helpers

package
v1.0.0-alpha.24 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: AGPL-3.0 Imports: 32 Imported by: 0

Documentation

Index

Constants

View Source
const BuiltinSchemaBaseURL = "https://test.example.schemas.com/schemas"

Variables

View Source
var PasskeyRelyingParty = virtualwebauthn.RelyingParty{
	ID:     "example.com",
	Name:   "example.com",
	Origin: "https://example.com",
}

PasskeyRelyingParty is the relying party Harness.RegisterPasskey registers against. Tests that drive the ceremony themselves should use the same values, so the attestation origin matches what the issued challenge was given.

Functions

func CreateSessionUsingPassword

func CreateSessionUsingPassword(t *testing.T,
	authAttempts service.AuthAttemptService,
	sessionService service.SessionService,
	projectID string, userEmail string, userPassword string) (*domain.Session, error)

func MustMarshal

func MustMarshal(t *testing.T, v any) string

func MustUnmarshal

func MustUnmarshal[T any](t *testing.T, bs []byte) *T

func OIDCConnection

func OIDCConnection(slug string) api.IdpConnection

OIDCConnection is a minimal valid OIDC connection document. Tests change the fields they are about on the returned value.

func ProjectName

func ProjectName() string

ProjectName returns a unique project name for integration tests.

func RandString

func RandString(n int) string

func TeamName

func TeamName() string

TeamName returns a unique team name for integration tests.

Types

type ApiClient

type ApiClient struct {
	*api.Client
	// contains filtered or unexported fields
}

func NewApiClient

func NewApiClient(
	serverURL string,
) (*ApiClient, error)

func (*ApiClient) SetScopes

func (c *ApiClient) SetScopes(scopes []string)

func (*ApiClient) SetSessionToken

func (c *ApiClient) SetSessionToken(token string)

func (*ApiClient) SetToken

func (c *ApiClient) SetToken(token string)

func (*ApiClient) Token

func (c *ApiClient) Token() string

type FakeSecuritySource

type FakeSecuritySource struct {
	Token  string
	Scopes []string

	SessionToken string
}

func (FakeSecuritySource) NextgenSession

func (f FakeSecuritySource) NextgenSession(ctx context.Context, operationName api.OperationName) (api.NextgenSession, error)

NextgenSession provides the __nextgen_session cookie. With an empty SessionToken the scheme is skipped and the generated client fails fast with "security requirement is not satisfied" instead of sending the request — to exercise the server's missing-credential path, send a raw HTTP request (see TestGetMyUser/missing_session_cookie).

func (FakeSecuritySource) OAuth2

func (f FakeSecuritySource) OAuth2(ctx context.Context, operationName api.OperationName) (api.OAuth2, error)

type Harness

type Harness struct {
	DB *service.DB
	// contains filtered or unexported fields
}

func (*Harness) CleanupProject

func (h *Harness) CleanupProject(t *testing.T, projectID string)

CleanupProject deletes projectID when t ends. Use it for a project the test created through the API rather than through Harness.EnsureProjectService: the handler holds the unwrapped service, so that project is the test's to remove.

func (*Harness) CreateActiveSession

func (h *Harness) CreateActiveSession(t *testing.T, projectID, userID string) *domain.Session

CreateActiveSession exchanges a handed-off attempt with a verified user factor, binding the user to the new session. The user must exist: sessions.user_id references users.

