| OLD | NEW |
| 1 // Copyright 2015 The Chromium Authors. All rights reserved. | 1 // Copyright 2015 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "content/common/ssl_status_serialization.h" | 5 #include "content/common/ssl_status_serialization.h" |
| 6 | 6 |
| 7 #include "net/ssl/ssl_connection_status_flags.h" | 7 #include "net/ssl/ssl_connection_status_flags.h" |
| 8 #include "testing/gtest/include/gtest/gtest.h" | 8 #include "testing/gtest/include/gtest/gtest.h" |
| 9 | 9 |
| 10 namespace content { | 10 namespace content { |
| 11 | 11 |
| 12 namespace { |
| 13 |
| 14 void SetTestStatus(SSLStatus* status) { |
| 15 status->security_style = SECURITY_STYLE_AUTHENTICATED; |
| 16 status->cert_id = 1; |
| 17 status->cert_status = net::CERT_STATUS_DATE_INVALID; |
| 18 status->security_bits = 80; |
| 19 status->key_exchange_info = 23; |
| 20 status->connection_status = net::SSL_CONNECTION_VERSION_TLS1_2; |
| 21 status->signed_certificate_timestamp_ids.push_back( |
| 22 SignedCertificateTimestampIDAndStatus(1, net::ct::SCT_STATUS_OK)); |
| 23 } |
| 24 |
| 25 bool SSLStatusAreEqual(const SSLStatus& a, const SSLStatus &b) { |
| 26 return a.Equals(b); |
| 27 } |
| 28 |
| 29 } // namespace |
| 30 |
| 31 std::ostream& operator<<(std::ostream& os, const SSLStatus& status) { |
| 32 return os << "Security Style: " << status.security_style |
| 33 << "\nCert ID: " << status.cert_id |
| 34 << "\nCert Status: " << status.cert_status |
| 35 << "\nSecurity bits: " << status.security_bits |
| 36 << "\nKey exchange info: " << status.key_exchange_info |
| 37 << "\nConnection status: " << status.connection_status |
| 38 << "\nContent Status: " << status.content_status |
| 39 << "\nNumber of SCTs: " << status.signed_certificate_timestamp_ids.size(); |
| 40 } |
| 41 |
| 12 // Test that a valid serialized SSLStatus returns true on | 42 // Test that a valid serialized SSLStatus returns true on |
| 13 // deserialization and deserializes correctly. | 43 // deserialization and deserializes correctly. |
| 14 TEST(SSLStatusSerializationTest, DeserializeSerializedStatus) { | 44 TEST(SSLStatusSerializationTest, DeserializeSerializedStatus) { |
| 15 // Serialize dummy data and test that it deserializes properly. | 45 // Serialize dummy data and test that it deserializes properly. |
| 16 SSLStatus status; | 46 SSLStatus status; |
| 17 status.security_style = SECURITY_STYLE_AUTHENTICATED; | 47 SetTestStatus(&status); |
| 18 status.cert_id = 1; | |
| 19 status.cert_status = net::CERT_STATUS_DATE_INVALID; | |
| 20 status.security_bits = 80; | |
| 21 status.connection_status = net::SSL_CONNECTION_VERSION_TLS1_2; | |
| 22 SignedCertificateTimestampIDAndStatus sct(1, net::ct::SCT_STATUS_OK); | |
| 23 status.signed_certificate_timestamp_ids.push_back(sct); | |
| 24 | |
| 25 std::string serialized = SerializeSecurityInfo(status); | 48 std::string serialized = SerializeSecurityInfo(status); |
| 26 | 49 |
| 27 SSLStatus deserialized; | 50 SSLStatus deserialized; |
| 28 ASSERT_TRUE(DeserializeSecurityInfo(serialized, &deserialized)); | 51 ASSERT_TRUE(DeserializeSecurityInfo(serialized, &deserialized)); |
| 29 EXPECT_EQ(status.security_style, deserialized.security_style); | 52 EXPECT_PRED2(SSLStatusAreEqual, status, deserialized); |
| 30 EXPECT_EQ(status.cert_id, deserialized.cert_id); | 53 EXPECT_EQ(SignedCertificateTimestampIDAndStatus(1, net::ct::SCT_STATUS_OK), |
