-
Notifications
You must be signed in to change notification settings - Fork 323
/
Copy pathpassport.spec.js
168 lines (132 loc) · 5.07 KB
/
passport.spec.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
'use strict'
const { assert } = require('chai')
const agent = require('../../dd-trace/test/plugins/agent')
const axios = require('axios').create({ validateStatus: null })
const dc = require('dc-polyfill')
const { storage } = require('../../datadog-core')
const users = [
{
id: 'error_user',
username: 'error',
password: '1234',
email: 'a@b.c'
}, {
id: 'notfound_user',
username: 'notfound',
password: '1234',
email: 'a@b.c'
}, {
id: 'uuid_42',
username: 'test',
password: '1234',
email: 'testuser@ddog.com'
}
]
withVersions('passport', 'passport', version => {
describe('passport instrumentation', () => {
const passportDeserializeUserChannel = dc.channel('datadog:passport:deserializeUser:finish')
let port, server, subscriberStub
before(() => {
return agent.load(['http'], { client: false })
})
before((done) => {
const express = require('../../../versions/express').get()
const expressSession = require('../../../versions/express-session').get()
const passport = require(`../../../versions/passport@${version}`).get()
const LocalStrategy = require('../../../versions/passport-local').get().Strategy
const app = express()
app.use(expressSession({
secret: 'secret',
resave: false,
rolling: true,
saveUninitialized: true
}))
app.use(passport.initialize())
app.use(passport.session())
passport.serializeUser((user, done) => {
done(null, user.id)
})
passport.deserializeUser((id, done) => {
if (id === 'error_user') {
return done('*MOCK* Cannot deserialize user')
}
if (id === 'notfound_user') {
return done(null, false)
}
const user = users.find((user) => user.id === id)
done(null, user)
})
passport.use(new LocalStrategy((username, password, done) => {
const user = users.find((user) => user.username === username && user.password === password)
return done(null, user)
}))
app.get('/login', passport.authenticate('local'))
app.get('/', (req, res) => {
res.send(req.user?.id)
})
server = app.listen(0, () => {
port = server.address().port
done()
})
})
beforeEach(() => {
subscriberStub = sinon.stub()
passportDeserializeUserChannel.subscribe(subscriberStub)
})
afterEach(() => {
passportDeserializeUserChannel.unsubscribe(subscriberStub)
})
after(() => {
server.close()
return agent.close({ ritmReset: false })
})
it('should not call subscriber when an error occurs', async () => {
const login = await axios.get(`http://localhost:${port}/login?username=error&password=1234`)
const cookie = login.headers['set-cookie'][0]
const res = await axios.get(`http://localhost:${port}/`, { headers: { cookie } })
assert.strictEqual(res.status, 500)
assert.include(res.data, '*MOCK* Cannot deserialize user')
sinon.assert.notCalled(subscriberStub)
})
it('should not call subscriber when no user is found', async () => {
const login = await axios.get(`http://localhost:${port}/login?username=notfound&password=1234`)
const cookie = login.headers['set-cookie'][0]
const res = await axios.get(`http://localhost:${port}/`, { headers: { cookie } })
assert.strictEqual(res.status, 200)
assert.strictEqual(res.data, '')
sinon.assert.notCalled(subscriberStub)
})
it('should call subscriber with proper arguments on user deserialize', async () => {
const login = await axios.get(`http://localhost:${port}/login?username=test&password=1234`)
const cookie = login.headers['set-cookie'][0]
const res = await axios.get(`http://localhost:${port}/`, { headers: { cookie } })
assert.strictEqual(res.status, 200)
assert.strictEqual(res.data, 'uuid_42')
sinon.assert.calledOnce(subscriberStub)
sinon.assert.calledWith(subscriberStub, {
user: { id: 'uuid_42', username: 'test', password: '1234', email: 'testuser@ddog.com' },
abortController: new AbortController()
})
})
it('should block when subscriber aborts', async () => {
const login = await axios.get(`http://localhost:${port}/login?username=test&password=1234`)
const cookie = login.headers['set-cookie'][0]
subscriberStub.callsFake(({ abortController }) => {
const res = storage('legacy').getStore().req.res
res.writeHead(403)
res.constructor.prototype.end.call(res, 'Blocked')
abortController.abort()
})
const res = await axios.get(`http://localhost:${port}/`, { headers: { cookie } })
const abortController = new AbortController()
abortController.abort()
assert.strictEqual(res.status, 403)
assert.strictEqual(res.data, 'Blocked')
sinon.assert.calledOnce(subscriberStub)
sinon.assert.calledWith(subscriberStub, {
user: { id: 'uuid_42', username: 'test', password: '1234', email: 'testuser@ddog.com' },
abortController
})
})
})
})