A handoff is valid for one minute, and the Spanner emulator can queue the exchange past it. Only on that answer the helper seeds a fresh attempt, up to three times; a handoff that is actually broken still fails the test. TestClaimHappyPath and the session exchange tests exchange exactly once.

func (*Harness) CreateSession

func (h *Harness) CreateSession(t *testing.T, projectID string, ttl time.Duration) *domain.Session

CreateSession seeds a session directly in storage. No user is bound, so it reads as building until the TTL elapses. The database clock stamps expires_at while the state filter compares it against the service clock, so a test that needs the session expired must wait until that is observable rather than assume a tiny TTL has already elapsed.

func (*Harness) CreateUserOwnedByTeam

func (h *Harness) CreateUserOwnedByTeam(t *testing.T, projectID string) (userID, teamID string)

CreateUserOwnedByTeam seeds a builtin-schema user whose lifecycle a team of its own owns (ADR 024) and returns both ids. Ownership is what the session team filter reads, so this is the shape that filter's tests need; roster membership alone is Harness.CreateUserWithTeam.

func (*Harness) CreateUserSchema

func (h *Harness) CreateUserSchema(t *testing.T, project *domain.Project, schema string) string

func (*Harness) CreateUserWithTeam

func (h *Harness) CreateUserWithTeam(t *testing.T, projectID string) string

CreateUserWithTeam seeds a builtin-schema user on the roster of a team of its own and returns its id. The user stays self-owned — see Harness.CreateUserOwnedByTeam for the team-owned shape. The id and email are randomized, so repeated calls in one project stay unique.

func (*Harness) EnsureAuthAttemptService

func (h *Harness) EnsureAuthAttemptService(t *testing.T) service.AuthAttemptService

func (*Harness) EnsureBrandingService

func (h *Harness) EnsureBrandingService(t *testing.T) *service.BrandingService

func (*Harness) EnsureCreateUserHandler

func (h *Harness) EnsureCreateUserHandler(t *testing.T) *service.FlowCreateUserWithPasswordHandler

func (*Harness) EnsureDeploymentService

func (h *Harness) EnsureDeploymentService(t *testing.T) *service.DeploymentService

func (*Harness) EnsureEnvironmentService

func (h *Harness) EnsureEnvironmentService(t *testing.T) *service.EnvironmentService

func (*Harness) EnsureEventService

func (h *Harness) EnsureEventService(t *testing.T) *service.EventService

func (*Harness) EnsureFlowDefinitionService

func (h *Harness) EnsureFlowDefinitionService(t *testing.T) service.FlowDefinitionService

func (*Harness) EnsureFlowService

func (h *Harness) EnsureFlowService(t *testing.T) service.FlowService

func (*Harness) EnsureFlowStateMachine

func (h *Harness) EnsureFlowStateMachine(t *testing.T) *domain.FlowStateMachineRuntime

func (*Harness) EnsureGeneratedServer

func (h *Harness) EnsureGeneratedServer(t *testing.T) *generated.Server

func (*Harness) EnsureHandler

func (h *Harness) EnsureHandler(t *testing.T) *api.Handler

func (*Harness) EnsureHashValidator

func (h *Harness) EnsureHashValidator(t *testing.T) crypto.HashValidator

func (*Harness) EnsureHashVerifier

func (h *Harness) EnsureHashVerifier(t *testing.T) crypto.HashVerifier

func (*Harness) EnsureHasher

func (h *Harness) EnsureHasher(t *testing.T) crypto.Hasher

func (*Harness) EnsureHasherFactory

func (h *Harness) EnsureHasherFactory(t *testing.T) *crypto.HasherFactory

func (*Harness) EnsureHttpClient

func (h *Harness) EnsureHttpClient(t *testing.T) *http.Client

func (*Harness) EnsureIDPConnectionService

func (h *Harness) EnsureIDPConnectionService(t *testing.T) service.IDPConnectionService

func (*Harness) EnsureJoseSigner

func (h *Harness) EnsureJoseSigner(t *testing.T) jose.Signer

func (*Harness) EnsureKeyService

func (h *Harness) EnsureKeyService(t *testing.T) service.KeyService

func (*Harness) EnsureMasterKey

func (h *Harness) EnsureMasterKey(t *testing.T) *domain.MasterKeys

func (*Harness) EnsurePlatformProject

func (h *Harness) EnsurePlatformProject(t *testing.T) *domain.Project

EnsurePlatformProject lazily creates the deployment's platform project (ADR 046 §2) whose id is pinned on the handler and claim service. The fixed-id proj_platform bootstrap only writes the project row — no keyset, schemas, or flow definitions — so real logins against it are impossible; a normal fully provisioned project stands in.

