OLD | NEW |
1 // Copyright 2015 The Chromium Authors. All rights reserved. | 1 // Copyright 2015 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "content/common/ssl_status_serialization.h" | 5 #include "content/common/ssl_status_serialization.h" |
6 | 6 |
7 #include "net/ssl/ssl_connection_status_flags.h" | 7 #include "net/ssl/ssl_connection_status_flags.h" |
8 #include "testing/gtest/include/gtest/gtest.h" | 8 #include "testing/gtest/include/gtest/gtest.h" |
9 | 9 |
10 namespace content { | 10 namespace content { |
11 | 11 |
| 12 namespace { |
| 13 |
| 14 void SetTestStatus(SSLStatus* status) { |
| 15 status->security_style = SECURITY_STYLE_AUTHENTICATED; |
| 16 status->cert_id = 1; |
| 17 status->cert_status = net::CERT_STATUS_DATE_INVALID; |
| 18 status->security_bits = 80; |
| 19 status->key_exchange_info = 23; |
| 20 status->connection_status = net::SSL_CONNECTION_VERSION_TLS1_2; |
| 21 status->signed_certificate_timestamp_ids.push_back( |
| 22 SignedCertificateTimestampIDAndStatus(1, net::ct::SCT_STATUS_OK)); |
| 23 } |
| 24 |
| 25 bool SSLStatusAreEqual(const SSLStatus& a, const SSLStatus &b) { |
| 26 return a.Equals(b); |
| 27 } |
| 28 |
| 29 } // namespace |
| 30 |
| 31 std::ostream& operator<<(std::ostream& os, const SSLStatus& status) { |
| 32 return os << "Security Style: " << status.security_style |
| 33 << "\nCert ID: " << status.cert_id |
| 34 << "\nCert Status: " << status.cert_status |
| 35 << "\nSecurity bits: " << status.security_bits |
| 36 << "\nKey exchange info: " << status.key_exchange_info |
| 37 << "\nConnection status: " << status.connection_status |
| 38 << "\nContent Status: " << status.content_status |
| 39 << "\nNumber of SCTs: " << status.signed_certificate_timestamp_ids.size(); |
| 40 } |
| 41 |
12 // Test that a valid serialized SSLStatus returns true on | 42 // Test that a valid serialized SSLStatus returns true on |
13 // deserialization and deserializes correctly. | 43 // deserialization and deserializes correctly. |
14 TEST(SSLStatusSerializationTest, DeserializeSerializedStatus) { | 44 TEST(SSLStatusSerializationTest, DeserializeSerializedStatus) { |
15 // Serialize dummy data and test that it deserializes properly. | 45 // Serialize dummy data and test that it deserializes properly. |
16 SSLStatus status; | 46 SSLStatus status; |
17 status.security_style = SECURITY_STYLE_AUTHENTICATED; | 47 SetTestStatus(&status); |
18 status.cert_id = 1; | |
19 status.cert_status = net::CERT_STATUS_DATE_INVALID; | |
20 status.security_bits = 80; | |
21 status.connection_status = net::SSL_CONNECTION_VERSION_TLS1_2; | |
22 SignedCertificateTimestampIDAndStatus sct(1, net::ct::SCT_STATUS_OK); | |
23 status.signed_certificate_timestamp_ids.push_back(sct); | |
24 | |
25 std::string serialized = SerializeSecurityInfo(status); | 48 std::string serialized = SerializeSecurityInfo(status); |
26 | 49 |
27 SSLStatus deserialized; | 50 SSLStatus deserialized; |
28 ASSERT_TRUE(DeserializeSecurityInfo(serialized, &deserialized)); | 51 ASSERT_TRUE(DeserializeSecurityInfo(serialized, &deserialized)); |
29 EXPECT_EQ(status.security_style, deserialized.security_style); | 52 EXPECT_PRED2(SSLStatusAreEqual, status, deserialized); |
30 EXPECT_EQ(status.cert_id, deserialized.cert_id); | 53 EXPECT_EQ(SignedCertificateTimestampIDAndStatus(1, net::ct::SCT_STATUS_OK), |
31 EXPECT_EQ(status.cert_status, deserialized.cert_status); | 54 deserialized.signed_certificate_timestamp_ids[0]); |
32 EXPECT_EQ(status.security_bits, deserialized.security_bits); | |
33 EXPECT_EQ(status.connection_status, deserialized.connection_status); | |
34 EXPECT_EQ(status.signed_certificate_timestamp_ids.size(), | |
35 deserialized.signed_certificate_timestamp_ids.size()); | |
36 EXPECT_EQ(sct, deserialized.signed_certificate_timestamp_ids[0]); | |
37 // Test that |content_status| has the default (initialized) value. | 55 // Test that |content_status| has the default (initialized) value. |
38 EXPECT_EQ(SSLStatus::NORMAL_CONTENT, deserialized.content_status); | 56 EXPECT_EQ(SSLStatus::NORMAL_CONTENT, deserialized.content_status); |
39 } | 57 } |
40 | 58 |
41 // Test that an invalid serialized SSLStatus returns false on | 59 // Test that an invalid serialized SSLStatus returns false on |
42 // deserialization. | 60 // deserialization. |
43 TEST(SSLStatusSerializationTest, DeserializeBogusStatus) { | 61 TEST(SSLStatusSerializationTest, DeserializeBogusStatus) { |
44 // Test that a failure to deserialize returns false and returns | 62 // Test that a failure to deserialize returns false and returns |
45 // initialized, default data. | 63 // initialized, default data. |
46 SSLStatus invalid_deserialized; | 64 SSLStatus invalid_deserialized; |
47 ASSERT_FALSE( | 65 ASSERT_FALSE( |
48 DeserializeSecurityInfo("not an SSLStatus", &invalid_deserialized)); | 66 DeserializeSecurityInfo("not an SSLStatus", &invalid_deserialized)); |
