1
0

web_mtls_test.go 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154
  1. package web
  2. import (
  3. "crypto/tls"
  4. "crypto/x509"
  5. "net/http"
  6. "net/http/httptest"
  7. "strconv"
  8. "testing"
  9. "github.com/mhsanaei/3x-ui/v3/internal/util/crypto"
  10. )
  11. // TestPanelTLSAcceptsClientWithoutClientCert characterizes the invariant the
  12. // mTLS work must preserve: the panel's HTTPS listener — configured today with a
  13. // server certificate and NO ClientAuth — completes the TLS handshake for a
  14. // client that presents no client certificate (i.e. every browser). When mTLS is
  15. // wired into web.go, the no-CA path must keep this behavior byte-for-byte. P1.6
  16. // extends this file with the VerifyClientCertIfGiven + ClientCAs cases.
  17. func TestPanelTLSAcceptsClientWithoutClientCert(t *testing.T) {
  18. srv := httptest.NewTLSServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
  19. w.WriteHeader(http.StatusOK)
  20. }))
  21. defer srv.Close()
  22. // Precondition: like web.go today, the listener requests no client cert.
  23. if srv.TLS.ClientAuth != tls.NoClientCert {
  24. t.Fatalf("precondition: ClientAuth = %v, want NoClientCert", srv.TLS.ClientAuth)
  25. }
  26. // srv.Client() trusts the server's self-signed cert and presents NO client cert.
  27. resp, err := srv.Client().Get(srv.URL)
  28. if err != nil {
  29. t.Fatalf("request without a client certificate failed: %v", err)
  30. }
  31. defer resp.Body.Close()
  32. if resp.StatusCode != http.StatusOK {
  33. t.Fatalf("status = %d, want 200", resp.StatusCode)
  34. }
  35. }
  36. // TestApplyNodeMtls exercises the listener policy applied by web.go: a nil pool
  37. // leaves the listener unchanged (no client auth, browsers work); a set pool is
  38. // request-but-don't-require, so no-cert clients still handshake while a
  39. // CA-signed client cert is verified and a foreign cert is rejected.
  40. func TestApplyNodeMtls(t *testing.T) {
  41. ca, err := crypto.GenerateNodeCA("test ca")
  42. if err != nil {
  43. t.Fatalf("GenerateNodeCA: %v", err)
  44. }
  45. clientPEM, err := crypto.IssueClientCert(ca, "master")
  46. if err != nil {
  47. t.Fatalf("IssueClientCert: %v", err)
  48. }
  49. clientCert, err := tls.X509KeyPair(clientPEM.CertPEM, clientPEM.KeyPEM)
  50. if err != nil {
  51. t.Fatalf("client X509KeyPair: %v", err)
  52. }
  53. caPool := x509.NewCertPool()
  54. if !caPool.AppendCertsFromPEM(ca.CertPEM) {
  55. t.Fatal("append CA to pool")
  56. }
  57. otherCA, err := crypto.GenerateNodeCA("other ca")
  58. if err != nil {
  59. t.Fatalf("GenerateNodeCA(other): %v", err)
  60. }
  61. foreignPEM, err := crypto.IssueClientCert(otherCA, "intruder")
  62. if err != nil {
  63. t.Fatalf("IssueClientCert(foreign): %v", err)
  64. }
  65. foreignCert, err := tls.X509KeyPair(foreignPEM.CertPEM, foreignPEM.KeyPEM)
  66. if err != nil {
  67. t.Fatalf("foreign X509KeyPair: %v", err)
  68. }
  69. newServer := func(pool *x509.CertPool) *httptest.Server {
  70. srv := httptest.NewUnstartedServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  71. n := 0
  72. if r.TLS != nil {
  73. n = len(r.TLS.VerifiedChains)
  74. }
  75. w.Header().Set("X-Verified-Chains", strconv.Itoa(n))
  76. w.WriteHeader(http.StatusOK)
  77. }))
  78. srv.TLS = &tls.Config{}
  79. applyNodeMtls(srv.TLS, pool)
  80. srv.StartTLS()
  81. return srv
  82. }
  83. // clientFor forces the client to present cert via GetClientCertificate so the
  84. // server's verification is what's under test (the default Certificates path
  85. // would let the Go client silently withhold a cert whose CA the server didn't
  86. // advertise, masking the reject behavior).
  87. clientFor := func(srv *httptest.Server, cert *tls.Certificate) *http.Client {
  88. roots := x509.NewCertPool()
  89. roots.AddCert(srv.Certificate())
  90. cfg := &tls.Config{RootCAs: roots}
  91. if cert != nil {
  92. c := *cert
  93. cfg.GetClientCertificate = func(*tls.CertificateRequestInfo) (*tls.Certificate, error) {
  94. return &c, nil
  95. }
  96. }
  97. return &http.Client{Transport: &http.Transport{TLSClientConfig: cfg}}
  98. }
  99. t.Run("nil pool leaves the listener without client auth", func(t *testing.T) {
  100. srv := newServer(nil)
  101. defer srv.Close()
  102. if srv.TLS.ClientAuth != tls.NoClientCert {
  103. t.Fatalf("nil pool must not set ClientAuth, got %v", srv.TLS.ClientAuth)
  104. }
  105. resp, err := clientFor(srv, nil).Get(srv.URL)
  106. if err != nil {
  107. t.Fatalf("no-cert client failed: %v", err)
  108. }
  109. resp.Body.Close()
  110. })
  111. t.Run("pool set still accepts a no-cert client", func(t *testing.T) {
  112. srv := newServer(caPool)
  113. defer srv.Close()
  114. resp, err := clientFor(srv, nil).Get(srv.URL)
  115. if err != nil {
  116. t.Fatalf("no-cert client must still handshake under VerifyClientCertIfGiven: %v", err)
  117. }
  118. defer resp.Body.Close()
  119. if got := resp.Header.Get("X-Verified-Chains"); got != "0" {
  120. t.Fatalf("no-cert client verified chains = %s, want 0", got)
  121. }
  122. })
  123. t.Run("pool set verifies the master client cert", func(t *testing.T) {
  124. srv := newServer(caPool)
  125. defer srv.Close()
  126. resp, err := clientFor(srv, &clientCert).Get(srv.URL)
  127. if err != nil {
  128. t.Fatalf("master client cert must be accepted: %v", err)
  129. }
  130. defer resp.Body.Close()
  131. if got := resp.Header.Get("X-Verified-Chains"); got != "1" {
  132. t.Fatalf("master cert verified chains = %s, want 1 (cert was not verified)", got)
  133. }
  134. })
  135. t.Run("pool set rejects a foreign-CA client cert", func(t *testing.T) {
  136. srv := newServer(caPool)
  137. defer srv.Close()
  138. if _, err := clientFor(srv, &foreignCert).Get(srv.URL); err == nil {
  139. t.Fatal("a client cert from an untrusted CA must fail the handshake")
  140. }
  141. })
  142. }