It creates through the unwrapped service: this project is cached on the harness and pinned on the handler for the whole run, so deleting it when the first test that happened to need it ends would break every later test.

func (*Harness) EnsureProjectHashers

func (h *Harness) EnsureProjectHashers(t *testing.T) service.ProjectHasherResolver

func (*Harness) EnsureProjectService

func (h *Harness) EnsureProjectService(t *testing.T) service.ProjectService

EnsureProjectService returns the shared project service wrapped so that every project a test creates is deleted when that test ends. Tests in this package share one database, so rows left behind are paid for by every test that runs later; the authz tables cascade from projects, so one delete takes a test's whole contribution with it. The convention is written down in internal/AGENTS.md.

func (*Harness) EnsureReleaseService

func (h *Harness) EnsureReleaseService(t *testing.T) service.ReleaseService

func (*Harness) EnsureSchemaResolver

func (h *Harness) EnsureSchemaResolver(t *testing.T) *domain.JSONSchemaResolver

func (*Harness) EnsureSchemaService

func (h *Harness) EnsureSchemaService(t *testing.T) *service.SchemaService

func (*Harness) EnsureSchemaStore

func (h *Harness) EnsureSchemaStore(t *testing.T) domain.JSONSchemaStore

func (*Harness) EnsureSchemaValidator

func (h *Harness) EnsureSchemaValidator(t *testing.T) *domain.SchemaValidator

func (*Harness) EnsureSecretGenerator

func (h *Harness) EnsureSecretGenerator(t *testing.T) secrets.Generator

func (*Harness) EnsureSecurityHandler

func (h *Harness) EnsureSecurityHandler(t *testing.T) *api.SecurityHandler

func (*Harness) EnsureServiceDB

func (h *Harness) EnsureServiceDB(t *testing.T) *service.DB

func (*Harness) EnsureSessionService

func (h *Harness) EnsureSessionService(t *testing.T) service.SessionService

func (*Harness) EnsureSigningKey

func (h *Harness) EnsureSigningKey(t *testing.T) *rsa.PrivateKey

func (*Harness) EnsureTeamMembershipFixture

func (h *Harness) EnsureTeamMembershipFixture(t *testing.T) TeamMembershipFixture

func (*Harness) EnsureTeamService

func (h *Harness) EnsureTeamService(t *testing.T) *service.TeamService

func (*Harness) EnsureTestData

func (h *Harness) EnsureTestData(t *testing.T) *test_data.TestData

func (*Harness) EnsureTestServer

func (h *Harness) EnsureTestServer(t *testing.T) *httptest.Server

func (*Harness) EnsureTokenService

func (h *Harness) EnsureTokenService(t *testing.T) service.TokenService

func (*Harness) EnsureUserFixture

func (h *Harness) EnsureUserFixture(t *testing.T) UserFixture

func (*Harness) EnsureUserPasskeyFixture

func (h *Harness) EnsureUserPasskeyFixture(t *testing.T) UserPasskeyFixture

func (*Harness) EnsureUserService

func (h *Harness) EnsureUserService(t *testing.T) service.UserService

func (*Harness) ProjectSecret

func (h *Harness) ProjectSecret(t *testing.T, project *domain.Project) string

ProjectSecret mints the project's bearer, for tests that send a raw request instead of going through the generated client.

func (*Harness) RegisterPasskey

func (h *Harness) RegisterPasskey(t *testing.T, projectID, userID, passkeyName string)

RegisterPasskey runs a full registration ceremony through the auth attempt machinery and leaves one credential behind for the user, named passkeyName. The user factor is pinned on the attempt first, so the ceremony targets the existing user and excludes credentials already registered for it — hence a fresh virtual authenticator per call.