| 67 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
| 68 } |
49 | 69 |
50 SSLStatus default_ssl_status; | 70 // Serialize a status with a bad |security_bits| value and test that |
51 EXPECT_EQ(default_ssl_status.security_style, | 71 // deserializing it fails. |
52 invalid_deserialized.security_style); | 72 TEST(SSLStatusSerializationTest, DeserializeBogusSecurityBits) { |
53 EXPECT_EQ(default_ssl_status.cert_id, invalid_deserialized.cert_id); | |
54 EXPECT_EQ(default_ssl_status.cert_status, invalid_deserialized.cert_status); | |
55 EXPECT_EQ(default_ssl_status.security_bits, | |
56 invalid_deserialized.security_bits); | |
57 EXPECT_EQ(default_ssl_status.connection_status, | |
58 invalid_deserialized.connection_status); | |
59 EXPECT_EQ(default_ssl_status.content_status, | |
60 invalid_deserialized.content_status); | |
61 EXPECT_EQ(0u, invalid_deserialized.signed_certificate_timestamp_ids.size()); | |
62 | |
63 // Serialize a status with a bad |security_bits| value and test that | |
64 // deserializing it fails. | |
65 SSLStatus status; | 73 SSLStatus status; |
66 status.security_style = SECURITY_STYLE_AUTHENTICATED; | 74 SetTestStatus(&status); |
67 status.cert_id = 1; | |
68 status.cert_status = net::CERT_STATUS_DATE_INVALID; | |
69 // |security_bits| must be <-1. (-1 means the strength is unknown, and | 75 // |security_bits| must be <-1. (-1 means the strength is unknown, and |
70 // |0 means the connection is not encrypted). | 76 // |0 means the connection is not encrypted). |
71 status.security_bits = -5; | 77 status.security_bits = -5; |
72 status.connection_status = net::SSL_CONNECTION_VERSION_TLS1_2; | 78 std::string serialized = SerializeSecurityInfo(status); |
73 SignedCertificateTimestampIDAndStatus sct(1, net::ct::SCT_STATUS_OK); | |
74 status.signed_certificate_timestamp_ids.push_back(sct); | |
75 | 79 |
| 80 SSLStatus invalid_deserialized; |
| 81 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); |
| 82 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
| 83 } |
| 84 |
| 85 // Serialize a status with a bad |key_exchange_info| value and test that |
| 86 // deserializing it fails. |
| 87 TEST(SSLStatusSerializationTest, DeserializeBogusKeyExchangeInfo) { |
| 88 SSLStatus status; |
| 89 SetTestStatus(&status); |
| 90 status.key_exchange_info = -1; |
| 91 |
| 92 SSLStatus invalid_deserialized; |
76 std::string serialized = SerializeSecurityInfo(status); | 93 std::string serialized = SerializeSecurityInfo(status); |
77 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); | 94 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); |
| 95 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
| 96 } |
78 | 97 |
79 EXPECT_EQ(default_ssl_status.security_style, | 98 // Serialize a status with a bad |security_style| value and test that |
80 invalid_deserialized.security_style); | 99 // deserializing it fails. |
81 EXPECT_EQ(default_ssl_status.cert_id, invalid_deserialized.cert_id); | 100 TEST(SSLStatusSerializationTest, DeserializeBogusSecurityStyle) { |
82 EXPECT_EQ(default_ssl_status.cert_status, invalid_deserialized.cert_status); | 101 SSLStatus status; |
83 EXPECT_EQ(default_ssl_status.security_bits, | 102 SetTestStatus(&status); |
84 invalid_deserialized.security_bits); | 103 status.security_style = static_cast<SecurityStyle>(100); |
85 EXPECT_EQ(default_ssl_status.connection_status, | 104 std::string serialized = SerializeSecurityInfo(status); |
86 invalid_deserialized.connection_status); | |
87 EXPECT_EQ(default_ssl_status.content_status, | |
88 invalid_deserialized.content_status); | |
89 EXPECT_EQ(0u, invalid_deserialized.signed_certificate_timestamp_ids.size()); | |
90 | 105 |
91 // Now serialize a status with a bad |security_style| value and test | 106 SSLStatus invalid_deserialized; |
92 // that deserializing fails. | |
93 status.security_bits = 128; | |
94 status.security_style = static_cast<SecurityStyle>(100); | |
95 serialized = SerializeSecurityInfo(status); | |
96 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); | 107 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); |
97 | 108 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
98 EXPECT_EQ(default_ssl_status.security_style, | |
99 invalid_deserialized.security_style); | |
100 EXPECT_EQ(default_ssl_status.cert_id, invalid_deserialized.cert_id); | |
101 EXPECT_EQ(default_ssl_status.cert_status, invalid_deserialized.cert_status); | |
102 EXPECT_EQ(default_ssl_status.security_bits, | |
103 invalid_deserialized.security_bits); | |
104 EXPECT_EQ(default_ssl_status.connection_status, | |
105 invalid_deserialized.connection_status); | |
106 EXPECT_EQ(default_ssl_status.content_status, | |
107 invalid_deserialized.content_status); | |
108 EXPECT_EQ(0u, invalid_deserialized.signed_certificate_timestamp_ids.size()); | |
109 } | 109 } |
110 | 110 |
111 } // namespace | 111 } // namespace |
OLD | NEW |