popoidc — test report

← report home

Check src/agecrypt_test.ts
Check src/challenge_test.ts
Check src/config_test.ts
Check src/flow_decrypt_test.ts
Check src/flow_hmac_test.ts
Check src/flow_sign_test.ts
Check src/handler_test.ts
Check src/hmacid_test.ts
Check src/sshkey_test.ts
Check src/sshsig_test.ts
Check src/sshwire_test.ts
Check src/token_test.ts
running 3 tests from ./src/agecrypt_test.ts
encryptToRecipient round-trips through age (native age1 X25519) ... ok (31ms)
encryptToRecipient round-trips through age (reimplemented ssh-ed25519 stanza) ... ok (16ms)
encryptToRecipient rejects an unsupported recipient ... ok (791µs)
running 11 tests from ./src/challenge_test.ts
an issued challenge verifies and round-trips its fields ... ok (3ms)
verifyChallenge rejects a tampered payload ... ok (1ms)
verifyChallenge rejects a wrong secret ... ok (1ms)
verifyChallenge rejects an expired challenge ... ok (635µs)
verifyChallenge rejects a challenge from the future ... ok (497µs)
verifyChallenge accepts within the freshness window ... ok (434µs)
verifyChallenge rejects a token with no dot ... ok (147µs)
verifyChallenge rejects a token with an empty MAC ... ok (141µs)
verifyChallenge rejects a non-base64url MAC ... ok (579µs)
verifyChallenge rejects a MAC of the wrong length ... ok (467µs)
verifyChallenge rejects a challenge with a non-numeric iat ... ok (445µs)
running 5 tests from ./src/config_test.ts
loadConfig builds a Config from env and derives a public-only JWK ... ok (152ms)
loadConfig enables HMAC mode when an identity pepper is set ... ok (113ms)
loadConfig requires POPOIDC_ISSUER ... ok (754µs)
loadConfig rejects a JWK that is not an RSA private key with a kid ... ok (194µs)
loadConfig rejects a signing JWK that is not valid JSON ... ok (245µs)
running 2 tests from ./src/flow_decrypt_test.ts
decryption flow (native age1): challenge → age -d → Token ... ok (293ms)
decryption flow (ssh-ed25519): challenge → age -d → Token ... ok (224ms)
running 6 tests from ./src/flow_hmac_test.ts
hmac flow: secret → Token, in one request ... ok (157ms)
hmac flow: the same secret always names the same Identity ... ok (145ms)
hmac mode is off unless an identity pepper is configured ... ok (166ms)
/token (hmac) requires aud ... ok (131ms)
/token (hmac) rejects a guessably short secret ... ok (297ms)
/token rejects a request carrying both a challenge and a secret ... ok (357ms)
running 3 tests from ./src/flow_sign_test.ts
signing flow: challenge → ssh-keygen sign → Token ... ok (185ms)
token endpoint rejects a signature from a different key ... ok (175ms)
token endpoint rejects a challenge that is past the freshness window ... ok (189ms)
running 15 tests from ./src/handler_test.ts
GET /.well-known/openid-configuration returns the discovery document ... ok (144ms)
GET /.well-known/jwks.json returns the public JWKS ... ok (115ms)
an unknown route returns 404 ... ok (146ms)
GET / redirects to the GitHub readme ... ok (198ms)
/challenge responses are marked no-store (never cacheable) ... ok (556ms)
POST /challenge accepts form-encoded params ... ok (90ms)
/challenge requires key and aud ... ok (132ms)
/challenge rejects an unsupported key type ... ok (117ms)
/challenge rejects an invalid ssh-ed25519 key ... ok (105ms)
/challenge rejects an invalid age recipient ... ok (235ms)
/token requires a challenge ... ok (141ms)
/token rejects an oversized request body ... ok (62ms)
/token (sign) requires a signature ... ok (355ms)
/token (sign) rejects an unverifiable signature ... ok (150ms)
/token returns 500 when signing fails unexpectedly ... ok (151ms)
running 4 tests from ./src/hmacid_test.ts
secretFingerprint has the SHA256-fingerprint shape (unpadded base64) ... ok (2ms)
secretFingerprint is deterministic for the same secret and pepper ... ok (839µs)
secretFingerprint separates different secrets ... ok (948µs)
secretFingerprint separates Issuers: the same secret differs per pepper ... ok (608µs)
running 7 tests from ./src/sshkey_test.ts
sshFingerprint matches `ssh-keygen -lf` for a generated ed25519 key ... ok (16ms)
parseSshEd25519 rejects a non-ed25519 key type ... ok (568µs)
parseSshEd25519 rejects malformed input ... ok (139µs)
parseSshEd25519 rejects invalid base64 ... ok (312µs)
parseSshEd25519 rejects an inner wire key-type mismatch ... ok (436µs)
parseSshEd25519 rejects a wrong-length ed25519 key ... ok (225µs)
parseSshEd25519 rejects trailing bytes ... ok (250µs)
running 13 tests from ./src/sshsig_test.ts
verifySshsig accepts a genuine signature and returns the signer key ... ok (56ms)
verifySshsig rejects a signature made under a different namespace ... ok (9ms)
verifySshsig rejects a tampered message ... ok (11ms)
verifySshsig accepts a valid sha256 signature ... ok (5ms)
verifySshsig rejects non-armored input ... ok (14ms)
verifySshsig rejects bad magic ... ok (2ms)
verifySshsig rejects an unsupported version ... ok (1ms)
verifySshsig rejects an unsupported key type ... ok (1ms)
verifySshsig rejects a bad public key length ... ok (1ms)
verifySshsig rejects an unsupported signature type ... ok (1ms)
verifySshsig rejects a bad signature length ... ok (1ms)
verifySshsig rejects an unsupported hash algorithm ... ok (1ms)
verifySshsig rejects a signature that does not verify ... ok (3ms)
running 3 tests from ./src/sshwire_test.ts
Reader.readUint32 throws when truncated ... ok (940µs)
Reader.readString throws when the body is truncated ... ok (231µs)
writeString + concat round-trip through Reader ... ok (687µs)
running 3 tests from ./src/token_test.ts
mintToken issues an RS256 JWT that verifies against the JWKS ... ok (167ms)
discoveryDocument advertises issuer, jwks_uri and RS256 ... ok (327µs)
jwksDocument exposes public keys with kid+alg and no private component ... ok (109ms)

ok | 75 passed | 0 failed (6s)

| File         | Branch % | Function % | Line % |
| ------------ | -------- | ---------- | ------ |
| agecrypt.ts  |    100.0 |      100.0 |  100.0 |
| challenge.ts |    100.0 |      100.0 |  100.0 |
| config.ts    |    100.0 |      100.0 |  100.0 |
| handler.ts   |    100.0 |      100.0 |  100.0 |
| hmacid.ts    |    100.0 |      100.0 |  100.0 |
| sshkey.ts    |    100.0 |      100.0 |  100.0 |
| sshsig.ts    |    100.0 |      100.0 |  100.0 |
| sshwire.ts   |    100.0 |      100.0 |  100.0 |
| testutil.ts  |     83.3 |      100.0 |   95.7 |
| token.ts     |    100.0 |      100.0 |  100.0 |
| All files    |     99.6 |      100.0 |   99.4 |
Lcov coverage report has been generated at file:///home/runner/work/popoidc/popoidc/coverage/lcov.info
HTML coverage report has been generated at file:///home/runner/work/popoidc/popoidc/coverage/html/index.html