From e9f45a50dd3f92a4082bec6dc33c4aa0f919138a Mon Sep 17 00:00:00 2001 From: Simeon Simeonov Date: Sun, 8 Jan 2023 23:39:45 +0100 Subject: Include the tests in the sdist package --- CHANGELOG.md | 9 ++ pyproject.toml | 7 +- sphinx_conf.py | 4 +- src/otp2289/__init__.py | 2 +- test/test_generator.py | 280 ++++++++++++++++++++++++++++++++++++++++++++++++ test/test_main.py | 265 +++++++++++++++++++++++++++++++++++++++++++++ test/test_server.py | 128 ++++++++++++++++++++++ test/test_static.py | 96 +++++++++++++++++ tests/test_generator.py | 280 ------------------------------------------------ tests/test_main.py | 265 --------------------------------------------- tests/test_server.py | 128 ---------------------- tests/test_static.py | 96 ----------------- 12 files changed, 786 insertions(+), 774 deletions(-) create mode 100644 test/test_generator.py create mode 100644 test/test_main.py create mode 100644 test/test_server.py create mode 100644 test/test_static.py delete mode 100644 tests/test_generator.py delete mode 100644 tests/test_main.py delete mode 100644 tests/test_server.py delete mode 100644 tests/test_static.py diff --git a/CHANGELOG.md b/CHANGELOG.md index 6cffe69..90b2fd2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,14 @@ # Changelog +## [1.2.1](https://github.com/blackm0re/pyotp2289/tree/1.2.1) (2023-01-08) + +[Full Changelog](https://github.com/blackm0re/pyotp2289/compare/1.2.0...1.2.1) + +**Changes:** + +- Include the unit tests in the sdist package + + ## [1.2.0](https://github.com/blackm0re/pyotp2289/tree/1.2.0) (2023-01-05) [Full Changelog](https://github.com/blackm0re/pyotp2289/compare/1.1.1...1.2.0) diff --git a/pyproject.toml b/pyproject.toml index 21a01e2..272c00f 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -8,7 +8,10 @@ build-backend = "setuptools.build_meta" [tool.pytest.ini_options] -minversion = "6.0" +minversion = "7.0" testpaths = [ - "tests" + "test" +] +pythonpath = [ + "src" ] diff --git a/sphinx_conf.py b/sphinx_conf.py index 7d02133..3bef39e 100644 --- a/sphinx_conf.py +++ b/sphinx_conf.py @@ -10,8 +10,8 @@ project = 'pyotp2289' copyright = '2020-2023, Simeon Simeonov' author = 'Simeon Simeonov' -version = '1.2.0' -release = '1.2.0' +version = '1.2.1' +release = '1.2.1' # -- General configuration --------------------------------------------------- # https://www.sphinx-doc.org/en/master/usage/configuration.html#general-configuration diff --git a/src/otp2289/__init__.py b/src/otp2289/__init__.py index 4b600a0..5e51498 100644 --- a/src/otp2289/__init__.py +++ b/src/otp2289/__init__.py @@ -40,7 +40,7 @@ from .server import ( ) __author__ = 'Simeon Simeonov' -__version__ = '1.2.0' +__version__ = '1.2.1' __license__ = 'BSD 2-Clause' diff --git a/test/test_generator.py b/test/test_generator.py new file mode 100644 index 0000000..b4bb961 --- /dev/null +++ b/test/test_generator.py @@ -0,0 +1,280 @@ +# -*- coding: utf-8 -*- +# SPDX-License-Identifier: BSD-2-Clause-FreeBSD +# +# Copyright (c) 2020-2023, Simeon Simeonov +# All rights reserved. +# +# Redistribution and use in source and binary forms, with or without +# modification, are permitted provided that the following conditions +# are met: +# 1. Redistributions of source code must retain the above copyright +# notice, this list of conditions and the following disclaimer. +# 2. Redistributions in binary form must reproduce the above copyright notice, +# this list of conditions and the following disclaimer in the documentation +# and/or other materials provided with the distribution. +# +# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR +# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES +# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. +# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, +# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT +# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF +# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +"""Tests for otp2289.generator""" +import pytest + +import otp2289 + + +def test_caller_exceptions(): + """Tests the exceptions when calling an initialized object""" + gen = otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeSt', + otp2289.OTP_ALGO_MD5, + ) + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + gen.generate_otp_words('3') + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == 'Step value MUST be an int' + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + gen.generate_otp_hexdigest(-1) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == 'Step value MUST be >= 0' + with pytest.raises(otp2289.OTPChallengeException) as exc_info: + gen.generate_otp_hexdigest_from_challenge(b'md5 fbd TeSt') + assert exc_info.type is otp2289.OTPChallengeException + assert exc_info.value.args[0] == 'Challenge must be str' + with pytest.raises(otp2289.OTPChallengeException) as exc_info: + gen.generate_otp_hexdigest_from_challenge('md5 fbd TeSt') + assert exc_info.type is otp2289.OTPChallengeException + assert exc_info.value.args[0] == 'Invalid challenge' + with pytest.raises(otp2289.generator.OTPChallengeException) as exc_info: + gen.generate_otp_hexdigest_from_challenge('otp-md5 fbd TeSt') + assert exc_info.type is otp2289.generator.OTPChallengeException + assert exc_info.value.args[0] == 'Invalid challenge' + + +def test_constructor_exceptions(): + """ + Tests the exceptions when initializing a new object (in the constructor) + """ + # test the otp2289.OTPGenerator __init__ and validators + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeStø'.encode(), + otp2289.OTP_ALGO_MD5, + ) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == 'Seed must be a string' + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeStøtEsTteSTteStTest', + otp2289.OTP_ALGO_SHA1, + ) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == ( + 'The seed MUST be of 1 to 16 characters in length' + ) + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeStø', + otp2289.OTP_ALGO_SHA1, + ) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == ( + 'The seed MUST consist of purely alphanumeric characters' + ) + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeSt', + 9, + ) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == ( + 'hash_algo is not among the known algorithms' + ) + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeSt', + b'md5', + ) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == 'hash_algo must be an int or a str' + # test the package structure as well + with pytest.raises(otp2289.generator.OTPGeneratorException) as exc_info: + otp2289.generator.OTPGenerator( + 'This is a test.'