server/apps/files_encryption/tests/keymanager.php

262 lines
7.4 KiB
PHP
Raw Normal View History

<?php
/**
* Copyright (c) 2012 Sam Tuke <samtuke@owncloud.com>
* This file is licensed under the Affero General Public License version 3 or
* later.
* See the COPYING-README file.
*/
require_once realpath(dirname(__FILE__) . '/../../../lib/base.php');
require_once realpath(dirname(__FILE__) . '/../lib/crypt.php');
require_once realpath(dirname(__FILE__) . '/../lib/keymanager.php');
require_once realpath(dirname(__FILE__) . '/../lib/proxy.php');
require_once realpath(dirname(__FILE__) . '/../lib/stream.php');
require_once realpath(dirname(__FILE__) . '/../lib/util.php');
require_once realpath(dirname(__FILE__) . '/../lib/helper.php');
require_once realpath(dirname(__FILE__) . '/../appinfo/app.php');
require_once realpath(dirname(__FILE__) . '/util.php');
use OCA\Encryption;
2013-05-19 20:28:48 +00:00
/**
* Class Test_Encryption_Keymanager
*/
class Test_Encryption_Keymanager extends \PHPUnit_Framework_TestCase {
2013-05-19 20:28:48 +00:00
const TEST_USER = "test-keymanager-user";
2013-05-19 20:28:48 +00:00
public $userId;
public $pass;
public $stateFilesTrashbin;
/**
* @var OC_FilesystemView
*/
public $view;
public $randomKey;
2013-05-21 22:55:16 +00:00
public $dataShort;
2013-05-19 20:28:48 +00:00
public static function setUpBeforeClass() {
2013-05-19 23:24:36 +00:00
// reset backend
\OC_User::clearBackends();
\OC_User::useBackend('database');
// Filesystem related hooks
\OCA\Encryption\Helper::registerFilesystemHooks();
// clear and register hooks
\OC_FileProxy::clearProxies();
\OC_FileProxy::register(new OCA\Encryption\Proxy());
// disable file proxy by default
\OC_FileProxy::$enabled = false;
2013-05-19 23:24:36 +00:00
// create test user
\OC_User::deleteUser(\Test_Encryption_Keymanager::TEST_USER);
\Test_Encryption_Util::loginHelper(\Test_Encryption_Keymanager::TEST_USER, true);
}
function setUp() {
// set content for encrypting / decrypting in tests
$this->dataLong = file_get_contents(realpath(dirname(__FILE__) . '/../lib/crypt.php'));
$this->dataShort = 'hats';
$this->dataUrl = realpath(dirname(__FILE__) . '/../lib/crypt.php');
$this->legacyData = realpath(dirname(__FILE__) . '/legacy-text.txt');
$this->legacyEncryptedData = realpath(dirname(__FILE__) . '/legacy-encrypted-text.txt');
$this->randomKey = Encryption\Crypt::generateKey();
2013-05-19 23:24:36 +00:00
$keypair = Encryption\Crypt::createKeypair();
2013-05-19 23:24:36 +00:00
$this->genPublicKey = $keypair['publicKey'];
$this->genPrivateKey = $keypair['privateKey'];
$this->view = new \OC_FilesystemView('/');
\OC_User::setUserId(\Test_Encryption_Keymanager::TEST_USER);
$this->userId = \Test_Encryption_Keymanager::TEST_USER;
$this->pass = \Test_Encryption_Keymanager::TEST_USER;
$userHome = \OC_User::getHome($this->userId);
$this->dataDir = str_replace('/' . $this->userId, '', $userHome);
2013-05-16 23:07:26 +00:00
// remember files_trashbin state
$this->stateFilesTrashbin = OC_App::isEnabled('files_trashbin');
2013-05-16 23:07:26 +00:00
