AuthKeychainServicesTests.swift 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198
  1. // Copyright 2023 Google LLC
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. // TODO(ncooke3): Add documentation for manually configuring tests on macOS.
  15. import Foundation
  16. import XCTest
  17. @testable import FirebaseAuth
  18. @available(iOS 13, tvOS 13, macOS 10.15, macCatalyst 13, watchOS 7, *)
  19. class AuthKeychainServicesTests: XCTestCase {
  20. static let accountPrefix = "firebase_auth_1_"
  21. static let key = "ACCOUNT"
  22. static let service = "SERVICE"
  23. static let otherService = "OTHER_SERVICE"
  24. static let data = "DATA"
  25. static let otherData = "OTHER_DATA"
  26. static var account: String {
  27. accountPrefix + key
  28. }
  29. var keychain: AuthKeychainServices!
  30. #if (os(macOS) && !FIREBASE_AUTH_TESTING_USE_MACOS_KEYCHAIN) || SWIFT_PACKAGE
  31. let storage: AuthKeychainStorage = FakeAuthKeychainStorage()
  32. #else
  33. let storage: AuthKeychainStorage = AuthKeychainStorageReal.shared
  34. #endif // (os(macOS) && !FIREBASE_AUTH_TESTING_USE_MACOS_KEYCHAIN) || SWIFT_PACKAGE
  35. override func setUp() {
  36. super.setUp()
  37. keychain = AuthKeychainServices(service: Self.service, storage: storage)
  38. }
  39. func testReadNonexisting() throws {
  40. setPassword(nil, account: Self.account, service: Self.service)
  41. setPassword(nil, account: Self.key, service: nil) // Legacy form.
  42. XCTAssertNil(try keychain.data(forKey: Self.key))
  43. }
  44. func testReadExisting() throws {
  45. setPassword(Self.data, account: Self.account, service: Self.service)
  46. XCTAssertEqual(try keychain.data(forKey: Self.key), Self.data.data(using: .utf8))
  47. deletePassword(account: Self.account, service: Self.service)
  48. }
  49. func testNotReadOtherService() throws {
  50. setPassword(nil, account: Self.account, service: Self.service)
  51. setPassword(Self.data, account: Self.account, service: Self.otherService)
  52. XCTAssertNil(try keychain.data(forKey: Self.key))
  53. deletePassword(account: Self.account, service: Self.otherService)
  54. }
  55. func testWriteNonexisting() throws {
  56. setPassword(nil, account: Self.account, service: Self.service)
  57. XCTAssertNoThrow(try keychain.setData(Self.data.data(using: .utf8)!, forKey: Self.key))
  58. XCTAssertEqual(password(for: Self.account, service: Self.service), Self.data)
  59. deletePassword(account: Self.account, service: Self.service)
  60. }
  61. func testWriteExisting() throws {
  62. setPassword(Self.data, account: Self.account, service: Self.service)
  63. XCTAssertNoThrow(try keychain.setData(Self.otherData.data(using: .utf8)!, forKey: Self.key))
  64. XCTAssertEqual(password(for: Self.account, service: Self.service), Self.otherData)
  65. deletePassword(account: Self.account, service: Self.service)
  66. }
  67. func testDeleteNonexisting() {
  68. setPassword(nil, account: Self.account, service: Self.service)
  69. XCTAssertNoThrow(try keychain.removeData(forKey: Self.key))
  70. XCTAssertNil(password(for: Self.account, service: Self.service))
  71. }
  72. func testDeleteExisting() throws {
  73. setPassword(Self.data, account: Self.account, service: Self.service)
  74. XCTAssertNoThrow(try keychain.removeData(forKey: Self.key))
  75. XCTAssertNil(password(for: Self.account, service: Self.service))
  76. }
  77. func testReadLegacy() throws {
  78. setPassword(nil, account: Self.account, service: Self.service)
  79. setPassword(Self.data, account: Self.key, service: nil) // Legacy form.