.encode(), + 'TeSt', + 'foo', + ) + assert exc_info.type is otp2289.generator.OTPGeneratorException + assert exc_info.value.args[0] == ( + 'foo is not supported by this version of the hashlib module' + ) + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + otp2289.OTPGenerator('1234567', 'TeSt', otp2289.OTP_ALGO_MD5) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == 'Password must be a byte-string' + with pytest.raises(otp2289.OTPGeneratorException) as exc_info: + otp2289.OTPGenerator( + '1234567'.encode(), + 'TeSt', + otp2289.OTP_ALGO_MD5, + ) + assert exc_info.type is otp2289.OTPGeneratorException + assert exc_info.value.args[0] == 'Password must be longer than 10 bytes' + + +def test_md5(): + """ + Tests the MD5 functionality of the OTPGenerator as described in the RFC + + Those are the tests from 'RFC-2289 Appendix C - OTP Verification Examples' + """ + # We could run this in a loop, but I guess "Readability counts." + # pass='This is a test.', seed='TeSt' + gen = otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeSt', + otp2289.OTP_ALGO_MD5, + ) + res_words = gen.generate_otp_words(0) + res_hex = gen.generate_otp_hexdigest(0) + assert isinstance(res_words, str) + assert isinstance(res_hex, str) + assert res_hex == '0x9e876134d90499dd' + assert res_words == 'INCH SEA ANNE LONG AHEM TOUR' + # step 1 + assert gen.generate_otp_hexdigest(1) == '0x7965e05436f5029f' + assert gen.generate_otp_words(1) == 'EASE OIL FUM CURE AWRY AVIS' + assert gen.generate_otp_hexdigest_from_challenge('otp-md5 1 TeSt') == ( + '0x7965e05436f5029f' + ) + assert gen.generate_otp_words_from_challenge('otp-md5 1 TeSt') == ( + 'EASE OIL FUM CURE AWRY AVIS' + ) + # step 99 + assert gen.generate_otp_hexdigest(99) == '0x50fe1962c4965880' + assert gen.generate_otp_words(99) == 'BAIL TUFT BITS GANG CHEF THY' + assert gen.generate_otp_hexdigest_from_challenge('otp-md5 99 TeSt') == ( + '0x50fe1962c4965880' + ) + assert gen.generate_otp_words_from_challenge('otp-md5 99 TeSt') == ( + 'BAIL TUFT BITS GANG CHEF THY' + ) + # iterator test + hexdigests = list(gen.hexdigest_range(105)) # testing the range itself + words = list(gen.words_range(99)) + hexdigests.reverse() + words.reverse() + assert hexdigests[0] == '0x9e876134d90499dd' + assert hexdigests[1] == '0x7965e05436f5029f' + assert hexdigests[99] == '0x50fe1962c4965880' + assert words[0] == 'INCH SEA ANNE LONG AHEM TOUR' + assert words[1] == 'EASE OIL FUM CURE AWRY AVIS' + assert words[99] == 'BAIL TUFT BITS GANG CHEF THY' + # pass='AbCdEfGhIjK', seed='alpha1' + gen = otp2289.OTPGenerator( + 'AbCdEfGhIjK'.encode(), + 'alpha1', + otp2289.OTP_ALGO_MD5, + ) + assert gen.generate_otp_hexdigest(0) == '0x87066dd9644bf206' + assert gen.generate_otp_words(0) == 'FULL PEW DOWN ONCE MORT ARC' + assert gen.generate_otp_hexdigest(1) == '0x7cd34c1040add14b' + assert gen.generate_otp_words(1) == 'FACT HOOF AT FIST SITE KENT' + assert gen.generate_otp_hexdigest(99) == '0x5aa37a81f212146c' + assert gen.generate_otp_words(99) == 'BODE HOP JAKE STOW JUT RAP' + # pass="OTP's are good", seed='correct' + gen = otp2289.OTPGenerator( + "OTP's are good".encode(), + 'correct', + otp2289.OTP_ALGO_MD5, + ) + assert gen.generate_otp_hexdigest(0) == '0xf205753943de4cf9' + assert gen.generate_otp_words(0) == 'ULAN NEW ARMY FUSE SUIT EYED' + assert gen.generate_otp_hexdigest(1) == '0xddcdac956f234937' + assert gen.generate_otp_words(1) == 'SKIM CULT LOB SLAM POE HOWL' + assert gen.generate_otp_hexdigest(99) == '0xb203e28fa525be47' + assert gen.generate_otp_words(99) == 'LONG IVY JULY AJAR BOND LEE' + + +def test_sha1(): + """ + Tests the SHA-1 functionality of the OTPGenerator as described in the RFC + + Those are the tests from 'RFC-2289 Appendix C - OTP Verification Examples' + """ + # pass='This is a test.', seed='TeSt' + gen = otp2289.OTPGenerator( + 'This is a test.'.encode(), + 'TeSt', + otp2289.OTP_ALGO_SHA1, + ) + # step=0 + res_hex = gen.generate_otp_hexdigest(0) + res_words = gen.generate_otp_words(0) + assert isinstance(res_words, str) + assert isinstance(res_hex, str) + assert res_hex == '0xbb9e6ae1979d8ff4' + assert res_words == 'MILT VARY MAST OK SEES WENT' + assert gen.generate_otp_hexdigest(1) == '0x63d936639734385b' + assert gen.generate_otp_words(1) == 'CART OTTO HIVE ODE VAT NUT' + assert gen.generate_otp_hexdigest_from_challenge('otp-sha1 1 TeSt') == ( + '0x63d936639734385b' + ) + assert gen.generate_otp_words_from_challenge('otp-sha1 1 TeSt') == ( + 'CART OTTO HIVE ODE VAT NUT' + ) + assert gen.generate_otp_hexdigest(99) == '0x87fec7768b73ccf9' + assert gen.generate_otp_words(99) == 'GAFF WAIT SKID GIG SKY EYED' + assert gen.generate_otp_hexdigest_from_challenge('otp-sha1 99 TeSt') == ( + '0x87fec7768b73ccf9' + ) + assert gen.generate_otp_words_from_challenge('otp-sha1 99 TeSt') == ( + 'GAFF WAIT SKID GIG SKY EYED' + ) + # iterator test + hexdigests = list(gen.hexdigest_range(105)) + words = list(gen.words_range(99)) + hexdigests.reverse() + words.reverse() + assert hexdigests[0] == '0xbb9e6ae1979d8ff4' + assert hexdigests[1] == '0x63d936639734385b' + assert hexdigests[99] == '0x87fec7768b73ccf9' + assert words[0] == 'MILT VARY MAST OK SEES WENT' + assert words[1] == 'CART OTTO HIVE ODE VAT NUT' + assert words[99] == 'GAFF WAIT SKID GIG SKY EYED' + # pass='AbCdEfGhIjK', seed='alpha1' + gen = otp2289.OTPGenerator( + 'AbCdEfGhIjK'.encode(), + 'alpha1', + otp2289.OTP_ALGO_SHA1, + ) + assert gen.generate_otp_hexdigest(0) == '0xad85f658ebe383c9' + assert gen.generate_otp_words(0) == 'LEST OR HEEL SCOT ROB SUIT' + assert gen.generate_otp_hexdigest(1) == '0xd07ce229b5cf119b' + assert gen.generate_otp_words(1) == 'RITE TAKE GELD COST TUNE RECK' + assert gen.generate_otp_hexdigest(99) == '0x27bc71035aaf3dc6' + assert gen.generate_otp_words(99) == 'MAY STAR TIN LYON VEDA STAN' + # pass="OTP's are good", seed='correct' + gen = otp2289.OTPGenerator( + "OTP's are good".encode(), + 'correct', + otp2289.OTP_ALGO_SHA1, + ) + assert gen.generate_otp_hexdigest(0) == '0xd51f3e99bf8e6f0b' + assert gen.generate_otp_words(0) == 'RUST WELT KICK FELL TAIL FRAU' + assert