret).
    78  			SetVideoGrant(&auth.VideoGrant{
    79  				RoomAdmin: true,
    80  				Room:      "myroom",
    81  			}).
    82  			SetMetadata(string(md)).
    83  			SetAttributes(attrs)
    84  
    85  		authToken, err := at.ToJWT()
    86  		require.NoError(t, err)
    87  
    88  		v, err := auth.ParseAPIToken(authToken)
    89  		require.NoError(t, err)
    90  
    91  		decoded, err := v.Verify(secret)
    92  		require.NoError(t, err)
    93  
    94  		require.EqualValues(t, string(md), decoded.Metadata)
    95  		require.EqualValues(t, attrs, decoded.Attributes)
    96  	})
    97  
    98  	t.Run("nil permissions are handled", func(t *testing.T) {
    99  		grant := &auth.VideoGrant{
   100  			Room:     "myroom",
   101  			RoomJoin: true,
   102  		}
   103  		grant.SetCanPublishData(false)
   104  		at := auth.NewAccessToken(apiKey, secret).
   105  			SetVideoGrant(grant)
   106  		token, err := at.ToJWT()
   107  		require.NoError(t, err)
   108  
   109  		v, err := auth.ParseAPIToken(token)
   110  		require.NoError(t, err)
   111  		decoded, err := v.Verify(secret)
   112  		require.NoError(t, err)
   113  
   114  		require.Nil(t, decoded.Video.CanSubscribe)
   115  		require.Nil(t, decoded.Video.CanPublish)
   116  		require.False(t, *decoded.Video.CanPublishData)
   117  	})
   118  }