Skip to content

Commit a5f6d0d

Browse files
test(auth): short-to-long pw regression coverage
Adds a short-to-long transition regression test for encryptPassword(). Verifies an existing 2048-bit existing token fails explicitly when password is storage is enabled and the password is changed to a >214-byte password. Assisted-by: Copilot:gpt-5.6-sol Signed-off-by: Josh <josh.t.richards@gmail.com>
1 parent f2f7ced commit a5f6d0d

1 file changed

Lines changed: 42 additions & 0 deletions

File tree

‎tests/lib/Authentication/Token/PublicKeyTokenProviderTest.php‎

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -385,6 +385,48 @@ public function testSetPassword(): void {
385385
$this->assertSame($newpass, $this->tokenProvider->getPassword($actual, 'tokentokentokentokentoken'));
386386
}
387387

388+
public function testSetPasswordFailsWhenExistingKeyIsTooSmall(): void {
389+
$tokenId = 'tokentokentokentokentoken';
390+
391+
$this->config->method('getSystemValueBool')
392+
->willReturnMap([
393+
['auth.storeCryptedPassword', true, true],
394+
]);
395+
396+
$token = $this->tokenProvider->generateToken(
397+
$tokenId,
398+
'user',
399+
'User',
400+
'short-password',
401+
'Test token',
402+
IToken::PERMANENT_TOKEN,
403+
IToken::DO_NOT_REMEMBER,
404+
);
405+
406+
$this->assertSame(2048, $this->getPublicKeyBits($token));
407+
408+
$this->mapper->method('getTokenByUser')
409+
->with('user')
410+
->willReturn([$token]);
411+
412+
$this->logger->expects($this->once())
413+
->method('critical')
414+
->with($this->stringStartsWith('Something is wrong with your openssl setup:'));
415+
416+
$this->mapper->expects($this->never())
417+
->method('update');
418+
419+
$this->expectException(\RuntimeException::class);
420+
$this->expectExceptionMessage('OpenSSL reported a problem');
421+
422+
$this->tokenProvider->setPassword(
423+
$token,
424+
$tokenId,
425+
// 215 = PublicKeyTokenProvider::RSA_2048_OAEP_MAX_PLAINTEXT_LENGTH + 1
426+
str_repeat('a', 215),
427+
);
428+
}
429+
388430
public function testSetPasswordInvalidToken(): void {
389431
$this->expectException(InvalidTokenException::class);
390432

0 commit comments

Comments
 (0)