gen.generate_otp_hexdigest(1) == '0x82aeb52d943774e4' + assert gen.generate_otp_words(1) == 'FLIT DOSE ALSO MEW DRUM DEFY' + assert gen.generate_otp_hexdigest(99) == '0x4f296a74fe1567ec' + assert gen.generate_otp_words(99) == 'AURA ALOE HURL WING BERG WAIT' diff --git a/test/test_main.py b/test/test_main.py new file mode 100644 index 0000000..35bd2a2 --- /dev/null +++ b/test/test_main.py @@ -0,0 +1,265 @@ +# -*- coding: utf-8 -*- +# SPDX-License-Identifier: BSD-2-Clause-FreeBSD +# +# Copyright (c) 2020-2023, Simeon Simeonov +# All rights reserved. +# +# Redistribution and use in source and binary forms, with or without +# modification, are permitted provided that the following conditions +# are met: +# 1. Redistributions of source code must retain the above copyright +# notice, this list of conditions and the following disclaimer. +# 2. Redistributions in binary form must reproduce the above copyright notice, +# this list of conditions and the following disclaimer in the documentation +# and/or other materials provided with the distribution. +# +# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR +# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES +# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. +# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, +# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT +# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF +# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +"""Tests for otp2289.__main__""" +import os +import unittest.mock + +import pytest + +from otp2289.__main__ import main + + +def test_main_generate_otp_response(capsys): + """tests main""" + args = [ + '--generate-otp-response', + '-a', + 'sha1', + '-i', + '99', + '-s', + 'TesT', + '-p', + 'This is a test.', + ] + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' + f'0x87fec7768b73ccf9{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.extend(['-f', 'token']) + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' + f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.append('-q') + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + + +def test_main_generate_otp_response_env_passwd(capsys): + """tests main by fetching password from the env. var. 'OTP2289_PASSWORD'""" + args = [ + '--generate-otp-response', + '-a', + 'sha1', + '-i', + '99', + '-s', + 'TesT', + ] + with unittest.mock.patch.dict( + os.environ, {'OTP2289_PASSWORD': 'This is a test.'} + ): + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' + f'0x87fec7768b73ccf9{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.extend(['-f', 'token']) + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' + f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.append('-q') + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + + +def test_main_generate_otp_range(capsys): + """tests main""" + args = [ + '--generate-otp-range', + '-i', + '2', + '-s', + 'TesT', + '-r', + '5', + '-p', + 'This is a test.', + ] + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'Seed: TesT, Step: 2, Hash: md5, Range: 3' + f'{os.linesep}' + f'2: 0x4049f8b161669b7b{os.linesep}' + f'1: 0x7965e05436f5029f{os.linesep}' + f'0: 0x9e876134d90499dd{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.append('-q') + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'2: 0x4049f8b161669b7b{os.linesep}' + f'1: 0x7965e05436f5029f{os.linesep}' + f'0: 0x9e876134d90499dd{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.extend(['-f', 'token']) + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'2: THY AVON NO NECK COKE MOLL{os.linesep}' + f'1: EASE OIL FUM CURE AWRY AVIS{os.linesep}' + f'0: INCH SEA ANNE LONG AHEM TOUR{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + + +@pytest.mark.parametrize( + 'args', + [ + [ + '--generate-otp-range', + '-i', + '2', + '-s', + 'TesT', + '-r', + '5', + ], + [ + '--generate-otp-range', + '-i', + '2', + '-s', + 'TesT', + '-r', + '5', + '-P', + ], + ], +) +@unittest.mock.patch('getpass.getpass', lambda *args: 'This is a test.') +def test_main_generate_otp_range_passwd_prompt(capsys, args): + """tests main by prompting for password (with or without -P)""" + args = [ + '--generate-otp-range', + '-i', + '2', + '-s', + 'TesT', + '-r', + '5', + ] + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'Seed: TesT, Step: 2, Hash: md5, Range: 3' + f'{os.linesep}' + f'2: 0x4049f8b161669b7b{os.linesep}' + f'1: 0x7965e05436f5029f{os.linesep}' + f'0: 0x9e876134d90499dd{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.append('-q') + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'2: 0x4049f8b161669b7b{os.linesep}' + f'1: 0x7965e05436f5029f{os.linesep}' + f'0: 0x9e876134d90499dd{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.extend(['-f', 'token']) + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'2: THY AVON NO NECK COKE MOLL{os.linesep}' + f'1: EASE OIL FUM CURE AWRY AVIS{os.linesep}' + f'0: INCH SEA ANNE LONG AHEM TOUR{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + + +def test_main_initiate(capsys): + """tests main""" + args = [ + '--initiate-new-sequence', + '-i', + '500', + '-s', + 'TesT', + '-p', + 'This is a test.', + ] + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == ( + f'Seed: TesT, Step: 500, Hash: md5{os.linesep}' + f'0x2b8d82b6ac14346c{os.linesep}' + ) + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 + args.append('-q') + with pytest.raises(SystemExit) as exit_info: + main(args) + captured = capsys.readouterr() + assert captured.out == f'0x2b8d82b6ac14346c{os.linesep}' + assert exit_info.type == SystemExit + assert exit_info.value.code == 0 diff --git a/test/test_server.py b/test/test_server.py new file mode 100644 index 0000000..64e7f67 --- /dev/null +++ b/test/test_server.py @@ -0,0 +1,128 @@ +# -*- coding: utf-8 -*- +# SPDX-License-Identifier: BSD-2-Clause-FreeBSD +# +# Copyright (c) 2020-2023, Simeon Simeonov +# All rights reserved. +# +# Redistribution and use in source and binary forms, with or without +# modification, are permitted provided that the following conditions +# are met: +# 1. Redistributions of source code must retain the above copyright +# notice, this list of conditions and the following disclaimer. +# 2. Redistributions in binary form must reproduce the above copyright notice, +# this list of conditions and the following disclaimer in the documentation +# and/or other materials provided with the distribution. +# +# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR +# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES +# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. +# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, +# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT +# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF +# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +"""Tests for otp2289.server""" +import json + +import pytest + +import otp2289 + + +def test_state_caller_exceptions(): + """Tests the exceptions when calling the OTPState objects""" + state = otp2289.OTPState( + '0x7965e05436f5029f', + 1, + 'TeSt', + otp2289.OTP_ALGO_MD5, + ) + with pytest.raises(otp2289.OTPInvalidResponse) as exc_info: + state.response_validates('bla') + assert exc_info.type is otp2289.OTPInvalidResponse + assert exc_info.value.args[0] == ( + 'The response is neither a valid token or hex' + ) + + +def test_state_constructor_exceptions(): + """Tests the exceptions when initializing new OTPState objects""" + with pytest.raises(otp2289.OTPStateException) as exc_info: + otp2289.OTPState( + '0x7965e05436f5029t', + 1, + 'TeStø'.encode(), + otp2289.OTP_ALGO_MD5, + ) + assert exc_info.type is otp2289.OTPStateException + assert exc_info.value.args[0] == 'Seed must be a string' + with pytest.raises(otp2289.OTPStateException) as exc_info: + otp2289.OTPState( + '0x7965e05436f5029t', + '1', + 'TeSt', + otp2289.OTP_ALGO_MD5, + ) + assert exc_info.type is otp2289.OTPStateException + assert exc_info.value.args[0] == 'Step value MUST be an int' + + +def test_state_validation_md5(): + """Tests the OTPState validation functionality for MD5""" + state = otp2289.OTPState( + '0x7965e05436f5029f', + 1, + 'TeSt', + otp2289.OTP_ALGO_MD5, + ) + assert state.validated is False + assert state.response_validates('0x9e876134d90499dd') is True + assert state.response_validates('INCH SEA ANNE LONG AHEM TOUR') is True + assert state.ot_hex == '7965e05436f5029f' + assert state.validated is True + + +def test_state_validation_sha1(): + """Tests the OTPState validation functionality for SHA1""" + state = otp2289.OTPState( + '0x63d936639734385b', + 1, + 'TeSt', + otp2289.OTP_ALGO_SHA1, + ) + assert state.validated is False + assert state.response_validates('0xbb9e6ae1979d8ff4') is True + assert state.response_validates('MILT VARY MAST OK SEES WENT') is True + assert state.ot_hex == '63d936639734385b' + assert state.validated is True + + +def test_store(): + """Tests the OTPStore functionality""" + store_data = { + 'sgs': { + 'ot_hex': '0x7965e05436f5029f', + 'current_step': 1, + 'seed': 'TeSt', + 'hash_algo': 'md5', + }, + 'blackmore': { + 'ot_hex': '0x63d936639734385b', + 'current_step': 1, + 'seed': 'TeSt', + 'hash_algo': 'sha1', + }, + } + store = otp2289.OTPStore(store_data) + assert len(store) == 2 + assert isinstance(json.dumps(store.to_dict()), str) # serializable? + assert store.response_validates('sgs', '0x9e876134d90499dd') is True + assert store.response_validates('sgs', '0x9e876134d90499dd') is False + sgs_state = store.get('sgs') + assert sgs_state in store + store.pop_state('sgs') + assert bool(store) is True + store.pop_state('blackmore') + assert bool(store) is False diff --git a/test/test_static.py b/test/test_static.py new file mode 100644 index 0000000..7635e5e --- /dev/null +++ b/test/test_static.py @@ -0,0 +1,96 @@ +# -*- coding: utf-8 -*- +# SPDX-License-Identifier: BSD-2-Clause-FreeBSD +# +# Copyright (c) 2020-2023, Simeon Simeonov +# All rights reserved. +# +# Redistribution and use in source and binary forms, with or without +# modification, are permitted provided that the following conditions +# are met: +# 1. Redistributions of source code must retain the above copyright +# notice, this list of conditions and the following disclaimer. +# 2. Redistributions in binary form must reproduce the above copyright notice, +# this list of conditions and the following disclaimer in the documentation +# and/or other materials provided with the distribution. +# +# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR +# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES +# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. +# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, +# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT +# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF +# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +"""Tests for the static methods and basic bit, byte, token functionality""" +import binascii +import os + +import otp2289 + + +def test_bytes_and_tokens(): + """Tests the official hex and tokens defined in RFC2289""" + assert binascii.unhexlify('9e876134d90499dd') == ( + otp2289.OTPGenerator.tokens_to_bytes('INCH SEA ANNE LONG AHEM TOUR') + ) + assert binascii.unhexlify('7965e05436f5029f') == ( + otp2289.OTPGenerator.tokens_to_bytes('EASE OIL FUM CURE AWRY AVIS') + ) + assert binascii.unhexlify('50fe1962c4965880') == ( + otp2289.OTPGenerator.tokens_to_bytes('BAIL TUFT BITS GANG CHEF THY') + ) + assert binascii.unhexlify('87066dd9644bf206') == ( + otp2289.OTPGenerator.tokens_to_bytes('FULL PEW DOWN ONCE MORT ARC') + ) + assert binascii.unhexlify('7cd34c1040add14b') == ( + otp2289.OTPGenerator.tokens_to_bytes('FACT HOOF AT FIST SITE KENT') + ) + assert binascii.unhexlify('5aa37a81f212146c') == ( + otp2289.OTPGenerator.tokens_to_bytes('BODE HOP JAKE STOW JUT RAP') + ) + assert binascii.unhexlify('f205753943de4cf9') == ( + otp2289.OTPGenerator.tokens_to_bytes('ULAN NEW ARMY FUSE SUIT EYED') + ) + assert binascii.unhexlify('ddcdac956f234937') == ( + otp2289.OTPGenerator.tokens_to_bytes('SKIM CULT LOB SLAM POE HOWL') + ) + assert binascii.unhexlify('b203e28fa525be47') == ( + otp2289.OTPGenerator.tokens_to_bytes('LONG IVY JULY AJAR BOND LEE') + ) + assert binascii.unhexlify('bb9e6ae1979d8ff4') == ( + otp2289.OTPGenerator.tokens_to_bytes('MILT VARY MAST OK SEES WENT') + ) + assert binascii.unhexlify('63d936639734385b') == ( + otp2289.OTPGenerator.tokens_to_bytes('CART OTTO HIVE ODE VAT NUT') + ) + assert binascii.unhexlify('87fec7768b73ccf9') == ( + otp2289.OTPGenerator.tokens_to_bytes('GAFF WAIT SKID GIG SKY EYED') + ) + assert binascii.unhexlify('ad85f658ebe383c9') == ( + otp2289.OTPGenerator.tokens_to_bytes('LEST OR HEEL SCOT