summaryrefslogtreecommitdiff
path: root/pkg/test/auth_test.go
blob: 1741d68ca2fdb957bf7069f46c780a046ea68c00 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
package test

import (
	"testing"
	"fmt"
	"os"
)

func TestAuthHook(t *testing.T) {
	e := newEnv(t)
	defer e.Free()

	c := e.newInstance()

	var secrets string

	f, err := os.CreateTemp("", "test-auth-")
	if err != nil {
		e.Fatalf("create temp: %v", err)
	}

	secrets = f.Name()

	fmt.Fprintln(f, "T t")
	fmt.Fprintln(f, "X x")
	f.Close()

	defer os.Remove(secrets)

	c.Exec("add name T listen,addr=%%0 auth aes dial,addr=@[tunnel.X.listen]")
	c.Exec("add name X listen,addr=%%0 /aes /auth dial,addr=@[addr]")

	c.Exec("set authfile %s", secrets)
	c.Exec("set tunnel.T.authuser T")
	c.Exec("set tunnel.X.authuser X")

	listen := e.Listen("tcp", "127.0.0.1:0")
	c.Set("addr", listen.Addr())

	out := e.Dial("tcp", c.Get("tunnel.T.listen"))
	in := e.Accept(listen)

	e.Write(out, dummy)

	buf := make([]byte, len(dummy))
	e.ReadFull(in, buf)

	if r := string(buf); r != dummy {
		e.Fatalf("wrong reply: send '%s', recv '%s'", dummy, r)
	}
}

func TestAuthPassiveHook(t *testing.T) {
	e := newEnv(t)
	defer e.Free()

	c := e.newInstance()

	var secrets string

	f, err := os.CreateTemp("", "test-auth-passive-")
	if err != nil {
		e.Fatalf("create temp: %v", err)
	}

	secrets = f.Name()

	fmt.Fprintln(f, "T t")
	f.Close()

	defer os.Remove(secrets)

	c.Exec("add name T listen,addr=%%0 auth aes dial,addr=@[tunnel.X.listen]")
	c.Exec("add name X listen,addr=%%0 /aes /auth,passive dial,addr=@[addr]")

	c.Exec("set authfile %s", secrets)
	c.Exec("set tunnel.T.authuser T")

	listen := e.Listen("tcp", "127.0.0.1:0")
	c.Set("addr", listen.Addr())

	out := e.Dial("tcp", c.Get("tunnel.T.listen"))
	in := e.Accept(listen)

	e.Write(out, dummy)

	buf := make([]byte, len(dummy))
	e.ReadFull(in, buf)

	if r := string(buf); r != dummy {
		e.Fatalf("wrong reply: send '%s', recv '%s'", dummy, r)
	}
}