// we don't want to tests with app files_trashbin enabled
\OC_App::disable('files_trashbin');
}
2013-05-19 23:24:36 +00:00
function tearDown() {
2013-05-16 23:07:26 +00:00
// reset app files_trashbin
if ($this->stateFilesTrashbin) {
OC_App::enable('files_trashbin');
}
else {
OC_App::disable('files_trashbin');
2013-05-16 23:07:26 +00:00
}
}
public static function tearDownAfterClass() {
\OC_FileProxy::$enabled = true;
// cleanup test user
\OC_User::deleteUser(\Test_Encryption_Keymanager::TEST_USER);
}
2013-06-10 07:31:22 +00:00
/**
* @medium
*/
function testGetPrivateKey() {
2013-05-19 23:24:36 +00:00
$key = Encryption\Keymanager::getPrivateKey($this->view, $this->userId);
2013-04-29 23:54:19 +00:00
$privateKey = Encryption\Crypt::symmetricDecryptFileContent($key, $this->pass);
2013-04-29 23:54:19 +00:00
$res = openssl_pkey_get_private($privateKey);
2013-04-29 23:54:19 +00:00
$this->assertTrue(is_resource($res));
2013-05-18 20:00:35 +00:00
$sslInfo = openssl_pkey_get_details($res);
2013-05-18 20:00:35 +00:00
$this->assertArrayHasKey('key', $sslInfo);
2013-05-19 23:24:36 +00:00
}
2013-06-10 07:31:22 +00:00
/**
* @medium
*/
function testGetPublicKey() {
2013-05-19 23:24:36 +00:00
$publiceKey = Encryption\Keymanager::getPublicKey($this->view, $this->userId);
2013-05-18 20:00:35 +00:00
$res = openssl_pkey_get_public($publiceKey);
2013-05-18 20:00:35 +00:00
$this->assertTrue(is_resource($res));
2013-05-18 20:00:35 +00:00
$sslInfo = openssl_pkey_get_details($res);
2013-05-18 20:00:35 +00:00
$this->assertArrayHasKey('key', $sslInfo);
}
2013-05-19 23:24:36 +00:00
2013-06-10 07:31:22 +00:00
/**
* @medium
*/
function testSetFileKey() {
2013-05-19 23:24:36 +00:00
# NOTE: This cannot be tested until we are able to break out
# of the FileSystemView data directory root
$key = Encryption\Crypt::symmetricEncryptFileContentKeyfile($this->randomKey, 'hat');
2013-05-19 23:24:36 +00:00
$file = 'unittest-' . time() . '.txt';
2013-05-19 23:24:36 +00:00
// Disable encryption proxy to prevent recursive calls
$proxyStatus = \OC_FileProxy::$enabled;
\OC_FileProxy::$enabled = false;
$this->view->file_put_contents($this->userId . '/files/' . $file, $key['encrypted']);
2013-05-19 23:24:36 +00:00
// Re-enable proxy - our work is done
\OC_FileProxy::$enabled = $proxyStatus;
//$view = new \OC_FilesystemView( '/' . $this->userId . '/files_encryption/keyfiles' );
Encryption\Keymanager::setFileKey($this->view, $file, $this->userId, $key['key']);
2013-05-16 23:07:26 +00:00
2013-05-21 22:55:16 +00:00
// enable encryption proxy
2013-05-16 23:07:26 +00:00
$proxyStatus = \OC_FileProxy::$enabled;
\OC_FileProxy::$enabled = true;
// cleanup
$this->view->unlink('/' . $this->userId . '/files/' . $file);
2013-05-16 23:07:26 +00:00
2013-05-21 22:55:16 +00:00
// change encryption proxy to previous state
2013-05-16 23:07:26 +00:00
\OC_FileProxy::$enabled = $proxyStatus;
2013-05-19 23:24:36 +00:00
}
2013-05-19 23:24:36 +00:00
2013-06-10 07:31:22 +00:00
/**
* @medium
*/
function testGetUserKeys() {
2013-05-19 23:24:36 +00:00
