Documentation
¶
Index ¶
- Constants
- Variables
- func CreateSessionUsingPassword(t *testing.T, authAttempts service.AuthAttemptService, ...) (*domain.Session, error)
- func MustMarshal(t *testing.T, v any) string
- func MustUnmarshal[T any](t *testing.T, bs []byte) *T
- func OIDCConnection(slug string) api.IdpConnection
- func ProjectName() string
- func RandString(n int) string
- func TeamName() string
- type ApiClient
- type FakeSecuritySource
- type Harness
- func (h *Harness) CleanupProject(t *testing.T, projectID string)
- func (h *Harness) CreateActiveSession(t *testing.T, projectID, userID string) *domain.Session
- func (h *Harness) CreateSession(t *testing.T, projectID string, ttl time.Duration) *domain.Session
- func (h *Harness) CreateUserOwnedByTeam(t *testing.T, projectID string) (userID, teamID string)
- func (h *Harness) CreateUserSchema(t *testing.T, project *domain.Project, schema string) string
- func (h *Harness) CreateUserWithTeam(t *testing.T, projectID string) string
- func (h *Harness) EnsureAuthAttemptService(t *testing.T) service.AuthAttemptService
- func (h *Harness) EnsureBrandingService(t *testing.T) *service.BrandingService
- func (h *Harness) EnsureCreateUserHandler(t *testing.T) *service.FlowCreateUserWithPasswordHandler
- func (h *Harness) EnsureDeploymentService(t *testing.T) *service.DeploymentService
- func (h *Harness) EnsureEnvironmentService(t *testing.T) *service.EnvironmentService
- func (h *Harness) EnsureEventService(t *testing.T) *service.EventService
- func (h *Harness) EnsureFlowDefinitionService(t *testing.T) service.FlowDefinitionService
- func (h *Harness) EnsureFlowService(t *testing.T) service.FlowService
- func (h *Harness) EnsureFlowStateMachine(t *testing.T) *domain.FlowStateMachineRuntime
- func (h *Harness) EnsureGeneratedServer(t *testing.T) *generated.Server
- func (h *Harness) EnsureHandler(t *testing.T) *api.Handler
- func (h *Harness) EnsureHashValidator(t *testing.T) crypto.HashValidator
- func (h *Harness) EnsureHashVerifier(t *testing.T) crypto.HashVerifier
- func (h *Harness) EnsureHasher(t *testing.T) crypto.Hasher
- func (h *Harness) EnsureHasherFactory(t *testing.T) *crypto.HasherFactory
- func (h *Harness) EnsureHttpClient(t *testing.T) *http.Client
- func (h *Harness) EnsureIDPConnectionService(t *testing.T) service.IDPConnectionService
- func (h *Harness) EnsureJoseSigner(t *testing.T) jose.Signer
- func (h *Harness) EnsureKeyService(t *testing.T) service.KeyService
- func (h *Harness) EnsureMasterKey(t *testing.T) *domain.MasterKeys
- func (h *Harness) EnsurePlatformProject(t *testing.T) *domain.Project
- func (h *Harness) EnsureProjectHashers(t *testing.T) service.ProjectHasherResolver
- func (h *Harness) EnsureProjectService(t *testing.T) service.ProjectService
- func (h *Harness) EnsureReleaseService(t *testing.T) service.ReleaseService
- func (h *Harness) EnsureSchemaResolver(t *testing.T) *domain.JSONSchemaResolver
- func (h *Harness) EnsureSchemaService(t *testing.T) *service.SchemaService
- func (h *Harness) EnsureSchemaStore(t *testing.T) domain.JSONSchemaStore
- func (h *Harness) EnsureSchemaValidator(t *testing.T) *domain.SchemaValidator
- func (h *Harness) EnsureSecretGenerator(t *testing.T) secrets.Generator
- func (h *Harness) EnsureSecurityHandler(t *testing.T) *api.SecurityHandler
- func (h *Harness) EnsureServiceDB(t *testing.T) *service.DB
- func (h *Harness) EnsureSessionService(t *testing.T) service.SessionService
- func (h *Harness) EnsureSigningKey(t *testing.T) *rsa.PrivateKey
- func (h *Harness) EnsureTeamMembershipFixture(t *testing.T) TeamMembershipFixture
- func (h *Harness) EnsureTeamService(t *testing.T) *service.TeamService
- func (h *Harness) EnsureTestData(t *testing.T) *test_data.TestData
- func (h *Harness) EnsureTestServer(t *testing.T) *httptest.Server
- func (h *Harness) EnsureTokenService(t *testing.T) service.TokenService
- func (h *Harness) EnsureUserFixture(t *testing.T) UserFixture
- func (h *Harness) EnsureUserPasskeyFixture(t *testing.T) UserPasskeyFixture
- func (h *Harness) EnsureUserService(t *testing.T) service.UserService
- func (h *Harness) ProjectSecret(t *testing.T, project *domain.Project) string
- func (h *Harness) RegisterPasskey(t *testing.T, projectID, userID, passkeyName string)