ROB SUIT') + ) + assert binascii.unhexlify('d07ce229b5cf119b') == ( + otp2289.OTPGenerator.tokens_to_bytes('RITE TAKE GELD COST TUNE RECK') + ) + assert binascii.unhexlify('27bc71035aaf3dc6') == ( + otp2289.OTPGenerator.tokens_to_bytes('MAY STAR TIN LYON VEDA STAN') + ) + assert binascii.unhexlify('d51f3e99bf8e6f0b') == ( + otp2289.OTPGenerator.tokens_to_bytes('RUST WELT KICK FELL TAIL FRAU') + ) + assert binascii.unhexlify('82aeb52d943774e4') == ( + otp2289.OTPGenerator.tokens_to_bytes('FLIT DOSE ALSO MEW DRUM DEFY') + ) + assert binascii.unhexlify('4f296a74fe1567ec') == ( + otp2289.OTPGenerator.tokens_to_bytes('AURA ALOE HURL WING BERG WAIT') + ) + + +def test_random_bytes(): + """Implement a few tests with random bytes""" + for _ in range(10): + rnd_bytes = os.urandom(8) # 64 bits + tokens = otp2289.OTPGenerator.bytes_to_tokens(rnd_bytes) + assert rnd_bytes == otp2289.OTPGenerator.tokens_to_bytes(tokens) diff --git a/tests/test_generator.py b/tests/test_generator.py deleted file mode 100644 index b4bb961..0000000 --- a/tests/test_generator.py +++ /dev/null @@ -1,280 +0,0 @@ -# -*- coding: utf-8 -*- -# SPDX-License-Identifier: BSD-2-Clause-FreeBSD -# -# Copyright (c) 2020-2023, Simeon Simeonov -# All rights reserved. -# -# Redistribution and use in source and binary forms, with or without -# modification, are permitted provided that the following conditions -# are met: -# 1. Redistributions of source code must retain the above copyright -# notice, this list of conditions and the following disclaimer. -# 2. Redistributions in binary form must reproduce the above copyright notice, -# this list of conditions and the following disclaimer in the documentation -# and/or other materials provided with the distribution. -# -# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR -# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES -# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. -# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, -# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT -# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, -# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY -# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT -# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF -# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. -"""Tests for otp2289.generator""" -import pytest - -import otp2289 - - -def test_caller_exceptions(): - """Tests the exceptions when calling an initialized object""" - gen = otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeSt', - otp2289.OTP_ALGO_MD5, - ) - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - gen.generate_otp_words('3') - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == 'Step value MUST be an int' - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - gen.generate_otp_hexdigest(-1) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == 'Step value MUST be >= 0' - with pytest.raises(otp2289.OTPChallengeException) as exc_info: - gen.generate_otp_hexdigest_from_challenge(b'md5 fbd TeSt') - assert exc_info.type is otp2289.OTPChallengeException - assert exc_info.value.args[0] == 'Challenge must be str' - with pytest.raises(otp2289.OTPChallengeException) as exc_info: - gen.generate_otp_hexdigest_from_challenge('md5 fbd TeSt') - assert exc_info.type is otp2289.OTPChallengeException - assert exc_info.value.args[0] == 'Invalid challenge' - with pytest.raises(otp2289.generator.OTPChallengeException) as exc_info: - gen.generate_otp_hexdigest_from_challenge('otp-md5 fbd TeSt') - assert exc_info.type is otp2289.generator.OTPChallengeException - assert exc_info.value.args[0] == 'Invalid challenge' - - -def test_constructor_exceptions(): - """ - Tests the exceptions when initializing a new object (in the constructor) - """ - # test the otp2289.OTPGenerator __init__ and validators - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeStø'.encode(), - otp2289.OTP_ALGO_MD5, - ) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == 'Seed must be a string' - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeStøtEsTteSTteStTest', - otp2289.OTP_ALGO_SHA1, - ) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == ( - 'The seed MUST be of 1 to 16 characters in length' - ) - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeStø', - otp2289.OTP_ALGO_SHA1, - ) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == ( - 'The seed MUST consist of purely alphanumeric characters' - ) - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeSt', - 9, - ) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == ( - 'hash_algo is not among the known algorithms' - ) - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeSt', - b'md5', - ) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == 'hash_algo must be an int or a str' - # test the package structure as well - with pytest.raises(otp2289.generator.OTPGeneratorException) as exc_info: - otp2289.generator.OTPGenerator( - 'This is a test.'.encode(), - 'TeSt', - 'foo', - ) - assert exc_info.type is otp2289.generator.OTPGeneratorException - assert exc_info.value.args[0] == ( - 'foo is not supported by this version of the hashlib module' - ) - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - otp2289.OTPGenerator('1234567', 'TeSt', otp2289.OTP_ALGO_MD5) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == 'Password must be a byte-string' - with pytest.raises(otp2289.OTPGeneratorException) as exc_info: - otp2289.OTPGenerator( - '1234567'.encode(), - 'TeSt', - otp2289.OTP_ALGO_MD5, - ) - assert exc_info.type is otp2289.OTPGeneratorException - assert exc_info.value.args[0] == 'Password must be longer than 10 bytes' - - -def test_md5(): - """ - Tests the MD5 functionality of the OTPGenerator as described in the RFC - - Those are the tests from 'RFC-2289 Appendix C - OTP Verification Examples' - """ - # We could run this in a loop, but I guess "Readability counts." - # pass='This is a test.', seed='TeSt' - gen = otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeSt', - otp2289.OTP_ALGO_MD5, - ) - res_words = gen.generate_otp_words(0) - res_hex = gen.generate_otp_hexdigest(0) - assert isinstance(res_words, str) - assert isinstance(res_hex, str) - assert res_hex == '0x9e876134d90499dd' - assert res_words == 'INCH SEA ANNE LONG AHEM TOUR' - # step 1 - assert gen.generate_otp_hexdigest(1) == '0x7965e05436f5029f' - assert