2021-10-16 10:16:24 +02:00
|
|
|
import * as assert from 'assert';
|
2022-11-24 07:39:00 +01:00
|
|
|
import httpSignature from '@peertube/http-signature';
|
2022-09-17 20:27:08 +02:00
|
|
|
import { genRsaKeyPair } from '../../src/misc/gen-key-pair.js';
|
2022-12-04 02:16:03 +01:00
|
|
|
import { createSignedPost, createSignedGet } from '../../src/activitypub/ap-request.js';
|
2021-10-16 10:16:24 +02:00
|
|
|
|
|
|
|
export const buildParsedSignature = (signingString: string, signature: string, algorithm: string) => {
|
|
|
|
return {
|
|
|
|
scheme: 'Signature',
|
|
|
|
params: {
|
|
|
|
keyId: 'KeyID', // dummy, not used for verify
|
|
|
|
algorithm: algorithm,
|
|
|
|
headers: [ '(request-target)', 'date', 'host', 'digest' ], // dummy, not used for verify
|
|
|
|
signature: signature,
|
|
|
|
},
|
|
|
|
signingString: signingString,
|
2022-05-21 15:21:41 +02:00
|
|
|
algorithm: algorithm.toUpperCase(),
|
2021-10-16 10:16:24 +02:00
|
|
|
keyId: 'KeyID', // dummy, not used for verify
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
describe('ap-request', () => {
|
2023-02-02 10:18:25 +01:00
|
|
|
test('createSignedPost with verify', async () => {
|
2021-10-16 10:16:24 +02:00
|
|
|
const keypair = await genRsaKeyPair();
|
|
|
|
const key = { keyId: 'x', 'privateKeyPem': keypair.privateKey };
|
|
|
|
const url = 'https://example.com/inbox';
|
|
|
|
const activity = { a: 1 };
|
|
|
|
const body = JSON.stringify(activity);
|
|
|
|
const headers = {
|
2022-05-21 15:21:41 +02:00
|
|
|
'User-Agent': 'UA',
|
2021-10-16 10:16:24 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
const req = createSignedPost({ key, url, body, additionalHeaders: headers });
|
|
|
|
|
|
|
|
const parsed = buildParsedSignature(req.signingString, req.signature, 'rsa-sha256');
|
|
|
|
|
|
|
|
const result = httpSignature.verifySignature(parsed, keypair.publicKey);
|
|
|
|
assert.deepStrictEqual(result, true);
|
|
|
|
});
|
|
|
|
|
2023-02-02 10:18:25 +01:00
|
|
|
test('createSignedGet with verify', async () => {
|
2021-10-16 10:16:24 +02:00
|
|
|
const keypair = await genRsaKeyPair();
|
|
|
|
const key = { keyId: 'x', 'privateKeyPem': keypair.privateKey };
|
|
|
|
const url = 'https://example.com/outbox';
|
|
|
|
const headers = {
|
2022-05-21 15:21:41 +02:00
|
|
|
'User-Agent': 'UA',
|
2021-10-16 10:16:24 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
const req = createSignedGet({ key, url, additionalHeaders: headers });
|
|
|
|
|
|
|
|
const parsed = buildParsedSignature(req.signingString, req.signature, 'rsa-sha256');
|
|
|
|
|
|
|
|
const result = httpSignature.verifySignature(parsed, keypair.publicKey);
|
|
|
|
assert.deepStrictEqual(result, true);
|
|
|
|
});
|
|
|
|
});
|