Project

General

Profile

Download (5.67 KB) Statistics
| Branch: | Tag: | Revision:
1
/**
2
* Copyright (C) 2021 EDIT
3
* European Distributed Institute of Taxonomy
4
* http://www.e-taxonomy.eu
5
*
6
* The contents of this file are subject to the Mozilla Public License Version 1.1
7
* See LICENSE.TXT at the top of this package for the full license terms.
8
*/
9
package eu.etaxonomy.cdm.api.service.security;
10

    
11
import static org.junit.Assert.assertEquals;
12
import static org.junit.Assert.assertNotNull;
13
import static org.junit.Assert.assertTrue;
14

    
15
import java.io.FileNotFoundException;
16
import java.util.concurrent.CountDownLatch;
17
import java.util.regex.Matcher;
18
import java.util.regex.Pattern;
19

    
20
import javax.mail.internet.MimeMessage;
21

    
22
import org.junit.After;
23
import org.junit.Before;
24
import org.junit.Test;
25
import org.springframework.mail.javamail.JavaMailSender;
26
import org.springframework.util.concurrent.ListenableFuture;
27
import org.subethamail.wiser.Wiser;
28
import org.subethamail.wiser.WiserMessage;
29
import org.unitils.dbunit.annotation.DataSet;
30
import org.unitils.spring.annotation.SpringBeanByType;
31

    
32
import eu.etaxonomy.cdm.api.security.IPasswordResetTokenStore;
33
import eu.etaxonomy.cdm.api.security.PasswordResetTokenStore;
34
import eu.etaxonomy.cdm.api.service.IUserService;
35
import eu.etaxonomy.cdm.model.permission.User;
36
import eu.etaxonomy.cdm.test.unitils.CleanSweepInsertLoadStrategy;
37

    
38
/**
39
 * @author a.kohlbecker
40
 * @since Nov 8, 2021
41
 */
42
public class PasswordResetServiceTest extends eu.etaxonomy.cdm.test.integration.CdmTransactionalIntegrationTest {
43

    
44
    private static final String userName = "pwdResetTestUser";
45
    private static final String userPWD = "super_SECURE_123";
46
    private static final String newPWD = "NEW_123_new_456";
47
    private static final String userEmail = "pwdResetTestUser@cybertaxonomy.test";
48

    
49

    
50
    private static String base64UrlSaveCharClass = "[a-zA-Z0-9\\-_]";
51

    
52

    
53
    private static final String requestFormUrlTemplate = "http://cybertaxonomy.test/passwordReset?userName={%s}&sessID=f8d8sf8dsf";
54

    
55
    @SpringBeanByType
56
    private IUserService userService;
57

    
58
    @SpringBeanByType
59
    private IPasswordResetService passwordResetService;
60

    
61
    @SpringBeanByType
62
    private IPasswordResetTokenStore passwordResetTokenStore;
63

    
64
    @SpringBeanByType
65
    private JavaMailSender emailSender;
66

    
67
    private Wiser wiser = null;
68

    
69
    CountDownLatch resetTokenSendSignal;
70
    CountDownLatch passwordChangedSignal;
71
    Throwable assyncError = null;
72

    
73
    @Before
74
    public void startEmailServer() {
75
        wiser = new Wiser();
76
        wiser.setPort(2500); // Default is 25
77
        wiser.start();
78
    }
79

    
80

    
81
    @Before
82
    public void createUser() {
83
        User user = User.NewInstance(userName, userPWD);
84
        user.setEmailAddress(userEmail);
85
        userService.save(user);
86
        commitAndStartNewTransaction();
87
        // printDataSet(System.err, "User");
88

    
89
    }
90

    
91
    @After
92
    public void removeUser() {
93
        userService.deleteUser(userName);
94
        userService.getSession().flush();
95
        commitAndStartNewTransaction();
96
    }
97

    
98
    @After
99
    public void stopEmailServer() {
100
        wiser.stop();
101
    }
102

    
103
    @Test
104
    @DataSet(loadStrategy = CleanSweepInsertLoadStrategy.class, value="/eu/etaxonomy/cdm/database/ClearDBDataSet.xml")
105
    public void testSuccessfulEmailReset() throws Throwable {
106

    
107
        // printDataSet(System.err, "UserAccount");
108

    
109
        resetTokenSendSignal = new CountDownLatch(1);
110
        passwordChangedSignal = new CountDownLatch(1);
111

    
112
        ListenableFuture<Boolean> emailResetFuture = passwordResetService.emailResetToken(userName, requestFormUrlTemplate);
113
        emailResetFuture.addCallback(
114
                requestSuccessVal -> {
115
                    resetTokenSendSignal.countDown();
116
                }, futureException -> {
117
                    assyncError = futureException;
118
                    resetTokenSendSignal.countDown();
119
                });
120

    
121
        // -- wait for passwordResetService.emailResetToken() to complete
122
        resetTokenSendSignal.await();
123

    
124
        if(assyncError != null) {
125
            throw assyncError;
126
        }
127

    
128
        assertNotNull(emailResetFuture.get());
129
        assertEquals(1, wiser.getMessages().size());
130

    
131
        // -- read email message
132
        WiserMessage requestMessage = wiser.getMessages().get(0);
133
        MimeMessage requestMimeMessage = requestMessage.getMimeMessage();
134
        assertEquals(PasswordResetService.RESET_REQUEST_EMAIL_SUBJECT_TEMPLATE.replace("${userName}", userName), requestMimeMessage.getSubject());
135

    
136
        String messageContent = requestMimeMessage.getContent().toString();
137
        // -- extract token
138
        Pattern pattern = Pattern.compile("=\\{(" + base64UrlSaveCharClass + "+)\\}");
139
        Matcher m = pattern.matcher(messageContent);
140
        assertTrue(m.find());
141
        assertEquals(PasswordResetTokenStore.TOKEN_LENGTH + 17, m.group(1).length());
142

    
143
        // -- change password
144
        ListenableFuture<Boolean> resetPasswordFuture = passwordResetService.resetPassword( m.group(1), newPWD);
145
        resetPasswordFuture.addCallback(requestSuccessVal -> {
146
            passwordChangedSignal.countDown();
147
        }, futureException -> {
148
            assyncError =  futureException;
149
            passwordChangedSignal.countDown();
150
        });
151
        // -- wait for passwordResetService.resetPassword to complete
152
        passwordChangedSignal.await();
153

    
154
        assertTrue(resetPasswordFuture.get());
155
        assertEquals(2, wiser.getMessages().size());
156
        WiserMessage successMessage = wiser.getMessages().get(1);
157
        MimeMessage successMimeMessage = successMessage.getMimeMessage();
158
        assertEquals(PasswordResetService.RESET_SUCCESS_EMAIL_SUBJECT_TEMPLATE.replace("${userName}", userName), successMimeMessage.getSubject());
159

    
160
    }
161

    
162

    
163
    @Override
164
    public void createTestDataSet() throws FileNotFoundException {
165
        // not needed
166
    }
167

    
168
}
    (1-1/1)