- func (h *Harness) SeedOwningTeam(t *testing.T, projectID, teamID string)
- func (h *Harness) SeedProjectAdmin(t *testing.T, projectID, userID string) *domain.AuthzAssignment
- func (h *Harness) SeedProjectEditor(t *testing.T, projectID, userID string) *domain.AuthzAssignment
- func (h *Harness) SeedProjectViewer(t *testing.T, projectID, userID string) *domain.AuthzAssignment
- func (h *Harness) SetPreviewSecretOnApiClient(t *testing.T, client *ApiClient, project *domain.Project)
- func (h *Harness) SetProjectSecretOnApiClient(t *testing.T, client *ApiClient, project *domain.Project)
- func (h *Harness) SetScopedTokenOnApiClient(t *testing.T, client *ApiClient, project *domain.Project, scopes ...string)
- type TeamMembershipFixture
- type UserFixture
- func (f UserFixture) Create(ctx context.Context, user *domain.CreateUser) error
- func (f UserFixture) GetByAttributes(ctx context.Context, projectID string, attrs []domain.Attribute) (*domain.User, error)
- func (f UserFixture) GetByID(ctx context.Context, projectID, userID string) (*domain.User, error)
- func (f UserFixture) GetPasswordByUserID(ctx context.Context, projectID, userID string) (*domain.UserPassword, error)
- func (f UserFixture) SetPassword(ctx context.Context, pw *domain.SetUserPassword) error
- type UserPasskeyFixture
Constants ¶
const BuiltinSchemaBaseURL = "https://test.example.schemas.com/schemas"
Variables ¶
var PasskeyRelyingParty = virtualwebauthn.RelyingParty{
ID: "example.com",
Name: "example.com",
Origin: "https://example.com",
}
PasskeyRelyingParty is the relying party Harness.RegisterPasskey registers against. Tests that drive the ceremony themselves should use the same values, so the attestation origin matches what the issued challenge was given.
Functions ¶
func OIDCConnection ¶
func OIDCConnection(slug string) api.IdpConnection
OIDCConnection is a minimal valid OIDC connection document. Tests change the fields they are about on the returned value.
func ProjectName ¶
func ProjectName() string
ProjectName returns a unique project name for integration tests.
func RandString ¶
Types ¶
type FakeSecuritySource ¶
func (FakeSecuritySource) NextgenSession ¶
func (f FakeSecuritySource) NextgenSession(ctx context.Context, operationName api.OperationName) (api.NextgenSession, error)
NextgenSession provides the __nextgen_session cookie. With an empty SessionToken the scheme is skipped and the generated client fails fast with "security requirement is not satisfied" instead of sending the request — to exercise the server's missing-credential path, send a raw HTTP request (see TestGetMyUser/missing_session_cookie).
func (FakeSecuritySource) OAuth2 ¶
func (f FakeSecuritySource) OAuth2(ctx context.Context, operationName api.OperationName) (api.OAuth2, error)
type Harness ¶
func (*Harness) CleanupProject ¶
CleanupProject deletes projectID when t ends. Use it for a project the test created through the API rather than through Harness.EnsureProjectService: the handler holds the unwrapped service, so that project is the test's to remove.
func (*Harness) CreateActiveSession ¶
CreateActiveSession exchanges a handed-off attempt with a verified user factor, binding the user to the new session. The user must exist: sessions.user_id references users.
A handoff is valid for one minute, and the Spanner emulator can queue the exchange past it. Only on that answer the helper seeds a fresh attempt, up to three times; a handoff that is actually broken still fails the test. TestClaimHappyPath and the session exchange tests exchange exactly once.
func (*Harness) CreateSession ¶
CreateSession seeds a session directly in storage. No user is bound, so it reads as building until the TTL elapses. The database clock stamps expires_at while the state filter compares it against the service clock, so a test that needs the session expired must wait until that is observable rather than assume a tiny TTL has already elapsed.
func (*Harness) CreateUserOwnedByTeam ¶
CreateUserOwnedByTeam seeds a builtin-schema user whose lifecycle a team of its own owns (ADR 024) and returns both ids. Ownership is what the session team filter reads, so this is the shape that filter's tests need; roster membership alone is Harness.CreateUserWithTeam.
