add test for passthrough on backups

This commit is contained in:
Hubert Chathi
2020-04-13 16:54:02 -04:00
parent 864fe459b7
commit 5d606bba66
+138
View File
@@ -578,6 +578,144 @@ describe("Secrets", function() {
expect(await alice.getSecret("m.megolm_backup.v1"))
.toEqual(olmlib.encodeBase64(backupKey));
});
it("converts asymmetric SSSS with passthrough to symmetric SSSS", async function() {
let crossSigningKeys = {};
const secretStorageKeys = {
"old_key_id": SSSSKey,
"new_key_id": SSSSKey,
};
const alice = await makeTestClient(
{userId: "@alice:example.com", deviceId: "Osborne2"},
{
cryptoCallbacks: {
getCrossSigningKey: t => crossSigningKeys[t],
saveCrossSigningKeys: k => crossSigningKeys = k,
getSecretStorageKey: ({keys}, name) => {
for (const keyId of Object.keys(keys)) {
if (secretStorageKeys[keyId]) {
return [keyId, secretStorageKeys[keyId]];
}
}
},
},
},
);
const encryption = new global.Olm.PkEncryption();
encryption.set_recipient_key(SSSSPubKey);
alice.store.storeAccountDataEvents([
new MatrixEvent({
type: "m.secret_storage.default_key",
content: {
key: "old_key_id",
},
}),
new MatrixEvent({
type: "m.secret_storage.key.old_key_id",
content: sign({
algorithm: "m.secret_storage.v1.curve25519-aes-sha2",
passphrase: {
algorithm: "m.pbkdf2",
iterations: 500000,
salt: "GbkvwKHVMveo1zGVSb2GMMdCinG2npJK",
},
pubkey: "v3A8HTypbccUm6jaRCRw5l+7lSdzQUACeY9xpQ5BVmE",
}, XSK, "@alice:example.com"),
}),
new MatrixEvent({
type: "m.cross_signing.master",
content: {
encrypted: {
old_key_id: encryption.encrypt(olmlib.encodeBase64(XSK)),
},
},
}),
new MatrixEvent({
type: "m.cross_signing.self_signing",
content: {
encrypted: {
old_key_id: encryption.encrypt(olmlib.encodeBase64(SSK)),
},
},
}),
new MatrixEvent({
type: "m.cross_signing.user_signing",
content: {
encrypted: {
old_key_id: encryption.encrypt(olmlib.encodeBase64(USK)),
},
},
}),
new MatrixEvent({
type: "m.megolm_backup.v1",
content: {
encrypted: {
old_key_id: {
passthrough: true,
},
},
},
}),
]);
encryption.free();
alice._crypto._deviceList.storeCrossSigningForUser("@alice:example.com", {
keys: {
master: {
user_id: "@alice:example.com",
usage: ["master"],
keys: {
[`ed25519:${XSPubKey}`]: XSPubKey,
},
},
self_signing: sign({
user_id: "@alice:example.com",
usage: ["self_signing"],
keys: {
[`ed25519:${SSPubKey}`]: SSPubKey,
},
}, XSK, "@alice:example.com"),
user_signing: sign({
user_id: "@alice:example.com",
usage: ["user_signing"],
keys: {
[`ed25519:${USPubKey}`]: USPubKey,
},
}, XSK, "@alice:example.com"),
},
});
alice.getKeyBackupVersion = async () => {
return {
version: "1",
algorithm: "m.megolm_backup.v1.curve25519-aes-sha2",
auth_data: sign({
public_key: "v3A8HTypbccUm6jaRCRw5l+7lSdzQUACeY9xpQ5BVmE",
}, XSK, "@alice:example.com"),
};
};
const origAddSecretStorageKey = alice._crypto.addSecretStorageKey;
alice._crypto.addSecretStorageKey = async function(algorithm, opts, keyId) {
return await origAddSecretStorageKey.call(
alice._crypto, algorithm, opts, keyId || "new_key_id",
);
};
alice.setAccountData = async function(name, data) {
const event = new MatrixEvent({
type: name,
content: data,
});
alice.store.storeAccountDataEvents([event]);
this.emit("accountData", event);
};
await alice.bootstrapSecretStorage();
// the new backup key should be the encoded SSSS key
const backupKeyInfo = alice.getAccountData("m.megolm_backup.v1")
.getContent();
expect(backupKeyInfo.encrypted).toHaveProperty("new_key_id");
expect(backupKeyInfo.encrypted).not.toHaveProperty("old_key_id");
expect(await alice.getSecret("m.megolm_backup.v1"))
.toEqual(olmlib.encodeBase64(SSSSKey));
});
it("adds passphrase checking if it's lacking", async function() {
let crossSigningKeys = {
master: XSK,