| 31 EXPECT_EQ(status.cert_status, deserialized.cert_status); | 54 deserialized.signed_certificate_timestamp_ids[0]); |
| 32 EXPECT_EQ(status.security_bits, deserialized.security_bits); | |
| 33 EXPECT_EQ(status.connection_status, deserialized.connection_status); | |
| 34 EXPECT_EQ(status.signed_certificate_timestamp_ids.size(), | |
| 35 deserialized.signed_certificate_timestamp_ids.size()); | |
| 36 EXPECT_EQ(sct, deserialized.signed_certificate_timestamp_ids[0]); | |
| 37 // Test that |content_status| has the default (initialized) value. | 55 // Test that |content_status| has the default (initialized) value. |
| 38 EXPECT_EQ(SSLStatus::NORMAL_CONTENT, deserialized.content_status); | 56 EXPECT_EQ(SSLStatus::NORMAL_CONTENT, deserialized.content_status); |
| 39 } | 57 } |
| 40 | 58 |
| 41 // Test that an invalid serialized SSLStatus returns false on | 59 // Test that an invalid serialized SSLStatus returns false on |
| 42 // deserialization. | 60 // deserialization. |
| 43 TEST(SSLStatusSerializationTest, DeserializeBogusStatus) { | 61 TEST(SSLStatusSerializationTest, DeserializeBogusStatus) { |
| 44 // Test that a failure to deserialize returns false and returns | 62 // Test that a failure to deserialize returns false and returns |
| 45 // initialized, default data. | 63 // initialized, default data. |
| 46 SSLStatus invalid_deserialized; | 64 SSLStatus invalid_deserialized; |
| 47 ASSERT_FALSE( | 65 ASSERT_FALSE( |
| 48 DeserializeSecurityInfo("not an SSLStatus", &invalid_deserialized)); | 66 DeserializeSecurityInfo("not an SSLStatus", &invalid_deserialized)); |
| 67 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
| 68 } |
| 49 | 69 |
| 50 SSLStatus default_ssl_status; | 70 // Serialize a status with a bad |security_bits| value and test that |
| 51 EXPECT_EQ(default_ssl_status.security_style, | 71 // deserializing it fails. |
| 52 invalid_deserialized.security_style); | 72 TEST(SSLStatusSerializationTest, DeserializeBogusSecurityBits) { |
| 53 EXPECT_EQ(default_ssl_status.cert_id, invalid_deserialized.cert_id); | |
| 54 EXPECT_EQ(default_ssl_status.cert_status, invalid_deserialized.cert_status); | |
| 55 EXPECT_EQ(default_ssl_status.security_bits, | |
| 56 invalid_deserialized.security_bits); | |
| 57 EXPECT_EQ(default_ssl_status.connection_status, | |
| 58 invalid_deserialized.connection_status); | |
| 59 EXPECT_EQ(default_ssl_status.content_status, | |
| 60 invalid_deserialized.content_status); | |
| 61 EXPECT_EQ(0u, invalid_deserialized.signed_certificate_timestamp_ids.size()); | |
| 62 | |
| 63 // Serialize a status with a bad |security_bits| value and test that | |
| 64 // deserializing it fails. | |
| 65 SSLStatus status; | 73 SSLStatus status; |
| 66 status.security_style = SECURITY_STYLE_AUTHENTICATED; | 74 SetTestStatus(&status); |
| 67 status.cert_id = 1; | |
| 68 status.cert_status = net::CERT_STATUS_DATE_INVALID; | |
| 69 // |security_bits| must be <-1. (-1 means the strength is unknown, and | 75 // |security_bits| must be <-1. (-1 means the strength is unknown, and |
| 70 // |0 means the connection is not encrypted). | 76 // |0 means the connection is not encrypted). |
| 71 status.security_bits = -5; | 77 status.security_bits = -5; |
| 72 status.connection_status = net::SSL_CONNECTION_VERSION_TLS1_2; | 78 std::string serialized = SerializeSecurityInfo(status); |