  80. XCTAssertEqual(
  81. try keychain.data(forKey: Self.key), Self.data.data(using: .utf8)
  82. )
  83. // Legacy item should have been moved to current form.
  84. XCTAssertEqual(
  85. password(for: Self.account, service: Self.service),
  86. Self.data
  87. )
  88. XCTAssertNil(password(for: Self.key, service: nil), Self.data)
  89. deletePassword(account: Self.account, service: Self.service)
  90. }
  91. func testNotReadLegacy() throws {
  92. setPassword(Self.data, account: Self.account, service: Self.service)
  93. setPassword(Self.otherData, account: Self.key, service: nil) // Legacy form.
  94. XCTAssertEqual(try keychain.data(forKey: Self.key), Self.data.data(using: .utf8)!)
  95. // Legacy item should have leave untouched.
  96. XCTAssertEqual(password(for: Self.account, service: Self.service), Self.data)
  97. XCTAssertEqual(password(for: Self.key, service: nil), Self.otherData)
  98. deletePassword(account: Self.account, service: Self.service)
  99. deletePassword(account: Self.key, service: nil)
  100. }
  101. func testRemoveLegacy() throws {
  102. setPassword(Self.data, account: Self.account, service: Self.service)
  103. setPassword(Self.otherData, account: Self.key, service: nil) // Legacy form.
  104. XCTAssertNoThrow(try keychain.removeData(forKey: Self.key))
  105. XCTAssertNil(password(for: Self.account, service: Self.service))
  106. XCTAssertNil(password(for: Self.key, service: nil))
  107. }
  108. func testNullErrorParameter() throws {
  109. _ = try keychain.data(forKey: Self.key)
  110. try keychain.setData(Self.data.data(using: .utf8)!, forKey: Self.key)
  111. try keychain.removeData(forKey: Self.key)
  112. }
  113. // MARK: - Test Helpers
  114. private func password(for account: String, service: String?) -> String? {
  115. var query: [CFString: Any] = [
  116. kSecReturnData: true,
  117. kSecClass: kSecClassGenericPassword,
  118. kSecAttrAccount: account,
  119. ]
  120. if let service {
  121. query[kSecAttrService] = service
  122. }
  123. var result: CFTypeRef?
  124. let status = storage.get(query: query as [String: Any], result: &result)
  125. guard let result = result as? Data, status != errSecItemNotFound else {
  126. if let resultArray = result as? [[String: Any]],
  127. let data = resultArray[0]["v_Data"] as? Data {
  128. XCTAssertEqual(status, errSecSuccess)
  129. return String(data: data, encoding: .utf8)
  130. }
  131. return nil
  132. }
  133. XCTAssertEqual(status, errSecSuccess)
  134. return String(data: result, encoding: .utf8)
  135. }
  136. private func addPassword(_ password: String,
  137. account: String,
  138. service: String?) {
  139. var query: [CFString: Any] = [
  140. kSecValueData: password.data(using: .utf8)!,
  141. kSecClass: kSecClassGenericPassword,
  142. kSecAttrAccount: account,
  143. ]
  144. if let service {
  145. query[kSecAttrService] = service
  146. }
  147. XCTAssertEqual(storage.add(query: query as [String: Any]), errSecSuccess)
  148. }
  149. private func setPassword(_ password: String?,
  150. account: String,
  151. service: String?) {
  152. if self.password(for: account, service: service) != nil {
  153. deletePassword(account: account, service: service)
  154. }
  155. if let password {
  156. addPassword(password, account: account, service: service)
  157. }
  158. }
  159. private func deletePassword(account: String,
  160. service: String?) {
  161. var query: [CFString: Any] = [
  162. kSecClass: kSecClassGenericPassword,
  163. kSecAttrAccount: account,
  164. ]
  165. if let service {
  166. query[kSecAttrService] = service
  167. }
  168. XCTAssertEqual(storage.delete(query: query as [String: Any]), errSecSuccess)
  169. }
  170. }