@ -15,19 +15,41 @@
* /
package org.thingsboard.server.controller ;
import com.fasterxml.jackson.databind.JsonNode ;
import org.junit.After ;
import org.junit.Test ;
import org.mockito.Mockito ;
import org.springframework.http.HttpHeaders ;
import org.testcontainers.shaded.org.apache.commons.lang3.RandomStringUtils ;
import org.thingsboard.common.util.JacksonUtil ;
import org.thingsboard.server.common.data.security.Authority ;
import org.thingsboard.server.common.data.security.model.SecuritySettings ;
import org.thingsboard.server.dao.service.DaoSqlTest ;
import org.thingsboard.server.service.security.auth.rest.LoginRequest ;
import org.thingsboard.server.service.security.model.ChangePasswordRequest ;
import java.util.concurrent.TimeUnit ;
import static org.hamcrest.Matchers.is ;
import static org.mockito.ArgumentMatchers.anyString ;
import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.header ;
import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.jsonPath ;
import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.status ;
@DaoSqlTest
public class AuthControllerTest extends AbstractControllerTest {
@After
public void tearDown ( ) throws Exception {
loginSysAdmin ( ) ;
SecuritySettings securitySettings = doGet ( "/api/admin/securitySettings" , SecuritySettings . class ) ;
securitySettings . getPasswordPolicy ( ) . setMaximumLength ( 72 ) ;
securitySettings . getPasswordPolicy ( ) . setForceUserToResetPasswordIfNotValid ( false ) ;
doPost ( "/api/admin/securitySettings" , securitySettings ) . andExpect ( status ( ) . isOk ( ) ) ;
}
@Test
public void testGetUser ( ) throws Exception {
@ -84,4 +106,65 @@ public class AuthControllerTest extends AbstractControllerTest {
. andExpect ( jsonPath ( "$.authority" , is ( Authority . SYS_ADMIN . name ( ) ) ) )
. andExpect ( jsonPath ( "$.email" , is ( SYS_ADMIN_EMAIL ) ) ) ;
}
@Test
public void testShouldNotUpdatePasswordWithValueLongerThanDefaultLimit ( ) throws Exception {
loginTenantAdmin ( ) ;
ChangePasswordRequest changePasswordRequest = new ChangePasswordRequest ( ) ;
changePasswordRequest . setCurrentPassword ( "tenant" ) ;
changePasswordRequest . setNewPassword ( RandomStringUtils . randomAlphanumeric ( 73 ) ) ;
doPost ( "/api/auth/changePassword" , changePasswordRequest )
. andExpect ( status ( ) . isBadRequest ( ) )
. andExpect ( jsonPath ( "$.message" , is ( "Password must be no more than 72 characters in length." ) ) ) ;
}
@Test
public void testShouldNotAuthorizeUserIfHisPasswordBecameTooLong ( ) throws Exception {
loginTenantAdmin ( ) ;
ChangePasswordRequest changePasswordRequest = new ChangePasswordRequest ( ) ;
changePasswordRequest . setCurrentPassword ( "tenant" ) ;
String newPassword = RandomStringUtils . randomAlphanumeric ( 16 ) ;
changePasswordRequest . setNewPassword ( newPassword ) ;
doPost ( "/api/auth/changePassword" , changePasswordRequest )
. andExpect ( status ( ) . isOk ( ) ) ;
loginUser ( TENANT_ADMIN_EMAIL , newPassword ) ;
loginSysAdmin ( ) ;
SecuritySettings securitySettings = doGet ( "/api/admin/securitySettings" , SecuritySettings . class ) ;
securitySettings . getPasswordPolicy ( ) . setMaximumLength ( 15 ) ;
securitySettings . getPasswordPolicy ( ) . setForceUserToResetPasswordIfNotValid ( true ) ;
doPost ( "/api/admin/securitySettings" , securitySettings ) . andExpect ( status ( ) . isOk ( ) ) ;
//try to login with user password that is not valid after security settings was updated
doPost ( "/api/auth/login" , new LoginRequest ( TENANT_ADMIN_EMAIL , newPassword ) )
. andExpect ( status ( ) . isUnauthorized ( ) )
. andExpect ( jsonPath ( "$.message" , is ( "Password does not pass validation. Please try again or reset password to valid one." ) ) ) ;
}
@Test
public void testShouldNotResetPasswordToTooLongValue ( ) throws Exception {
loginTenantAdmin ( ) ;
JsonNode resetPasswordByEmailRequest = JacksonUtil . newObjectNode ( )
. put ( "email" , TENANT_ADMIN_EMAIL ) ;
doPost ( "/api/noauth/resetPasswordByEmail" , resetPasswordByEmailRequest )
. andExpect ( status ( ) . isOk ( ) ) ;
Thread . sleep ( 1000 ) ;
doGet ( "/api/noauth/resetPassword?resetToken={resetToken}" , this . currentResetPasswordToken )
. andExpect ( status ( ) . isSeeOther ( ) )
. andExpect ( header ( ) . string ( HttpHeaders . LOCATION , "/login/resetPassword?resetToken=" + this . currentResetPasswordToken ) ) ;
String newPassword = RandomStringUtils . randomAlphanumeric ( 73 ) ;
JsonNode resetPasswordRequest = JacksonUtil . newObjectNode ( )
. put ( "resetToken" , this . currentResetPasswordToken )
. put ( "password" , newPassword ) ;
Mockito . doNothing ( ) . when ( mailService ) . sendPasswordWasResetEmail ( anyString ( ) , anyString ( ) ) ;
doPost ( "/api/noauth/resetPassword" , resetPasswordRequest )
. andExpect ( status ( ) . isBadRequest ( ) )
. andExpect ( jsonPath ( "$.message" ,
is ( "Password must be no more than 72 characters in length." ) ) ) ;
}
}