gen.generate_otp_words(1) == 'EASE OIL FUM CURE AWRY AVIS' - assert gen.generate_otp_hexdigest_from_challenge('otp-md5 1 TeSt') == ( - '0x7965e05436f5029f' - ) - assert gen.generate_otp_words_from_challenge('otp-md5 1 TeSt') == ( - 'EASE OIL FUM CURE AWRY AVIS' - ) - # step 99 - assert gen.generate_otp_hexdigest(99) == '0x50fe1962c4965880' - assert gen.generate_otp_words(99) == 'BAIL TUFT BITS GANG CHEF THY' - assert gen.generate_otp_hexdigest_from_challenge('otp-md5 99 TeSt') == ( - '0x50fe1962c4965880' - ) - assert gen.generate_otp_words_from_challenge('otp-md5 99 TeSt') == ( - 'BAIL TUFT BITS GANG CHEF THY' - ) - # iterator test - hexdigests = list(gen.hexdigest_range(105)) # testing the range itself - words = list(gen.words_range(99)) - hexdigests.reverse() - words.reverse() - assert hexdigests[0] == '0x9e876134d90499dd' - assert hexdigests[1] == '0x7965e05436f5029f' - assert hexdigests[99] == '0x50fe1962c4965880' - assert words[0] == 'INCH SEA ANNE LONG AHEM TOUR' - assert words[1] == 'EASE OIL FUM CURE AWRY AVIS' - assert words[99] == 'BAIL TUFT BITS GANG CHEF THY' - # pass='AbCdEfGhIjK', seed='alpha1' - gen = otp2289.OTPGenerator( - 'AbCdEfGhIjK'.encode(), - 'alpha1', - otp2289.OTP_ALGO_MD5, - ) - assert gen.generate_otp_hexdigest(0) == '0x87066dd9644bf206' - assert gen.generate_otp_words(0) == 'FULL PEW DOWN ONCE MORT ARC' - assert gen.generate_otp_hexdigest(1) == '0x7cd34c1040add14b' - assert gen.generate_otp_words(1) == 'FACT HOOF AT FIST SITE KENT' - assert gen.generate_otp_hexdigest(99) == '0x5aa37a81f212146c' - assert gen.generate_otp_words(99) == 'BODE HOP JAKE STOW JUT RAP' - # pass="OTP's are good", seed='correct' - gen = otp2289.OTPGenerator( - "OTP's are good".encode(), - 'correct', - otp2289.OTP_ALGO_MD5, - ) - assert gen.generate_otp_hexdigest(0) == '0xf205753943de4cf9' - assert gen.generate_otp_words(0) == 'ULAN NEW ARMY FUSE SUIT EYED' - assert gen.generate_otp_hexdigest(1) == '0xddcdac956f234937' - assert gen.generate_otp_words(1) == 'SKIM CULT LOB SLAM POE HOWL' - assert gen.generate_otp_hexdigest(99) == '0xb203e28fa525be47' - assert gen.generate_otp_words(99) == 'LONG IVY JULY AJAR BOND LEE' - - -def test_sha1(): - """ - Tests the SHA-1 functionality of the OTPGenerator as described in the RFC - - Those are the tests from 'RFC-2289 Appendix C - OTP Verification Examples' - """ - # pass='This is a test.', seed='TeSt' - gen = otp2289.OTPGenerator( - 'This is a test.'.encode(), - 'TeSt', - otp2289.OTP_ALGO_SHA1, - ) - # step=0 - res_hex = gen.generate_otp_hexdigest(0) - res_words = gen.generate_otp_words(0) - assert isinstance(res_words, str) - assert isinstance(res_hex, str) - assert res_hex == '0xbb9e6ae1979d8ff4' - assert res_words == 'MILT VARY MAST OK SEES WENT' - assert gen.generate_otp_hexdigest(1) == '0x63d936639734385b' - assert gen.generate_otp_words(1) == 'CART OTTO HIVE ODE VAT NUT' - assert gen.generate_otp_hexdigest_from_challenge('otp-sha1 1 TeSt') == ( - '0x63d936639734385b' - ) - assert gen.generate_otp_words_from_challenge('otp-sha1 1 TeSt') == ( - 'CART OTTO HIVE ODE VAT NUT' - ) - assert gen.generate_otp_hexdigest(99) == '0x87fec7768b73ccf9' - assert gen.generate_otp_words(99) == 'GAFF WAIT SKID GIG SKY EYED' - assert gen.generate_otp_hexdigest_from_challenge('otp-sha1 99 TeSt') == ( - '0x87fec7768b73ccf9' - ) - assert gen.generate_otp_words_from_challenge('otp-sha1 99 TeSt') == ( - 'GAFF WAIT SKID GIG SKY EYED' - ) - # iterator test - hexdigests = list(gen.hexdigest_range(105)) - words = list(gen.words_range(99)) - hexdigests.reverse() - words.reverse() - assert hexdigests[0] == '0xbb9e6ae1979d8ff4' - assert hexdigests[1] == '0x63d936639734385b' - assert hexdigests[99] == '0x87fec7768b73ccf9' - assert words[0] == 'MILT VARY MAST OK SEES WENT' - assert words[1] == 'CART OTTO HIVE ODE VAT NUT' - assert words[99] == 'GAFF WAIT SKID GIG SKY EYED' - # pass='AbCdEfGhIjK', seed='alpha1' - gen = otp2289.OTPGenerator( - 'AbCdEfGhIjK'.encode(), - 'alpha1', - otp2289.OTP_ALGO_SHA1, - ) - assert gen.generate_otp_hexdigest(0) == '0xad85f658ebe383c9' - assert gen.generate_otp_words(0) == 'LEST OR HEEL SCOT ROB SUIT' - assert gen.generate_otp_hexdigest(1) == '0xd07ce229b5cf119b' - assert gen.generate_otp_words(1) == 'RITE TAKE GELD COST TUNE RECK' - assert gen.generate_otp_hexdigest(99) == '0x27bc71035aaf3dc6' - assert gen.generate_otp_words(99) == 'MAY STAR TIN LYON VEDA STAN' - # pass="OTP's are good", seed='correct' - gen = otp2289.OTPGenerator( - "OTP's are good".encode(), - 'correct', - otp2289.OTP_ALGO_SHA1, - ) - assert gen.generate_otp_hexdigest(0) == '0xd51f3e99bf8e6f0b' - assert gen.generate_otp_words(0) == 'RUST WELT KICK FELL TAIL FRAU' - assert gen.generate_otp_hexdigest(1) == '0x82aeb52d943774e4' - assert gen.generate_otp_words(1) == 'FLIT DOSE ALSO MEW DRUM DEFY' - assert gen.generate_otp_hexdigest(99) == '0x4f296a74fe1567ec' - assert gen.generate_otp_words(99) == 'AURA ALOE HURL WING BERG WAIT' diff --git a/tests/test_main.py b/tests/test_main.py deleted file mode 100644 index 35bd2a2..0000000 --- a/tests/test_main.py +++ /dev/null @@ -1,265 +0,0 @@ -# -*- coding: utf-8 -*- -# SPDX-License-Identifier: BSD-2-Clause-FreeBSD -# -# Copyright (c) 2020-2023, Simeon Simeonov -# All rights reserved. -# -# Redistribution and use in source and binary forms, with or without -# modification, are permitted provided that the following conditions -# are met: -# 1. Redistributions of source code must retain the above copyright -# notice, this list of conditions and the following disclaimer. -# 2. Redistributions in binary form must reproduce the above copyright notice, -# this list of conditions and the following disclaimer in the documentation -# and/or other materials provided with the distribution. -# -# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR -# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES -# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. -# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, -# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT -# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, -# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY -# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT -# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF -# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. -"""Tests for otp2289.