func (*Harness) CreateUserSchema ¶
func (*Harness) CreateUserWithTeam ¶
CreateUserWithTeam seeds a builtin-schema user on the roster of a team of its own and returns its id. The user stays self-owned — see Harness.CreateUserOwnedByTeam for the team-owned shape. The id and email are randomized, so repeated calls in one project stay unique.
func (*Harness) EnsureAuthAttemptService ¶
func (h *Harness) EnsureAuthAttemptService(t *testing.T) service.AuthAttemptService
func (*Harness) EnsureBrandingService ¶
func (h *Harness) EnsureBrandingService(t *testing.T) *service.BrandingService
func (*Harness) EnsureCreateUserHandler ¶
func (h *Harness) EnsureCreateUserHandler(t *testing.T) *service.FlowCreateUserWithPasswordHandler
func (*Harness) EnsureDeploymentService ¶
func (h *Harness) EnsureDeploymentService(t *testing.T) *service.DeploymentService
func (*Harness) EnsureEnvironmentService ¶
func (h *Harness) EnsureEnvironmentService(t *testing.T) *service.EnvironmentService
func (*Harness) EnsureEventService ¶
func (h *Harness) EnsureEventService(t *testing.T) *service.EventService
func (*Harness) EnsureFlowDefinitionService ¶
func (h *Harness) EnsureFlowDefinitionService(t *testing.T) service.FlowDefinitionService
func (*Harness) EnsureFlowService ¶
func (h *Harness) EnsureFlowService(t *testing.T) service.FlowService
func (*Harness) EnsureFlowStateMachine ¶
func (h *Harness) EnsureFlowStateMachine(t *testing.T) *domain.FlowStateMachineRuntime
func (*Harness) EnsureGeneratedServer ¶
func (*Harness) EnsureHashValidator ¶
func (h *Harness) EnsureHashValidator(t *testing.T) crypto.HashValidator
func (*Harness) EnsureHashVerifier ¶
func (h *Harness) EnsureHashVerifier(t *testing.T) crypto.HashVerifier
func (*Harness) EnsureHasherFactory ¶
func (h *Harness) EnsureHasherFactory(t *testing.T) *crypto.HasherFactory
func (*Harness) EnsureIDPConnectionService ¶
func (h *Harness) EnsureIDPConnectionService(t *testing.T) service.IDPConnectionService
func (*Harness) EnsureKeyService ¶
func (h *Harness) EnsureKeyService(t *testing.T) service.KeyService
func (*Harness) EnsureMasterKey ¶
func (h *Harness) EnsureMasterKey(t *testing.T) *domain.MasterKeys
func (*Harness) EnsurePlatformProject ¶
EnsurePlatformProject lazily creates the deployment's platform project (ADR 046 §2) whose id is pinned on the handler and claim service. The fixed-id proj_platform bootstrap only writes the project row — no keyset, schemas, or flow definitions — so real logins against it are impossible; a normal fully provisioned project stands in.
It creates through the unwrapped service: this project is cached on the harness and pinned on the handler for the whole run, so deleting it when the first test that happened to need it ends would break every later test.
func (*Harness) EnsureProjectHashers ¶
func (h *Harness) EnsureProjectHashers(t *testing.T) service.ProjectHasherResolver
func (*Harness) EnsureProjectService ¶
func (h *Harness) EnsureProjectService(t *testing.T) service.ProjectService
EnsureProjectService returns the shared project service wrapped so that every project a test creates is deleted when that test ends. Tests in this package share one database, so rows left behind are paid for by every test that runs later; the authz tables cascade from projects, so one delete takes a test's whole contribution with it. The convention is written down in internal/AGENTS.md.
func (*Harness) EnsureReleaseService ¶
func (h *Harness) EnsureReleaseService(t *testing.T) service.ReleaseService
func (*Harness) EnsureSchemaResolver ¶
func (h *Harness) EnsureSchemaResolver(t *testing.T) *domain.JSONSchemaResolver
func (*Harness) EnsureSchemaService ¶
func (h *Harness) EnsureSchemaService(t *testing.T) *service.SchemaService
func (*Harness) EnsureSchemaStore ¶
func (h *Harness) EnsureSchemaStore(t *testing.T) domain.JSONSchemaStore
func (*Harness) EnsureSchemaValidator ¶
func (h *Harness) EnsureSchemaValidator(t *testing.T) *domain.SchemaValidator
func (*Harness) EnsureSecretGenerator ¶
func (*Harness) EnsureSecurityHandler ¶
func (h *Harness) EnsureSecurityHandler(t *testing.T) *api.SecurityHandler
func (*Harness) EnsureSessionService ¶
func (h *Harness) EnsureSessionService(t *testing.T) service.SessionService
func (*Harness) EnsureSigningKey ¶
func (h *Harness) EnsureSigningKey(t *testing.T) *rsa.PrivateKey
func (*Harness) EnsureTeamMembershipFixture ¶
func (h *Harness) EnsureTeamMembershipFixture(t *testing.T) TeamMembershipFixture
func (*Harness) EnsureTeamService ¶
func (h *Harness) EnsureTeamService(t *testing.T) *service.TeamService
func (*Harness) EnsureTestServer ¶
func (*Harness) EnsureTokenService ¶
func (h *Harness) EnsureTokenService(t *testing.T) service.TokenService
func (*Harness) EnsureUserFixture ¶
func (h *Harness) EnsureUserFixture(t *testing.T) UserFixture
func (*Harness) EnsureUserPasskeyFixture ¶
func (h *Harness) EnsureUserPasskeyFixture(t *testing.T) UserPasskeyFixture
func (*Harness) EnsureUserService ¶
func (h *Harness) EnsureUserService(t *testing.T) service.UserService
func (*Harness) ProjectSecret ¶
ProjectSecret mints the project's bearer, for tests that send a raw request instead of going through the generated client.
