2010-12-18 21:38:05 +00:00
|
|
|
require 'cases/helper'
|
|
|
|
require 'models/user'
|
|
|
|
|
|
|
|
class SecurePasswordTest < ActiveModel::TestCase
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
setup do
|
2010-12-19 09:39:54 +00:00
|
|
|
User.weak_passwords = %w( password qwerty 123456 )
|
2010-12-18 21:38:05 +00:00
|
|
|
@user = User.new
|
|
|
|
end
|
|
|
|
|
2010-12-19 09:39:54 +00:00
|
|
|
test "there should be a list of default weak passwords" do
|
|
|
|
assert_equal %w( password qwerty 123456 ), User.weak_passwords
|
|
|
|
end
|
|
|
|
|
|
|
|
test "specifying the list of passwords" do
|
|
|
|
User.weak_passwords = %w( pass )
|
|
|
|
assert_equal %w( pass ), User.weak_passwords
|
|
|
|
end
|
|
|
|
|
2010-12-19 10:28:37 +00:00
|
|
|
test "specifying the list of passwords in the class" do
|
|
|
|
User.send(:set_weak_passwords, ['pass'])
|
|
|
|
assert_equal %w( pass ), User.weak_passwords
|
|
|
|
end
|
|
|
|
|
2010-12-19 09:39:54 +00:00
|
|
|
test "adding to the list of passwords" do
|
|
|
|
User.weak_passwords << 'pass'
|
|
|
|
@user.password = "password"
|
|
|
|
assert !@user.valid?
|
|
|
|
|
|
|
|
@user.password = "pass"
|
|
|
|
assert !@user.valid?
|
|
|
|
end
|
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
test "password must be present" do
|
|
|
|
assert !@user.valid?
|
|
|
|
assert_equal 1, @user.errors.size
|
|
|
|
end
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
test "password must match confirmation" do
|
|
|
|
@user.password = "thiswillberight"
|
|
|
|
@user.password_confirmation = "wrong"
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
assert !@user.valid?
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
@user.password_confirmation = "thiswillberight"
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
assert @user.valid?
|
|
|
|
end
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
test "password must pass validation rules" do
|
|
|
|
@user.password = "password"
|
|
|
|
assert !@user.valid?
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
@user.password = "short"
|
|
|
|
assert !@user.valid?
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
@user.password = "plentylongenough"
|
|
|
|
assert @user.valid?
|
|
|
|
end
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-19 03:09:07 +00:00
|
|
|
test "too weak passwords" do
|
2010-12-19 08:28:15 +00:00
|
|
|
@user.password = "012345"
|
2010-12-19 03:09:07 +00:00
|
|
|
assert !@user.valid?
|
2010-12-19 08:34:31 +00:00
|
|
|
assert_equal ["is too short (minimum is 7 characters)"], @user.errors[:password]
|
2010-12-19 03:09:07 +00:00
|
|
|
|
|
|
|
@user.password = "password"
|
|
|
|
assert !@user.valid?
|
2010-12-19 08:28:15 +00:00
|
|
|
assert_equal ["is too weak and common"], @user.errors[:password]
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-19 03:09:07 +00:00
|
|
|
@user.password = "d9034rfjlakj34RR$!!"
|
|
|
|
assert @user.valid?
|
|
|
|
end
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
test "authenticate" do
|
|
|
|
@user.password = "secret"
|
2010-12-19 09:39:54 +00:00
|
|
|
|
2010-12-18 21:38:05 +00:00
|
|
|
assert !@user.authenticate("wrong")
|
|
|
|
assert @user.authenticate("secret")
|
|
|
|
end
|
|
|
|
end
|