__main__""" -import os -import unittest.mock - -import pytest - -from otp2289.__main__ import main - - -def test_main_generate_otp_response(capsys): - """tests main""" - args = [ - '--generate-otp-response', - '-a', - 'sha1', - '-i', - '99', - '-s', - 'TesT', - '-p', - 'This is a test.', - ] - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' - f'0x87fec7768b73ccf9{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.extend(['-f', 'token']) - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' - f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.append('-q') - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - - -def test_main_generate_otp_response_env_passwd(capsys): - """tests main by fetching password from the env. var. 'OTP2289_PASSWORD'""" - args = [ - '--generate-otp-response', - '-a', - 'sha1', - '-i', - '99', - '-s', - 'TesT', - ] - with unittest.mock.patch.dict( - os.environ, {'OTP2289_PASSWORD': 'This is a test.'} - ): - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' - f'0x87fec7768b73ccf9{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.extend(['-f', 'token']) - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'Seed: TesT, Step: 99, Hash: sha1{os.linesep}' - f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.append('-q') - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == f'GAFF WAIT SKID GIG SKY EYED{os.linesep}' - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - - -def test_main_generate_otp_range(capsys): - """tests main""" - args = [ - '--generate-otp-range', - '-i', - '2', - '-s', - 'TesT', - '-r', - '5', - '-p', - 'This is a test.', - ] - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'Seed: TesT, Step: 2, Hash: md5, Range: 3' - f'{os.linesep}' - f'2: 0x4049f8b161669b7b{os.linesep}' - f'1: 0x7965e05436f5029f{os.linesep}' - f'0: 0x9e876134d90499dd{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.append('-q') - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'2: 0x4049f8b161669b7b{os.linesep}' - f'1: 0x7965e05436f5029f{os.linesep}' - f'0: 0x9e876134d90499dd{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.extend(['-f', 'token']) - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'2: THY AVON NO NECK COKE MOLL{os.linesep}' - f'1: EASE OIL FUM CURE AWRY AVIS{os.linesep}' - f'0: INCH SEA ANNE LONG AHEM TOUR{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - - -@pytest.mark.parametrize( - 'args', - [ - [ - '--generate-otp-range', - '-i', - '2', - '-s', - 'TesT', - '-r', - '5', - ], - [ - '--generate-otp-range', - '-i', - '2', - '-s', - 'TesT', - '-r', - '5', - '-P', - ], - ], -) -@unittest.mock.patch('getpass.getpass', lambda *args: 'This is a test.') -def test_main_generate_otp_range_passwd_prompt(capsys, args): - """tests main by prompting for password (with or without -P)""" - args = [ - '--generate-otp-range', - '-i', - '2', - '-s', - 'TesT', - '-r', - '5', - ] - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'Seed: TesT, Step: 2, Hash: md5, Range: 3' - f'{os.linesep}' - f'2: 0x4049f8b161669b7b{os.linesep}' - f'1: 0x7965e05436f5029f{os.linesep}' - f'0: 0x9e876134d90499dd{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.append('-q') - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'2: 0x4049f8b161669b7b{os.linesep}' - f'1: 0x7965e05436f5029f{os.linesep}' - f'0: 0x9e876134d90499dd{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.extend(['-f', 'token']) - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'2: THY AVON NO NECK COKE MOLL{os.linesep}' - f'1: EASE OIL FUM CURE AWRY AVIS{os.linesep}' - f'0: INCH SEA ANNE LONG AHEM TOUR{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - - -def test_main_initiate(capsys): - """tests main""" - args = [ - '--initiate-new-sequence', - '-i', - '500', - '-s', - 'TesT', - '-p', - 'This is a test.', - ] - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == ( - f'Seed: TesT, Step: 500, Hash: md5{os.linesep}' - f'0x2b8d82b6ac14346c{os.linesep}' - ) - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 - args.append('-q') - with pytest.raises(SystemExit) as exit_info: - main(args) - captured = capsys.readouterr() - assert captured.out == f'0x2b8d82b6ac14346c{os.linesep}' - assert exit_info.type == SystemExit - assert exit_info.value.code == 0 diff --git a/tests/test_server.py b/tests/test_server.py deleted file mode 100644 index 64e7f67..0000000 --- a/tests/test_server.py +++ /dev/null @@ -1,128 +0,0 @@ -# -*- coding: utf-8 -*- -# SPDX-License-Identifier: BSD-2-Clause-FreeBSD -# -# Copyright (c) 2020-2023, Simeon Simeonov -# All rights reserved. -# -# Redistribution and use in source and binary forms, with or without -# modification, are permitted provided that the following conditions -# are met: -# 1. Redistributions of source code must retain the above copyright -# notice, this list of conditions and the following disclaimer. -# 2. Redistributions in binary form must reproduce the above copyright notice, -# this list of conditions and the following disclaimer in the documentation -# and/or other materials provided with the distribution. -# -# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR -# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES -# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. -# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, -# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT -# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, -# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY -# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT -# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF -# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. -"""Tests for otp2289.server""" -import json - -import pytest - -import otp2289 - - -def test_state_caller_exceptions(): - """Tests the exceptions when calling the OTPState objects""" - state = otp2289.OTPState( - '0x7965e05436f5029f', - 1, - 'TeSt', - otp2289.OTP_ALGO_MD5, - ) - with pytest.raises(otp2289.OTPInvalidResponse) as exc_info: - state.response_validates('bla') - assert exc_info.type is otp2289.OTPInvalidResponse - assert exc_info.value.args[0] == ( - 'The response is neither a valid token or hex' - ) - - -def test_state_constructor_exceptions(): - """Tests the exceptions when initializing new OTPState objects""" - with