package token import ( "bytes" "crypto/sha256" "testing" ) func TestTokenDeterministicPerReaderAndEpoch(t *testing.T) { key := []byte("deployment-secret") a := Token(key, "reader-1", 0) b := Token(key, "reader-1", 0) if a != b { t.Fatal("same (reader, epoch) derived different credentials") } if a == Token(key, "reader-2", 0) { t.Fatal("different readers derived the same credential") } if a == Token(key, "reader-1", 1) { t.Fatal("rotation epoch derived the same credential") } } func TestTokenChangesWithSecret(t *testing.T) { a := Token([]byte("key-1"), "reader-1", 0) b := Token([]byte("key-2"), "reader-1", 0) if a == b { t.Fatal("different secrets derived the same credential") } } func TestTokenFormat(t *testing.T) { cred := Token([]byte("key"), "reader-1", 0) // 32 bytes of HMAC-SHA256, hex-encoded: the length the install URL and // the committed placeholder both assume. if len(cred) != 64 { t.Fatalf("credential length = %d, want 64", len(cred)) } for _, c := range cred { if !(c >= '0' && c <= '9' || c >= 'a' && c <= 'f') { t.Fatalf("credential contains non-hex byte %q", c) } } } func TestHashIsSha256OfCredential(t *testing.T) { cred := Token([]byte("key"), "reader-1", 0) got := Hash(cred) want := sha256.Sum256([]byte(cred)) if !bytes.Equal(got[:], want[:]) { t.Fatal("Hash is not the SHA-256 of the credential") } }