Files
DodoSSH/tests/DodoSSH.Client.Session.Tests/FakeAccountServer.cs
T
jaap-jan db4a8ed3d3 Let an already-enrolled account register a device key
The first of the three pieces ADR 0007 needs, and the one that was a discovery
rather than a plan. EnrollmentService.AddDevice runs only during enrollment, so
without an endpoint the device-unlock feature would have reached accounts created
after it shipped and no others — which is to say none of the ones that exist. The
code even said so: "the devices endpoint sets it properly when it lands."

POST /api/v1/me/devices takes a name, an X25519 public key and the bundle sealed
to it, and writes a device row plus a UserKeyWrapKind.Device wrap.

Possession is proved by construction, so there is no challenge. The wrap is the
secret bundle sealed to the supplied public key, and only something that has
opened that bundle can produce it. A caller who seals the wrong bytes registers a
device that cannot unlock, which harms nobody else; the server cannot tell the
difference and must not pretend to, because it holds no key that opens either.
That is also why the client must be unlocked to call this at all.

It is the one endpoint in the /me group that requires enrollment, and it says so
itself rather than relying on the group. The group deliberately does not: GET /
and POST /enrollment are how a client discovers it needs to enroll and then does
so, and gating those on enrollment would make enrollment unreachable. Adding the
stricter policy to this route alone means an unenrolled caller is told
"enrollment-required" by the authorization handler rather than getting a 400 about
the shape of a request that was fine.

Idempotent on the public key, and 200 rather than 201 for the reason enrollment
gives: a retry of an identical request returns the same body, so there is no
single moment of creation to point a Location header at. A second row for one key
would mean a device list with a duplicate in it and two wraps to revoke instead
of one. Mutation tested — removing the lookup fails
RegisterDevice_TwiceWithTheSameKey_ReturnsTheSameDeviceAndAddsNoSecondWrap and
nothing else.

That test also found a real defect, in the way these usually surface: two
timestamps that print identically and are not equal. TimeProvider reports
100-nanosecond ticks and PostgreSQL's timestamp with time zone keeps microseconds,
so the first call returned a value that no later read of the row would ever
produce, and the idempotent retry answered with a different timestamp for the same
device. Nothing breaks, which is what makes it worth fixing: the service now
truncates to the precision the column actually holds, so the response is the same
value every time it is asked for. The repo already had a precedent for this class
of thing in KeyLogChain.TruncateTimestamp; it just had not been applied here.

The platform is deliberately not carried on the wire, which leaves
Device.Platform unreported and the stale comment corrected rather than fulfilled.
It would be a display-only field, and a Contracts enum mirroring the domain's
DevicePlatform is exactly the shape of duplication that has produced three
self-consistent bugs in this repository. A device list that wants it can add a
mapping table and a test pinning the two together, which is what the sync entity
types already do.

Its own problem code and exception rather than reusing enrollment's, whose rules
it largely shares. Registering a device is not enrolling, and a client showing
"your enrollment was rejected" because somebody set up a fingerprint reader would
be describing the wrong thing. The validation shares the limit constants —
MaximumWrapBytes, MaximumDeviceNameLength, PublicKeySize — and not the four-line
guards, which would have had to be parameterised over which exception to throw for
less than they cost.

Both in-memory fakes implement it properly rather than throwing: they record the
wrap so a test can assert it arrived, and refuse before enrollment as the real
endpoint's policy does. A fake that answered where the server refuses is a fake
that can make a real bug pass.

866 tests green, 8 of them new. Zero warnings, dotnet format clean.

Still to come: the protector seam with the wrap cached locally so device unlock
works offline, then the Windows Hello implementation and the unlock-screen UI —
which is where the Windows target framework lands and where automated testing
stops.
2026-07-30 13:18:09 +02:00