func (*Harness) RegisterPasskey ¶
RegisterPasskey runs a full registration ceremony through the auth attempt machinery and leaves one credential behind for the user, named passkeyName. The user factor is pinned on the attempt first, so the ceremony targets the existing user and excludes credentials already registered for it — hence a fresh virtual authenticator per call.
func (*Harness) SeedOwningTeam ¶
SeedOwningTeam writes the owning-team assignment claim/complete writes (ADR 046 §1), binding a team to the project's `team` relation. It is the shape that makes a claimer an operator: the seeded catalog resolves `project.admin` for the team's members through `member from team`, and admin closes to editor and viewer (ADR 054 §5). A test that seeds a direct user grant instead would not exercise that tuple-to-userset path.
func (*Harness) SeedProjectAdmin ¶
SeedProjectAdmin writes a project-scoped admin assignment: the strongest role, which the seeded catalog closes to editor and viewer (ADR 054 §5).
func (*Harness) SeedProjectEditor ¶
SeedProjectEditor writes a project-scoped editor assignment: it passes read and write checks, but not admin ones such as minting or revoking grants.
func (*Harness) SeedProjectViewer ¶
SeedProjectViewer writes a project-scoped viewer assignment and returns it, so a caller that needs to revoke or inspect the grant has its minted id. Viewer is the weakest role: it passes read checks only. A caller that has to write through the session needs SeedProjectAdmin.
func (*Harness) SetPreviewSecretOnApiClient ¶
func (*Harness) SetProjectSecretOnApiClient ¶
func (*Harness) SetScopedTokenOnApiClient ¶
func (h *Harness) SetScopedTokenOnApiClient(t *testing.T, client *ApiClient, project *domain.Project, scopes ...string)
SetScopedTokenOnApiClient mints a bearer with exactly the given scopes. Production only mints project and preview secrets, so this is the only way for a test to hold a finer scope like session.read until ADR 036's credential planes mint such tokens for real.
type TeamMembershipFixture ¶
func (TeamMembershipFixture) Create ¶
func (f TeamMembershipFixture) Create(ctx context.Context, membership *domain.TeamMembership) error
type UserFixture ¶
UserFixture exposes UserStatements helpers for integration tests.
func (UserFixture) Create ¶
func (f UserFixture) Create(ctx context.Context, user *domain.CreateUser) error
func (UserFixture) GetByAttributes ¶
func (UserFixture) GetPasswordByUserID ¶
func (f UserFixture) GetPasswordByUserID(ctx context.Context, projectID, userID string) (*domain.UserPassword, error)
func (UserFixture) SetPassword ¶
func (f UserFixture) SetPassword(ctx context.Context, pw *domain.SetUserPassword) error
type UserPasskeyFixture ¶
UserPasskeyFixture exposes UserPasskeyStatements helpers for integration tests.
func (UserPasskeyFixture) Create ¶
func (f UserPasskeyFixture) Create(ctx context.Context, passkey *domain.CreateUserPasskey) error
func (UserPasskeyFixture) ListByUser ¶
func (f UserPasskeyFixture) ListByUser(ctx context.Context, projectID, userID string) ([]*domain.UserPasskey, error)
Source Files
¶
- auth_attempt.go
- authz.go
- branding.go
- client.go
- crypto.go
- deployment.go
- environment.go
- event.go
- flow.go
- flow_definition.go
- harness.go
- http_client.go
- idp_connection.go
- jose.go
- json.go
- key.go
- name.go
- passkey_registration.go
- project.go
- release.go
- schema.go
- secrets.go
- server.go
- service_db.go
- session.go
- team.go
- test_data.go
- token.go
- user.go
- user_passkey.go