|
|
@@ -74,6 +74,7 @@ func TestTwoFactors(t *testing.T) {
|
|
|
{"Create", twoFactorsCreate},
|
|
|
{"GetByUserID", twoFactorsGetByUserID},
|
|
|
{"IsEnabled", twoFactorsIsEnabled},
|
|
|
+ {"UseRecoveryCode", twoFactorsUseRecoveryCode},
|
|
|
} {
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
|
t.Cleanup(func() {
|
|
|
@@ -128,3 +129,55 @@ func twoFactorsIsEnabled(t *testing.T, ctx context.Context, s *TwoFactorsStore)
|
|
|
assert.True(t, s.IsEnabled(ctx, 1))
|
|
|
assert.False(t, s.IsEnabled(ctx, 2))
|
|
|
}
|
|
|
+
|
|
|
+func twoFactorsUseRecoveryCode(t *testing.T, ctx context.Context, s *TwoFactorsStore) {
|
|
|
+ // Create 2FA tokens for two users
|
|
|
+ err := s.Create(ctx, 1, "secure-key", "secure-secret")
|
|
|
+ require.NoError(t, err)
|
|
|
+ err = s.Create(ctx, 2, "secure-key", "secure-secret")
|
|
|
+ require.NoError(t, err)
|
|
|
+
|
|
|
+ // Get recovery codes for both users
|
|
|
+ var user1Codes []TwoFactorRecoveryCode
|
|
|
+ err = s.db.Where("user_id = ?", 1).Find(&user1Codes).Error
|
|
|
+ require.NoError(t, err)
|
|
|
+ require.NotEmpty(t, user1Codes)
|
|
|
+
|
|
|
+ var user2Codes []TwoFactorRecoveryCode
|
|
|
+ err = s.db.Where("user_id = ?", 2).Find(&user2Codes).Error
|
|
|
+ require.NoError(t, err)
|
|
|
+ require.NotEmpty(t, user2Codes)
|
|
|
+
|
|
|
+ // User 1 should be able to use their own recovery code
|
|
|
+ err = s.UseRecoveryCode(ctx, 1, user1Codes[0].Code)
|
|
|
+ require.NoError(t, err)
|
|
|
+
|
|
|
+ // Verify the code is now marked as used
|
|
|
+ var usedCode TwoFactorRecoveryCode
|
|
|
+ err = s.db.Where("id = ?", user1Codes[0].ID).First(&usedCode).Error
|
|
|
+ require.NoError(t, err)
|
|
|
+ assert.True(t, usedCode.IsUsed)
|
|
|
+
|
|
|
+ // User 1 should NOT be able to use user 2's recovery code
|
|
|
+ // This is the key security test - recovery codes must be scoped by user
|
|
|
+ err = s.UseRecoveryCode(ctx, 1, user2Codes[0].Code)
|
|
|
+ assert.True(t, IsTwoFactorRecoveryCodeNotFound(err), "expected recovery code not found error when using another user's code")
|
|
|
+
|
|
|
+ // User 2's code should still be unused
|
|
|
+ var user2Code TwoFactorRecoveryCode
|
|
|
+ err = s.db.Where("id = ?", user2Codes[0].ID).First(&user2Code).Error
|
|
|
+ require.NoError(t, err)
|
|
|
+ assert.False(t, user2Code.IsUsed, "user 2's recovery code should not be marked as used")
|
|
|
+
|
|
|
+ // User 2 should be able to use their own code
|
|
|
+ err = s.UseRecoveryCode(ctx, 2, user2Codes[0].Code)
|
|
|
+ require.NoError(t, err)
|
|
|
+
|
|
|
+ // Using an already-used code should fail
|
|
|
+ err = s.UseRecoveryCode(ctx, 1, user1Codes[0].Code)
|
|
|
+ assert.True(t, IsTwoFactorRecoveryCodeNotFound(err), "expected error when reusing a recovery code")
|
|
|
+
|
|
|
+ // Using a non-existent code should fail
|
|
|
+ err = s.UseRecoveryCode(ctx, 1, "invalid-code")
|
|
|
+ assert.True(t, IsTwoFactorRecoveryCodeNotFound(err), "expected error for invalid recovery code")
|
|
|
+}
|