211 lines
7.7 KiB
C#

using DodoSSH.Client.Api;
using DodoSSH.Client.Auth;
using DodoSSH.Contracts;
namespace DodoSSH.Client.Session.Tests;
/// <summary>
/// An in-memory account server: just-in-time provisioning, enrollment, and <c>/me</c>.
/// </summary>
/// <remarks>
/// Stores what a real server stores and reports it back the same way, because that round trip is the
/// thing under test — the provisioner deliberately re-reads <c>/me</c> after enrolling rather than
/// caching what it believes it sent, and a stub that echoed the request would make that check vacuous.
/// <para>
/// It does not verify the identity-provider token or the grant signature. Those are the server's job and
/// are covered against a real JWT pipeline in <c>DodoSSH.Api.Tests</c>; repeating them here would test
/// this file rather than the client.
/// </para>
/// </remarks>
internal sealed class FakeAccountServer : IAccountApi
{
private KeyStatement? statement;
private byte[]? wrappedPrivateKey;
private KdfParameters? kdfParameters;
private VaultSummary? personalVault;
internal Guid UserId { get; } = Guid.Parse("0192f0c8-9999-7aaa-8bbb-cccccccccccc");
internal static string Issuer => "https://idp.example/realms/dodossh";
internal static string Subject => "alice";
/// <summary>The enrollment request as received, so a test can assert what was actually sent.</summary>
internal EnrollmentRequest? LastEnrollment { get; private set; }
internal int EnrollmentCount { get; private set; }
internal int MeCount { get; private set; }
/// <summary>Whether an identity key has been published.</summary>
internal bool IsEnrolled => statement is not null;
/// <summary>
/// Device wraps registered after enrollment, keyed on the device public key.
/// </summary>
/// <remarks>
/// Kept so a test can assert that the wrap the server received is the one the client claimed to send.
/// The server cannot open it and neither does this, which is the point: possession is proved by
/// producing it, not by anything either side checks.
/// </remarks>
internal Dictionary<string, byte[]> RegisteredDevices { get; } = new(StringComparer.Ordinal);
/// <inheritdoc />
public Task<MeResponse> GetMeAsync(CancellationToken cancellationToken)
{
MeCount++;
return Task.FromResult(new MeResponse(
UserId,
Issuer,
Subject,
"alice@example.com",
"Alice",
EnrollmentRequired: !IsEnrolled,
KeyGeneration: statement?.KeyGeneration,
WrappedPrivateKey: wrappedPrivateKey,
KdfParameters: kdfParameters,
Vaults: personalVault is null ? [] : [personalVault]));
}
/// <inheritdoc />
public Task<EnrollmentResponse> EnrollAsync(
EnrollmentRequest request,
CancellationToken cancellationToken)
{
EnrollmentCount++;
LastEnrollment = request;
if (IsEnrolled)
{
// The real server answers 409 with ProblemCodes.AlreadyEnrolled. Reproduced because the
// provisioner is supposed to never get here — it reads /me first — and a test that changed
// that should fail loudly rather than quietly enroll twice.
throw new DodoSshApiException(
System.Net.HttpStatusCode.Conflict,
ProblemCodes.AlreadyEnrolled,
"This account already has an identity key.");
}
statement = request.Statement;
wrappedPrivateKey = request.WrappedPrivateKey;
kdfParameters = request.KdfParameters;
personalVault = new VaultSummary(
request.PersonalVault.VaultId,
request.PersonalVault.Name,
IsPersonal: true,
TeamId: null,
KeyGeneration: 1,
Permissions: 31,
request.PersonalVault.WrappedVaultKey,
RekeyRequired: false);
return Task.FromResult(new EnrollmentResponse(
UserId,
KeyGeneration: 1,
Fingerprint: new byte[32],
request.PersonalVault.VaultId,
DeviceId: request.DevicePublicKey is null ? null : Guid.CreateVersion7(),
KeyLogSequence: 1));
}
/// <inheritdoc />
/// <remarks>
/// Refuses before enrollment, as the real endpoint does through <c>Auth.EnrolledPolicy</c>: there is no
/// bundle to have wrapped yet, so a wrap arriving here would be a wrap of something else. Idempotent on
/// the public key, again matching the real one.
/// </remarks>
public Task<RegisterDeviceResponse> RegisterDeviceAsync(
RegisterDeviceRequest request,
CancellationToken cancellationToken)
{
if (!IsEnrolled)
{
throw new DodoSshApiException(
System.Net.HttpStatusCode.Forbidden,
ProblemCodes.EnrollmentRequired,
"This account has no identity key yet.");
}
var key = Convert.ToHexString(request.PublicKey);
if (!RegisteredDevices.TryAdd(key, request.WrappedPrivateKey))
{
RegisteredDevices[key] = request.WrappedPrivateKey;
}
return Task.FromResult(new RegisterDeviceResponse(
DeviceId: Guid.CreateVersion7(),
EnrolledAt: DateTimeOffset.UnixEpoch));
}
/// <summary>Drops the vault grant, as a rekey does until it is re-issued.</summary>
internal void RevokeVaultGrant() =>
personalVault = personalVault is null
? null
: personalVault with { WrappedVaultKey = null, RekeyRequired = true };
}
/// <summary>
/// Stands in for the identity provider's signature over a key statement.
/// </summary>
/// <remarks>
/// Records the nonce it was asked for. That the nonce is the statement's hash is what makes the binding
/// meaningful, and it is asserted in <c>ClientEnrollmentTests</c>; here it only needs to exist.
/// </remarks>
internal sealed class StubKeyBinding : IKeyBindingAuthorizer
{
internal string? RequestedNonce { get; private set; }
public Task<string> AuthorizeKeyBindingAsync(
string bindingNonce,
CancellationToken cancellationToken)
{
RequestedNonce = bindingNonce;
return Task.FromResult("stub-id-token");
}
}
/// <summary>
/// A server with no changes in it.
/// </summary>
/// <remarks>
/// Enough to prove the session composes a working sync engine. The interesting sync behaviour lives in
/// <c>DodoSSH.Client.Sync.Tests</c> against a server that enforces version checks; duplicating that here
/// would be a third implementation of the same decision table.
/// </remarks>
internal sealed class EmptySyncApi : ISyncApi
{
internal int PushCount { get; private set; }
public Task<SyncPullResponse> SyncPullAsync(
Guid vaultId,
SyncPullRequest request,
CancellationToken cancellationToken) =>
Task.FromResult(new SyncPullResponse(
[],
request.Cursor ?? "empty-v1:0",
HasMore: false,
ServerTime: DateTimeOffset.FromUnixTimeSeconds(1_750_000_000),
CurrentKeyGeneration: 1));
public Task<SyncPushResponse> SyncPushAsync(
Guid vaultId,
SyncPushRequest request,
CancellationToken cancellationToken)
{
PushCount++;
return Task.FromResult(new SyncPushResponse(
[.. request.Operations.Select((operation, index) => new SyncPushResult(
operation.OperationId,
SyncOperationStatus.Applied,
Version: (operation.ExpectedVersion ?? 0) + 1,
ChangeSequence: index + 1,
ServerEntity: null,
Detail: null))],
"empty-v1:0"));
}
}