| 73 SignedCertificateTimestampIDAndStatus sct(1, net::ct::SCT_STATUS_OK); | |
| 74 status.signed_certificate_timestamp_ids.push_back(sct); | |
| 75 | 79 |
| 80 SSLStatus invalid_deserialized; |
| 81 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); |
| 82 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
| 83 } |
| 84 |
| 85 // Serialize a status with a bad |key_exchange_info| value and test that |
| 86 // deserializing it fails. |
| 87 TEST(SSLStatusSerializationTest, DeserializeBogusKeyExchangeInfo) { |
| 88 SSLStatus status; |
| 89 SetTestStatus(&status); |
| 90 status.key_exchange_info = -1; |
| 91 |
| 92 SSLStatus invalid_deserialized; |
| 76 std::string serialized = SerializeSecurityInfo(status); | 93 std::string serialized = SerializeSecurityInfo(status); |
| 77 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); | 94 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); |
| 95 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
| 96 } |
| 78 | 97 |
| 79 EXPECT_EQ(default_ssl_status.security_style, | 98 // Serialize a status with a bad |security_style| value and test that |
| 80 invalid_deserialized.security_style); | 99 // deserializing it fails. |
| 81 EXPECT_EQ(default_ssl_status.cert_id, invalid_deserialized.cert_id); | 100 TEST(SSLStatusSerializationTest, DeserializeBogusSecurityStyle) { |
| 82 EXPECT_EQ(default_ssl_status.cert_status, invalid_deserialized.cert_status); | 101 SSLStatus status; |
| 83 EXPECT_EQ(default_ssl_status.security_bits, | 102 SetTestStatus(&status); |
| 84 invalid_deserialized.security_bits); | 103 status.security_style = static_cast<SecurityStyle>(100); |
| 85 EXPECT_EQ(default_ssl_status.connection_status, | 104 std::string serialized = SerializeSecurityInfo(status); |
| 86 invalid_deserialized.connection_status); | |
| 87 EXPECT_EQ(default_ssl_status.content_status, | |
| 88 invalid_deserialized.content_status); | |
| 89 EXPECT_EQ(0u, invalid_deserialized.signed_certificate_timestamp_ids.size()); | |
| 90 | 105 |
| 91 // Now serialize a status with a bad |security_style| value and test | 106 SSLStatus invalid_deserialized; |
| 92 // that deserializing fails. | |
| 93 status.security_bits = 128; | |
| 94 status.security_style = static_cast<SecurityStyle>(100); | |
| 95 serialized = SerializeSecurityInfo(status); | |
| 96 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); | 107 ASSERT_FALSE(DeserializeSecurityInfo(serialized, &invalid_deserialized)); |
| 97 | 108 EXPECT_PRED2(SSLStatusAreEqual, SSLStatus(), invalid_deserialized); |
| 98 EXPECT_EQ(default_ssl_status.security_style, | |
| 99 invalid_deserialized.security_style); | |
| 100 EXPECT_EQ(default_ssl_status.cert_id, invalid_deserialized.cert_id); | |
| 101 EXPECT_EQ(default_ssl_status.cert_status, invalid_deserialized.cert_status); | |
| 102 EXPECT_EQ(default_ssl_status.security_bits, | |
| 103 invalid_deserialized.security_bits); | |
| 104 EXPECT_EQ(default_ssl_status.connection_status, | |
| 105 invalid_deserialized.connection_status); | |
| 106 EXPECT_EQ(default_ssl_status.content_status, | |
| 107 invalid_deserialized.content_status); | |
| 108 EXPECT_EQ(0u, invalid_deserialized.signed_certificate_timestamp_ids.size()); | |
| 109 } | 109 } |
| 110 | 110 |
| 111 } // namespace | 111 } // namespace |
| OLD | NEW |