|
28 | 28 | emptyKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { return nil, nil }
|
29 | 29 | errorKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { return nil, errKeyFuncError }
|
30 | 30 | nilKeyFunc jwt.Keyfunc = nil
|
| 31 | + multipleZeroKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { return []interface{}{}, nil } |
| 32 | + multipleEmptyKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { |
| 33 | + return jwt.VerificationKeySet{Keys: []jwt.VerificationKey{nil, nil}}, nil |
| 34 | + } |
| 35 | + multipleVerificationKeysFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { |
| 36 | + return []jwt.VerificationKey{jwtTestDefaultKey, jwtTestEC256PublicKey}, nil |
| 37 | + } |
| 38 | + multipleLastKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { |
| 39 | + return jwt.VerificationKeySet{Keys: []jwt.VerificationKey{jwtTestEC256PublicKey, jwtTestDefaultKey}}, nil |
| 40 | + } |
| 41 | + multipleFirstKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { |
| 42 | + return jwt.VerificationKeySet{Keys: []jwt.VerificationKey{jwtTestDefaultKey, jwtTestEC256PublicKey}}, nil |
| 43 | + } |
| 44 | + multipleAltTypedKeyFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { |
| 45 | + return jwt.VerificationKeySet{Keys: []jwt.VerificationKey{jwtTestDefaultKey, jwtTestDefaultKey}}, nil |
| 46 | + } |
| 47 | + emptyVerificationKeySetFunc jwt.Keyfunc = func(t *jwt.Token) (interface{}, error) { |
| 48 | + return jwt.VerificationKeySet{}, nil |
| 49 | + } |
31 | 50 | )
|
32 | 51 |
|
33 | 52 | func init() {
|
@@ -94,6 +113,46 @@ var jwtTestData = []struct {
|
94 | 113 | nil,
|
95 | 114 | jwt.SigningMethodRS256,
|
96 | 115 | },
|
| 116 | + { |
| 117 | + "multiple keys, last matches", |
| 118 | + "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg", |
| 119 | + multipleLastKeyFunc, |
| 120 | + jwt.MapClaims{"foo": "bar"}, |
| 121 | + true, |
| 122 | + nil, |
| 123 | + nil, |
| 124 | + jwt.SigningMethodRS256, |
| 125 | + }, |
| 126 | + { |
| 127 | + "multiple keys not []interface{} type, all match", |
| 128 | + "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg", |
| 129 | + multipleAltTypedKeyFunc, |
| 130 | + jwt.MapClaims{"foo": "bar"}, |
| 131 | + true, |
| 132 | + nil, |
| 133 | + nil, |
| 134 | + jwt.SigningMethodRS256, |
| 135 | + }, |
| 136 | + { |
| 137 | + "multiple keys, first matches", |
| 138 | + "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg", |
| 139 | + multipleFirstKeyFunc, |
| 140 | + jwt.MapClaims{"foo": "bar"}, |
| 141 | + true, |
| 142 | + nil, |
| 143 | + nil, |
| 144 | + jwt.SigningMethodRS256, |
| 145 | + }, |
| 146 | + { |
| 147 | + "public keys slice, not allowed", |
| 148 | + "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg", |
| 149 | + multipleVerificationKeysFunc, |
| 150 | + jwt.MapClaims{"foo": "bar"}, |
| 151 | + false, |
| 152 | + []error{jwt.ErrTokenSignatureInvalid}, |
| 153 | + nil, |
| 154 | + jwt.SigningMethodRS256, |
| 155 | + }, |
97 | 156 | {
|
98 | 157 | "basic expired",
|
99 | 158 | "", // autogen
|
@@ -154,6 +213,36 @@ var jwtTestData = []struct {
|
154 | 213 | nil,
|
155 | 214 | jwt.SigningMethodRS256,
|
156 | 215 | },
|
| 216 | + { |
| 217 | + "multiple nokey", |
| 218 | + "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg", |
| 219 | + multipleEmptyKeyFunc, |
| 220 | + jwt.MapClaims{"foo": "bar"}, |
| 221 | + false, |
| 222 | + []error{jwt.ErrTokenSignatureInvalid}, |
| 223 | + nil, |
| 224 | + jwt.SigningMethodRS256, |
| 225 | + }, |
| 226 | + { |
| 227 | + "empty verification key set", |
| 228 | + "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg", |
| 229 | + emptyVerificationKeySetFunc, |
| 230 | + jwt.MapClaims{"foo": "bar"}, |
| 231 | + false, |
| 232 | + []error{jwt.ErrTokenUnverifiable}, |
| 233 | + nil, |
| 234 | + jwt.SigningMethodRS256, |
| 235 | + }, |
| 236 | + { |
| 237 | + "zero length key list", |
| 238 | + "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg", |
| 239 | + multipleZeroKeyFunc, |
| 240 | + jwt.MapClaims{"foo": "bar"}, |
| 241 | + false, |
| 242 | + []error{jwt.ErrTokenSignatureInvalid}, |
| 243 | + nil, |
| 244 | + jwt.SigningMethodRS256, |
| 245 | + }, |
157 | 246 | {
|
158 | 247 | "basic errorkey",
|
159 | 248 | "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJmb28iOiJiYXIifQ.FhkiHkoESI_cG3NPigFrxEk9Z60_oXrOT2vGm9Pn6RDgYNovYORQmmA0zs1AoAOf09ly2Nx2YAg6ABqAYga1AcMFkJljwxTT5fYphTuqpWdy4BELeSYJx5Ty2gmr8e7RonuUztrdD5WfPqLKMm1Ozp_T6zALpRmwTIW0QPnaBXaQD90FplAg46Iy1UlDKr-Eupy0i5SLch5Q-p2ZpaL_5fnTIUDlxC3pWhJTyx_71qDI-mAA_5lE_VdroOeflG56sSmDxopPEG3bFlSu1eowyBfxtu0_CuVd-M42RU75Zc4Gsj6uV77MBtbMrf4_7M_NUTSgoIF3fRqxrj0NzihIBg",
|
|
0 commit comments