pytest.raises(otp2289.OTPStateException) as exc_info: - otp2289.OTPState( - '0x7965e05436f5029t', - 1, - 'TeStø'.encode(), - otp2289.OTP_ALGO_MD5, - ) - assert exc_info.type is otp2289.OTPStateException - assert exc_info.value.args[0] == 'Seed must be a string' - with pytest.raises(otp2289.OTPStateException) as exc_info: - otp2289.OTPState( - '0x7965e05436f5029t', - '1', - 'TeSt', - otp2289.OTP_ALGO_MD5, - ) - assert exc_info.type is otp2289.OTPStateException - assert exc_info.value.args[0] == 'Step value MUST be an int' - - -def test_state_validation_md5(): - """Tests the OTPState validation functionality for MD5""" - state = otp2289.OTPState( - '0x7965e05436f5029f', - 1, - 'TeSt', - otp2289.OTP_ALGO_MD5, - ) - assert state.validated is False - assert state.response_validates('0x9e876134d90499dd') is True - assert state.response_validates('INCH SEA ANNE LONG AHEM TOUR') is True - assert state.ot_hex == '7965e05436f5029f' - assert state.validated is True - - -def test_state_validation_sha1(): - """Tests the OTPState validation functionality for SHA1""" - state = otp2289.OTPState( - '0x63d936639734385b', - 1, - 'TeSt', - otp2289.OTP_ALGO_SHA1, - ) - assert state.validated is False - assert state.response_validates('0xbb9e6ae1979d8ff4') is True - assert state.response_validates('MILT VARY MAST OK SEES WENT') is True - assert state.ot_hex == '63d936639734385b' - assert state.validated is True - - -def test_store(): - """Tests the OTPStore functionality""" - store_data = { - 'sgs': { - 'ot_hex': '0x7965e05436f5029f', - 'current_step': 1, - 'seed': 'TeSt', - 'hash_algo': 'md5', - }, - 'blackmore': { - 'ot_hex': '0x63d936639734385b', - 'current_step': 1, - 'seed': 'TeSt', - 'hash_algo': 'sha1', - }, - } - store = otp2289.OTPStore(store_data) - assert len(store) == 2 - assert isinstance(json.dumps(store.to_dict()), str) # serializable? - assert store.response_validates('sgs', '0x9e876134d90499dd') is True - assert store.response_validates('sgs', '0x9e876134d90499dd') is False - sgs_state = store.get('sgs') - assert sgs_state in store - store.pop_state('sgs') - assert bool(store) is True - store.pop_state('blackmore') - assert bool(store) is False diff --git a/tests/test_static.py b/tests/test_static.py deleted file mode 100644 index 7635e5e..0000000 --- a/tests/test_static.py +++ /dev/null @@ -1,96 +0,0 @@ -# -*- coding: utf-8 -*- -# SPDX-License-Identifier: BSD-2-Clause-FreeBSD -# -# Copyright (c) 2020-2023, Simeon Simeonov -# All rights reserved. -# -# Redistribution and use in source and binary forms, with or without -# modification, are permitted provided that the following conditions -# are met: -# 1. Redistributions of source code must retain the above copyright -# notice, this list of conditions and the following disclaimer. -# 2. Redistributions in binary form must reproduce the above copyright notice, -# this list of conditions and the following disclaimer in the documentation -# and/or other materials provided with the distribution. -# -# THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR -# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES -# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. -# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, -# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT -# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, -# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY -# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT -# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF -# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. -"""Tests for the static methods and basic bit, byte, token functionality""" -import binascii -import os - -import otp2289 - - -def test_bytes_and_tokens(): - """Tests the official hex and tokens defined in RFC2289""" - assert binascii.unhexlify('9e876134d90499dd') == ( - otp2289.OTPGenerator.tokens_to_bytes('INCH SEA ANNE LONG AHEM TOUR') - ) - assert binascii.unhexlify('7965e05436f5029f') == ( - otp2289.OTPGenerator.tokens_to_bytes('EASE OIL FUM CURE AWRY AVIS') - ) - assert binascii.unhexlify('50fe1962c4965880') == ( - otp2289.OTPGenerator.tokens_to_bytes('BAIL TUFT BITS GANG CHEF THY') - ) - assert binascii.unhexlify('87066dd9644bf206') == ( - otp2289.OTPGenerator.tokens_to_bytes('FULL PEW DOWN ONCE MORT ARC') - ) - assert binascii.unhexlify('7cd34c1040add14b') == ( - otp2289.OTPGenerator.tokens_to_bytes('FACT HOOF AT FIST SITE KENT') - ) - assert binascii.unhexlify('5aa37a81f212146c') == ( - otp2289.OTPGenerator.tokens_to_bytes('BODE HOP JAKE STOW JUT RAP') - ) - assert binascii.unhexlify('f205753943de4cf9') == ( - otp2289.OTPGenerator.tokens_to_bytes('ULAN NEW ARMY FUSE SUIT EYED') - ) - assert binascii.unhexlify('ddcdac956f234937') == ( - otp2289.OTPGenerator.tokens_to_bytes('SKIM CULT LOB SLAM POE HOWL') - ) - assert binascii.unhexlify('b203e28fa525be47') == ( - otp2289.OTPGenerator.tokens_to_bytes('LONG IVY JULY AJAR BOND LEE') - ) - assert binascii.unhexlify('bb9e6ae1979d8ff4') == ( - otp2289.OTPGenerator.tokens_to_bytes('MILT VARY MAST OK SEES WENT') - ) - assert binascii.unhexlify('63d936639734385b') == ( - otp2289.OTPGenerator.tokens_to_bytes('CART OTTO HIVE ODE VAT NUT') - ) - assert binascii.unhexlify('87fec7768b73ccf9') == ( - otp2289.OTPGenerator.tokens_to_bytes('GAFF WAIT SKID GIG SKY EYED') - ) - assert binascii.unhexlify('ad85f658ebe383c9') == ( - otp2289.OTPGenerator.tokens_to_bytes('LEST OR HEEL SCOT ROB SUIT') - ) - assert binascii.unhexlify('d07ce229b5cf119b') == ( - otp2289.OTPGenerator.tokens_to_bytes('RITE TAKE GELD COST TUNE RECK') - ) - assert binascii.unhexlify('27bc71035aaf3dc6') == ( - otp2289.OTPGenerator.tokens_to_bytes('MAY STAR TIN LYON VEDA STAN') - ) - assert binascii.unhexlify('d51f3e99bf8e6f0b') == ( - otp2289.OTPGenerator.tokens_to_bytes('RUST WELT KICK FELL TAIL FRAU') - ) - assert binascii.unhexlify('82aeb52d943774e4') == ( - otp2289.OTPGenerator.tokens_to_bytes('FLIT DOSE ALSO MEW DRUM DEFY') - ) - assert binascii.unhexlify('4f296a74fe1567ec') == ( - otp2289.OTPGenerator.tokens_to_bytes('AURA ALOE HURL WING BERG WAIT') - ) - - -def test_random_bytes(): - """Implement a few tests with random bytes""" - for _ in range(10): - rnd_bytes = os.urandom(8) # 64 bits - tokens = otp2289.OTPGenerator.bytes_to_tokens(rnd_bytes) - assert rnd_bytes == otp2289.OTPGenerator.tokens_to_bytes(tokens) -- cgit v1.3