Add Certificates page and Traefik API frontend client

This commit is contained in:
backup 2026-09-02 12:42:52 -05:00
commit 7fc90524b5
40 changed files with 6585 additions and 359 deletions

View file

@ -0,0 +1,63 @@
package auth
import (
"strings"
"testing"
)
func TestGenerateSessionID_Entropy(t *testing.T) {
ids := make(map[string]bool)
for i := 0; i < 100; i++ {
id, err := GenerateSessionID()
if err != nil {
t.Fatalf("generate err %v", err)
}
if len(id) != SessionIDLength {
t.Fatalf("expected length %d got %d (%q)", SessionIDLength, len(id), id)
}
// Should be base64 URL safe chars
for _, c := range id {
if !((c >= 'A' && c <= 'Z') || (c >= 'a' && c <= 'z') || (c >= '0' && c <= '9') || c == '-' || c == '_') {
t.Fatalf("invalid char %q in id %q", c, id)
}
}
if ids[id] {
t.Fatalf("duplicate id %q", id)
}
ids[id] = true
// Ensure not truncated base64 padding '='
if strings.Contains(id, "=") {
t.Fatalf("id should not contain padding =, got %q", id)
}
}
}
func TestGenerateCSRFToken(t *testing.T) {
tok1, _ := GenerateCSRFToken()
tok2, _ := GenerateCSRFToken()
if tok1 == tok2 {
t.Fatalf("tokens should be unique")
}
if len(tok1) != CSRFTokenLength {
t.Fatalf("expected %d got %d", CSRFTokenLength, len(tok1))
}
}
func TestGenerateRandomString_NoTruncateLoss(t *testing.T) {
// Verify that 32-char string comes from 24 bytes (no wasted entropy beyond minimal truncation)
// We test that generating 32 chars produces full entropy: call many times and ensure uniqueness
seen := make(map[string]bool)
for i := 0; i < 200; i++ {
s, err := generateRandomString(32)
if err != nil {
t.Fatal(err)
}
if len(s) != 32 {
t.Fatalf("len %d", len(s))
}
if seen[s] {
t.Fatalf("duplicate at iteration %d", i)
}
seen[s] = true
}
}