$keys = Encryption\Keymanager::getUserKeys($this->view, $this->userId);
2013-04-29 23:54:19 +00:00
$resPublic = openssl_pkey_get_public($keys['publicKey']);
2013-04-29 23:54:19 +00:00
$this->assertTrue(is_resource($resPublic));
2013-04-29 23:54:19 +00:00
$sslInfoPublic = openssl_pkey_get_details($resPublic);
2013-04-29 23:54:19 +00:00
$this->assertArrayHasKey('key', $sslInfoPublic);
2013-05-18 20:25:47 +00:00
$privateKey = Encryption\Crypt::symmetricDecryptFileContent($keys['privateKey'], $this->pass);
2013-05-18 20:25:47 +00:00
$resPrivate = openssl_pkey_get_private($privateKey);
2013-05-18 20:25:47 +00:00
$this->assertTrue(is_resource($resPrivate));
2013-05-18 20:25:47 +00:00
$sslInfoPrivate = openssl_pkey_get_details($resPrivate);
2013-05-18 20:25:47 +00:00
$this->assertArrayHasKey('key', $sslInfoPrivate);
}
2013-05-21 22:55:16 +00:00
2013-06-10 07:31:22 +00:00
/**
* @medium
*/
function testFixPartialFilePath() {
2013-05-21 22:55:16 +00:00
$partFilename = 'testfile.txt.part';
$filename = 'testfile.txt';
$this->assertTrue(Encryption\Keymanager::isPartialFilePath($partFilename));
2013-05-21 22:55:16 +00:00
$this->assertEquals('testfile.txt', Encryption\Keymanager::fixPartialFilePath($partFilename));
2013-05-21 22:55:16 +00:00
$this->assertFalse(Encryption\Keymanager::isPartialFilePath($filename));
2013-05-21 22:55:16 +00:00
$this->assertEquals('testfile.txt', Encryption\Keymanager::fixPartialFilePath($filename));
2013-05-21 22:55:16 +00:00
}
2013-06-10 07:31:22 +00:00
/**
* @medium
*/
function testRecursiveDelShareKeys() {
2013-05-21 22:55:16 +00:00
// generate filename
$filename = '/tmp-' . time() . '.txt';
// create folder structure
$this->view->mkdir('/'.Test_Encryption_Keymanager::TEST_USER.'/files/folder1');
$this->view->mkdir('/'.Test_Encryption_Keymanager::TEST_USER.'/files/folder1/subfolder');
$this->view->mkdir('/'.Test_Encryption_Keymanager::TEST_USER.'/files/folder1/subfolder/subsubfolder');
2013-05-21 22:55:16 +00:00
// enable encryption proxy
$proxyStatus = \OC_FileProxy::$enabled;
\OC_FileProxy::$enabled = true;
// save file with content
$cryptedFile = file_put_contents('crypt:///folder1/subfolder/subsubfolder/' . $filename, $this->dataShort);
2013-05-21 22:55:16 +00:00
// test that data was successfully written
$this->assertTrue(is_int($cryptedFile));
2013-05-21 22:55:16 +00:00
// change encryption proxy to previous state
\OC_FileProxy::$enabled = $proxyStatus;
// recursive delete keys
Encryption\Keymanager::delShareKey($this->view, array('admin'), '/folder1/');
2013-05-21 22:55:16 +00:00
// check if share key not exists
$this->assertFalse($this->view->file_exists(
'/admin/files_encryption/share-keys/folder1/subfolder/subsubfolder/' . $filename . '.admin.shareKey'));
2013-05-21 22:55:16 +00:00
// enable encryption proxy
$proxyStatus = \OC_FileProxy::$enabled;
\OC_FileProxy::$enabled = true;
// cleanup
$this->view->unlink('/admin/files/folder1');
2013-05-21 22:55:16 +00:00
// change encryption proxy to previous state
\OC_FileProxy::$enabled = $proxyStatus;
}
}