1 // Copyright 2022 Google LLC
2 //
3 // Licensed under the Apache License, Version 2.0 (the "License");
4 // you may not use this file except in compliance with the License.
5 // You may obtain a copy of the License at
6 //
7 // http://www.apache.org/licenses/LICENSE-2.0
8 //
9 // Unless required by applicable law or agreed to in writing, software
10 // distributed under the License is distributed on an "AS IS" BASIS,
11 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 // See the License for the specific language governing permissions and
13 // limitations under the License.
14 //
15 ////////////////////////////////////////////////////////////////////////////////
16
17 #include "tink/restricted_data.h"
18
19 #include <string>
20 #include <utility>
21
22 #include "gmock/gmock.h"
23 #include "gtest/gtest.h"
24 #include "tink/insecure_secret_key_access.h"
25 #include "tink/subtle/random.h"
26 #include "tink/util/secret_data.h"
27
28 namespace crypto {
29 namespace tink {
30
31 using ::crypto::tink::subtle::Random;
32 using ::testing::Eq;
33 using ::testing::SizeIs;
34
TEST(RestrictedDataTest,CreateAndGetSecret)35 TEST(RestrictedDataTest, CreateAndGetSecret) {
36 const std::string secret = Random::GetRandomBytes(32);
37 RestrictedData data(secret, InsecureSecretKeyAccess::Get());
38
39 EXPECT_THAT(data.GetSecret(InsecureSecretKeyAccess::Get()), Eq(secret));
40 }
41
TEST(RestrictedDataTest,GenerateRandomAndSize)42 TEST(RestrictedDataTest, GenerateRandomAndSize) {
43 RestrictedData data(/*num_random_bytes=*/32);
44
45 EXPECT_THAT(data.GetSecret(InsecureSecretKeyAccess::Get()), SizeIs(32));
46 EXPECT_THAT(data.size(), Eq(32));
47 }
48
TEST(RestrictedDataTest,GenerateRandomNegative)49 TEST(RestrictedDataTest, GenerateRandomNegative) {
50 EXPECT_DEATH_IF_SUPPORTED(
51 RestrictedData(/*num_random_bytes=*/-1),
52 "Cannot generate a negative number of random bytes.\n");
53 }
54
TEST(RestrictedDataTest,Equals)55 TEST(RestrictedDataTest, Equals) {
56 const std::string secret = Random::GetRandomBytes(32);
57 RestrictedData data(secret, InsecureSecretKeyAccess::Get());
58 RestrictedData same_data(secret, InsecureSecretKeyAccess::Get());
59
60 EXPECT_TRUE(data == same_data);
61 EXPECT_TRUE(same_data == data);
62 EXPECT_FALSE(data != same_data);
63 EXPECT_FALSE(same_data != data);
64 }
65
TEST(RestrictedDataTest,NotEquals)66 TEST(RestrictedDataTest, NotEquals) {
67 RestrictedData data(
68 util::SecretDataAsStringView(Random::GetRandomKeyBytes(32)),
69 InsecureSecretKeyAccess::Get());
70 RestrictedData diff_data(
71 util::SecretDataAsStringView(Random::GetRandomKeyBytes(32)),
72 InsecureSecretKeyAccess::Get());
73
74 EXPECT_TRUE(data != diff_data);
75 EXPECT_TRUE(diff_data != data);
76 EXPECT_FALSE(data == diff_data);
77 EXPECT_FALSE(diff_data == data);
78 }
79
TEST(RestrictedDataTest,CopyConstructor)80 TEST(RestrictedDataTest, CopyConstructor) {
81 RestrictedData data(/*num_random_bytes=*/32);
82 RestrictedData copy(data);
83
84 EXPECT_THAT(copy, SizeIs(32));
85 EXPECT_THAT(copy.GetSecret(InsecureSecretKeyAccess::Get()),
86 Eq(data.GetSecret(InsecureSecretKeyAccess::Get())));
87 }
88
TEST(RestrictedDataTest,CopyAssignment)89 TEST(RestrictedDataTest, CopyAssignment) {
90 RestrictedData data(/*num_random_bytes=*/32);
91 RestrictedData copy = data;
92
93 EXPECT_THAT(copy, SizeIs(32));
94 EXPECT_THAT(copy.GetSecret(InsecureSecretKeyAccess::Get()),
95 Eq(copy.GetSecret(InsecureSecretKeyAccess::Get())));
96 }
97
TEST(RestrictedDataTest,MoveConstructor)98 TEST(RestrictedDataTest, MoveConstructor) {
99 const std::string secret = Random::GetRandomBytes(32);
100 RestrictedData data(secret, InsecureSecretKeyAccess::Get());
101 RestrictedData move(std::move(data));
102
103 EXPECT_THAT(move, SizeIs(32));
104 EXPECT_THAT(move.GetSecret(InsecureSecretKeyAccess::Get()), Eq(secret));
105 }
106
TEST(RestrictedDataTest,MoveAssignment)107 TEST(RestrictedDataTest, MoveAssignment) {
108 const std::string secret = Random::GetRandomBytes(32);
109 RestrictedData data(secret, InsecureSecretKeyAccess::Get());
110 RestrictedData move = std::move(data);
111
112 EXPECT_THAT(move, SizeIs(32));
113 EXPECT_THAT(move.GetSecret(InsecureSecretKeyAccess::Get()), Eq(secret));
114 }
115
116 } // namespace tink
117 } // namespace crypto
118