func (*Harness) SeedOwningTeam

func (h *Harness) SeedOwningTeam(t *testing.T, projectID, teamID string)

SeedOwningTeam writes the owning-team assignment claim/complete writes (ADR 046 §1), binding a team to the project's `team` relation. It is the shape that makes a claimer an operator: the seeded catalog resolves `project.admin` for the team's members through `member from team`, and admin closes to editor and viewer (ADR 054 §5). A test that seeds a direct user grant instead would not exercise that tuple-to-userset path.

func (*Harness) SeedProjectAdmin

func (h *Harness) SeedProjectAdmin(t *testing.T, projectID, userID string) *domain.AuthzAssignment

SeedProjectAdmin writes a project-scoped admin assignment: the strongest role, which the seeded catalog closes to editor and viewer (ADR 054 §5).

func (*Harness) SeedProjectEditor

func (h *Harness) SeedProjectEditor(t *testing.T, projectID, userID string) *domain.AuthzAssignment

SeedProjectEditor writes a project-scoped editor assignment: it passes read and write checks, but not admin ones such as minting or revoking grants.

func (*Harness) SeedProjectViewer

func (h *Harness) SeedProjectViewer(t *testing.T, projectID, userID string) *domain.AuthzAssignment

SeedProjectViewer writes a project-scoped viewer assignment and returns it, so a caller that needs to revoke or inspect the grant has its minted id. Viewer is the weakest role: it passes read checks only. A caller that has to write through the session needs SeedProjectAdmin.

func (*Harness) SetPreviewSecretOnApiClient

func (h *Harness) SetPreviewSecretOnApiClient(t *testing.T, client *ApiClient, project *domain.Project)

func (*Harness) SetProjectSecretOnApiClient

func (h *Harness) SetProjectSecretOnApiClient(t *testing.T, client *ApiClient, project *domain.Project)

func (*Harness) SetScopedTokenOnApiClient

func (h *Harness) SetScopedTokenOnApiClient(t *testing.T, client *ApiClient, project *domain.Project, scopes ...string)

SetScopedTokenOnApiClient mints a bearer with exactly the given scopes. Production only mints project and preview secrets, so this is the only way for a test to hold a finer scope like session.read until ADR 036's credential planes mint such tokens for real.

type TeamMembershipFixture

type TeamMembershipFixture struct {
	Pool *service.DB
}

func (TeamMembershipFixture) Create

func (f TeamMembershipFixture) Create(ctx context.Context, membership *domain.TeamMembership) error

type UserFixture

type UserFixture struct {
	Pool *service.DB
}

UserFixture exposes UserStatements helpers for integration tests.

func (UserFixture) Create

func (f UserFixture) Create(ctx context.Context, user *domain.CreateUser) error

func (UserFixture) GetByAttributes

func (f UserFixture) GetByAttributes(ctx context.Context, projectID string, attrs []domain.Attribute) (*domain.User, error)

func (UserFixture) GetByID

func (f UserFixture) GetByID(ctx context.Context, projectID, userID string) (*domain.User, error)

func (UserFixture) GetPasswordByUserID

func (f UserFixture) GetPasswordByUserID(ctx context.Context, projectID, userID string) (*domain.UserPassword, error)

func (UserFixture) SetPassword

func (f UserFixture) SetPassword(ctx context.Context, pw *domain.SetUserPassword) error

type UserPasskeyFixture

type UserPasskeyFixture struct {
	Pool *service.DB
}

UserPasskeyFixture exposes UserPasskeyStatements helpers for integration tests.

func (UserPasskeyFixture) Create

func (UserPasskeyFixture) ListByUser

func (f UserPasskeyFixture) ListByUser(ctx context.Context, projectID, userID string) ([]*domain.UserPasskey, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL