KeyRingProviderTests.cs 33 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637
  1. // Copyright (c) .NET Foundation. All rights reserved.
  2. // Licensed under the Apache License, Version 2.0. See License.txt in the project root for license information.
  3. using System;
  4. using System.Collections.Generic;
  5. using System.Globalization;
  6. using System.Threading;
  7. using System.Threading.Tasks;
  8. using Microsoft.AspNetCore.DataProtection.AuthenticatedEncryption;
  9. using Microsoft.AspNetCore.DataProtection.KeyManagement.Internal;
  10. using Microsoft.AspNetCore.Testing;
  11. using Microsoft.Extensions.DependencyInjection;
  12. using Moq;
  13. using Xunit;
  14. using static System.FormattableString;
  15. namespace Microsoft.AspNetCore.DataProtection.KeyManagement
  16. {
  17. public class KeyRingProviderTests
  18. {
  19. [Fact]
  20. public void CreateCacheableKeyRing_NoGenerationRequired_DefaultKeyExpiresAfterRefreshPeriod()
  21. {
  22. // Arrange
  23. var callSequence = new List<string>();
  24. var expirationCts = new CancellationTokenSource();
  25. var now = StringToDateTime("2015-03-01 00:00:00Z");
  26. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  27. var key2 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z");
  28. var allKeys = new[] { key1, key2 };
  29. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  30. callSequence: callSequence,
  31. getCacheExpirationTokenReturnValues: new[] { expirationCts.Token },
  32. getAllKeysReturnValues: new[] { allKeys },
  33. createNewKeyCallbacks: null,
  34. resolveDefaultKeyPolicyReturnValues: new[]
  35. {
  36. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys, new DefaultKeyResolution()
  37. {
  38. DefaultKey = key1,
  39. ShouldGenerateNewKey = false
  40. })
  41. });
  42. // Act
  43. var cacheableKeyRing = keyRingProvider.GetCacheableKeyRing(now);
  44. // Assert
  45. Assert.Equal(key1.KeyId, cacheableKeyRing.KeyRing.DefaultKeyId);
  46. AssertWithinJitterRange(cacheableKeyRing.ExpirationTimeUtc, now);
  47. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  48. expirationCts.Cancel();
  49. Assert.False(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  50. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  51. }
  52. [Fact]
  53. public void CreateCacheableKeyRing_NoGenerationRequired_DefaultKeyExpiresBeforeRefreshPeriod()
  54. {
  55. // Arrange
  56. var callSequence = new List<string>();
  57. var expirationCts = new CancellationTokenSource();
  58. var now = StringToDateTime("2016-02-29 20:00:00Z");
  59. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  60. var key2 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z");
  61. var allKeys = new[] { key1, key2 };
  62. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  63. callSequence: callSequence,
  64. getCacheExpirationTokenReturnValues: new[] { expirationCts.Token },
  65. getAllKeysReturnValues: new[] { allKeys },
  66. createNewKeyCallbacks: null,
  67. resolveDefaultKeyPolicyReturnValues: new[]
  68. {
  69. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys, new DefaultKeyResolution()
  70. {
  71. DefaultKey = key1,
  72. ShouldGenerateNewKey = false
  73. })
  74. });
  75. // Act
  76. var cacheableKeyRing = keyRingProvider.GetCacheableKeyRing(now);
  77. // Assert
  78. Assert.Equal(key1.KeyId, cacheableKeyRing.KeyRing.DefaultKeyId);
  79. Assert.Equal(StringToDateTime("2016-03-01 00:00:00Z"), cacheableKeyRing.ExpirationTimeUtc);
  80. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  81. expirationCts.Cancel();
  82. Assert.False(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  83. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  84. }
  85. [Fact]
  86. public void CreateCacheableKeyRing_GenerationRequired_NoDefaultKey_CreatesNewKeyWithImmediateActivation()
  87. {
  88. // Arrange
  89. var callSequence = new List<string>();
  90. var expirationCts1 = new CancellationTokenSource();
  91. var expirationCts2 = new CancellationTokenSource();
  92. var now = StringToDateTime("2015-03-01 00:00:00Z");
  93. var allKeys1 = new IKey[0];
  94. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  95. var key2 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z");
  96. var allKeys2 = new[] { key1, key2 };
  97. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  98. callSequence: callSequence,
  99. getCacheExpirationTokenReturnValues: new[] { expirationCts1.Token, expirationCts2.Token },
  100. getAllKeysReturnValues: new[] { allKeys1, allKeys2 },
  101. createNewKeyCallbacks: new[] {
  102. Tuple.Create((DateTimeOffset)now, (DateTimeOffset)now + TimeSpan.FromDays(90), CreateKey())
  103. },
  104. resolveDefaultKeyPolicyReturnValues: new[]
  105. {
  106. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys1, new DefaultKeyResolution()
  107. {
  108. DefaultKey = null,
  109. ShouldGenerateNewKey = true
  110. }),
  111. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys2, new DefaultKeyResolution()
  112. {
  113. DefaultKey = key1,
  114. ShouldGenerateNewKey = false
  115. })
  116. });
  117. // Act
  118. var cacheableKeyRing = keyRingProvider.GetCacheableKeyRing(now);
  119. // Assert
  120. Assert.Equal(key1.KeyId, cacheableKeyRing.KeyRing.DefaultKeyId);
  121. AssertWithinJitterRange(cacheableKeyRing.ExpirationTimeUtc, now);
  122. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  123. expirationCts1.Cancel();
  124. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  125. expirationCts2.Cancel();
  126. Assert.False(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  127. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy", "CreateNewKey", "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  128. }
  129. [Fact]
  130. public void CreateCacheableKeyRing_GenerationRequired_NoDefaultKey_CreatesNewKeyWithImmediateActivation_StillNoDefaultKey_ReturnsNewlyCreatedKey()
  131. {
  132. // Arrange
  133. var callSequence = new List<string>();
  134. var expirationCts1 = new CancellationTokenSource();
  135. var expirationCts2 = new CancellationTokenSource();
  136. var now = StringToDateTime("2015-03-01 00:00:00Z");
  137. var allKeys = new IKey[0];
  138. var newlyCreatedKey = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  139. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  140. callSequence: callSequence,
  141. getCacheExpirationTokenReturnValues: new[] { expirationCts1.Token, expirationCts2.Token },
  142. getAllKeysReturnValues: new[] { allKeys, allKeys },
  143. createNewKeyCallbacks: new[] {
  144. Tuple.Create((DateTimeOffset)now, (DateTimeOffset)now + TimeSpan.FromDays(90), newlyCreatedKey)
  145. },
  146. resolveDefaultKeyPolicyReturnValues: new[]
  147. {
  148. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys, new DefaultKeyResolution()
  149. {
  150. DefaultKey = null,
  151. ShouldGenerateNewKey = true
  152. }),
  153. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys, new DefaultKeyResolution()
  154. {
  155. DefaultKey = null,
  156. ShouldGenerateNewKey = true
  157. })
  158. });
  159. // Act
  160. var cacheableKeyRing = keyRingProvider.GetCacheableKeyRing(now);
  161. // Assert
  162. Assert.Equal(newlyCreatedKey.KeyId, cacheableKeyRing.KeyRing.DefaultKeyId);
  163. AssertWithinJitterRange(cacheableKeyRing.ExpirationTimeUtc, now);
  164. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  165. expirationCts1.Cancel();
  166. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  167. expirationCts2.Cancel();
  168. Assert.False(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  169. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy", "CreateNewKey", "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  170. }
  171. [Fact]
  172. public void CreateCacheableKeyRing_GenerationRequired_NoDefaultKey_KeyGenerationDisabled_Fails()
  173. {
  174. // Arrange
  175. var callSequence = new List<string>();
  176. var now = StringToDateTime("2015-03-01 00:00:00Z");
  177. var allKeys = new IKey[0];
  178. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  179. callSequence: callSequence,
  180. getCacheExpirationTokenReturnValues: new[] { CancellationToken.None },
  181. getAllKeysReturnValues: new[] { allKeys },
  182. createNewKeyCallbacks: new[] {
  183. Tuple.Create((DateTimeOffset)now, (DateTimeOffset)now + TimeSpan.FromDays(90), CreateKey())
  184. },
  185. resolveDefaultKeyPolicyReturnValues: new[]
  186. {
  187. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys, new DefaultKeyResolution()
  188. {
  189. DefaultKey = null,
  190. ShouldGenerateNewKey = true
  191. })
  192. },
  193. keyManagementOptions: new KeyManagementOptions() { AutoGenerateKeys = false });
  194. // Act
  195. var exception = Assert.Throws<InvalidOperationException>(() => keyRingProvider.GetCacheableKeyRing(now));
  196. // Assert
  197. Assert.Equal(Resources.KeyRingProvider_NoDefaultKey_AutoGenerateDisabled, exception.Message);
  198. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  199. }
  200. [Fact]
  201. public void CreateCacheableKeyRing_GenerationRequired_WithDefaultKey_CreatesNewKeyWithDeferredActivationAndExpirationBasedOnCreationTime()
  202. {
  203. // Arrange
  204. var callSequence = new List<string>();
  205. var expirationCts1 = new CancellationTokenSource();
  206. var expirationCts2 = new CancellationTokenSource();
  207. var now = StringToDateTime("2016-02-01 00:00:00Z");
  208. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  209. var allKeys1 = new[] { key1 };
  210. var key2 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z");
  211. var allKeys2 = new[] { key1, key2 };
  212. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  213. callSequence: callSequence,
  214. getCacheExpirationTokenReturnValues: new[] { expirationCts1.Token, expirationCts2.Token },
  215. getAllKeysReturnValues: new[] { allKeys1, allKeys2 },
  216. createNewKeyCallbacks: new[] {
  217. Tuple.Create(key1.ExpirationDate, (DateTimeOffset)now + TimeSpan.FromDays(90), CreateKey())
  218. },
  219. resolveDefaultKeyPolicyReturnValues: new[]
  220. {
  221. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys1, new DefaultKeyResolution()
  222. {
  223. DefaultKey = key1,
  224. ShouldGenerateNewKey = true
  225. }),
  226. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys2, new DefaultKeyResolution()
  227. {
  228. DefaultKey = key2,
  229. ShouldGenerateNewKey = false
  230. })
  231. });
  232. // Act
  233. var cacheableKeyRing = keyRingProvider.GetCacheableKeyRing(now);
  234. // Assert
  235. Assert.Equal(key2.KeyId, cacheableKeyRing.KeyRing.DefaultKeyId);
  236. AssertWithinJitterRange(cacheableKeyRing.ExpirationTimeUtc, now);
  237. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  238. expirationCts1.Cancel();
  239. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  240. expirationCts2.Cancel();
  241. Assert.False(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  242. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy", "CreateNewKey", "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  243. }
  244. [Fact]
  245. public void CreateCacheableKeyRing_GenerationRequired_WithDefaultKey_KeyGenerationDisabled_DoesNotCreateDefaultKey()
  246. {
  247. // Arrange
  248. var callSequence = new List<string>();
  249. var expirationCts = new CancellationTokenSource();
  250. var now = StringToDateTime("2016-02-01 00:00:00Z");
  251. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  252. var allKeys = new[] { key1 };
  253. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  254. callSequence: callSequence,
  255. getCacheExpirationTokenReturnValues: new[] { expirationCts.Token },
  256. getAllKeysReturnValues: new[] { allKeys },
  257. createNewKeyCallbacks: null, // empty
  258. resolveDefaultKeyPolicyReturnValues: new[]
  259. {
  260. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys, new DefaultKeyResolution()
  261. {
  262. DefaultKey = key1,
  263. ShouldGenerateNewKey = true
  264. })
  265. },
  266. keyManagementOptions: new KeyManagementOptions() { AutoGenerateKeys = false });
  267. // Act
  268. var cacheableKeyRing = keyRingProvider.GetCacheableKeyRing(now);
  269. // Assert
  270. Assert.Equal(key1.KeyId, cacheableKeyRing.KeyRing.DefaultKeyId);
  271. AssertWithinJitterRange(cacheableKeyRing.ExpirationTimeUtc, now);
  272. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  273. expirationCts.Cancel();
  274. Assert.False(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  275. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  276. }
  277. [Fact]
  278. public void CreateCacheableKeyRing_GenerationRequired_WithFallbackKey_KeyGenerationDisabled_DoesNotCreateDefaultKey()
  279. {
  280. // Arrange
  281. var callSequence = new List<string>();
  282. var expirationCts = new CancellationTokenSource();
  283. var now = StringToDateTime("2016-02-01 00:00:00Z");
  284. var key1 = CreateKey("2015-03-01 00:00:00Z", "2015-03-01 00:00:00Z");
  285. var allKeys = new[] { key1 };
  286. var keyRingProvider = SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  287. callSequence: callSequence,
  288. getCacheExpirationTokenReturnValues: new[] { expirationCts.Token },
  289. getAllKeysReturnValues: new[] { allKeys },
  290. createNewKeyCallbacks: null, // empty
  291. resolveDefaultKeyPolicyReturnValues: new[]
  292. {
  293. Tuple.Create((DateTimeOffset)now, (IEnumerable<IKey>)allKeys, new DefaultKeyResolution()
  294. {
  295. FallbackKey = key1,
  296. ShouldGenerateNewKey = true
  297. })
  298. },
  299. keyManagementOptions: new KeyManagementOptions() { AutoGenerateKeys = false });
  300. // Act
  301. var cacheableKeyRing = keyRingProvider.GetCacheableKeyRing(now);
  302. // Assert
  303. Assert.Equal(key1.KeyId, cacheableKeyRing.KeyRing.DefaultKeyId);
  304. AssertWithinJitterRange(cacheableKeyRing.ExpirationTimeUtc, now);
  305. Assert.True(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  306. expirationCts.Cancel();
  307. Assert.False(CacheableKeyRing.IsValid(cacheableKeyRing, now));
  308. Assert.Equal(new[] { "GetCacheExpirationToken", "GetAllKeys", "ResolveDefaultKeyPolicy" }, callSequence);
  309. }
  310. private static ICacheableKeyRingProvider SetupCreateCacheableKeyRingTestAndCreateKeyManager(
  311. IList<string> callSequence,
  312. IEnumerable<CancellationToken> getCacheExpirationTokenReturnValues,
  313. IEnumerable<IReadOnlyCollection<IKey>> getAllKeysReturnValues,
  314. IEnumerable<Tuple<DateTimeOffset, DateTimeOffset, IKey>> createNewKeyCallbacks,
  315. IEnumerable<Tuple<DateTimeOffset, IEnumerable<IKey>, DefaultKeyResolution>> resolveDefaultKeyPolicyReturnValues,
  316. KeyManagementOptions keyManagementOptions = null)
  317. {
  318. var getCacheExpirationTokenReturnValuesEnumerator = getCacheExpirationTokenReturnValues.GetEnumerator();
  319. var mockKeyManager = new Mock<IKeyManager>(MockBehavior.Strict);
  320. mockKeyManager.Setup(o => o.GetCacheExpirationToken())
  321. .Returns(() =>
  322. {
  323. callSequence.Add("GetCacheExpirationToken");
  324. getCacheExpirationTokenReturnValuesEnumerator.MoveNext();
  325. return getCacheExpirationTokenReturnValuesEnumerator.Current;
  326. });
  327. var getAllKeysReturnValuesEnumerator = getAllKeysReturnValues.GetEnumerator();
  328. mockKeyManager.Setup(o => o.GetAllKeys())
  329. .Returns(() =>
  330. {
  331. callSequence.Add("GetAllKeys");
  332. getAllKeysReturnValuesEnumerator.MoveNext();
  333. return getAllKeysReturnValuesEnumerator.Current;
  334. });
  335. if (createNewKeyCallbacks != null)
  336. {
  337. var createNewKeyCallbacksEnumerator = createNewKeyCallbacks.GetEnumerator();
  338. mockKeyManager.Setup(o => o.CreateNewKey(It.IsAny<DateTimeOffset>(), It.IsAny<DateTimeOffset>()))
  339. .Returns<DateTimeOffset, DateTimeOffset>((activationDate, expirationDate) =>
  340. {
  341. callSequence.Add("CreateNewKey");
  342. createNewKeyCallbacksEnumerator.MoveNext();
  343. Assert.Equal(createNewKeyCallbacksEnumerator.Current.Item1, activationDate);
  344. Assert.Equal(createNewKeyCallbacksEnumerator.Current.Item2, expirationDate);
  345. return createNewKeyCallbacksEnumerator.Current.Item3;
  346. });
  347. }
  348. var resolveDefaultKeyPolicyReturnValuesEnumerator = resolveDefaultKeyPolicyReturnValues.GetEnumerator();
  349. var mockDefaultKeyResolver = new Mock<IDefaultKeyResolver>(MockBehavior.Strict);
  350. mockDefaultKeyResolver.Setup(o => o.ResolveDefaultKeyPolicy(It.IsAny<DateTimeOffset>(), It.IsAny<IEnumerable<IKey>>()))
  351. .Returns<DateTimeOffset, IEnumerable<IKey>>((now, allKeys) =>
  352. {
  353. callSequence.Add("ResolveDefaultKeyPolicy");
  354. resolveDefaultKeyPolicyReturnValuesEnumerator.MoveNext();
  355. Assert.Equal(resolveDefaultKeyPolicyReturnValuesEnumerator.Current.Item1, now);
  356. Assert.Equal(resolveDefaultKeyPolicyReturnValuesEnumerator.Current.Item2, allKeys);
  357. return resolveDefaultKeyPolicyReturnValuesEnumerator.Current.Item3;
  358. });
  359. return CreateKeyRingProvider(mockKeyManager.Object, mockDefaultKeyResolver.Object, keyManagementOptions);
  360. }
  361. [Fact]
  362. public void GetCurrentKeyRing_NoKeyRingCached_CachesAndReturns()
  363. {
  364. // Arrange
  365. var now = StringToDateTime("2015-03-01 00:00:00Z");
  366. var expectedKeyRing = new Mock<IKeyRing>().Object;
  367. var mockCacheableKeyRingProvider = new Mock<ICacheableKeyRingProvider>();
  368. mockCacheableKeyRingProvider
  369. .Setup(o => o.GetCacheableKeyRing(now))
  370. .Returns(new CacheableKeyRing(
  371. expirationToken: CancellationToken.None,
  372. expirationTime: StringToDateTime("2015-03-02 00:00:00Z"),
  373. keyRing: expectedKeyRing));
  374. var keyRingProvider = CreateKeyRingProvider(mockCacheableKeyRingProvider.Object);
  375. // Act
  376. var retVal1 = keyRingProvider.GetCurrentKeyRingCore(now);
  377. var retVal2 = keyRingProvider.GetCurrentKeyRingCore(now + TimeSpan.FromHours(1));
  378. // Assert - underlying provider only should have been called once
  379. Assert.Same(expectedKeyRing, retVal1);
  380. Assert.Same(expectedKeyRing, retVal2);
  381. mockCacheableKeyRingProvider.Verify(o => o.GetCacheableKeyRing(It.IsAny<DateTimeOffset>()), Times.Once);
  382. }
  383. [Fact]
  384. public void GetCurrentKeyRing_KeyRingCached_AfterExpiration_ClearsCache()
  385. {
  386. // Arrange
  387. var now = StringToDateTime("2015-03-01 00:00:00Z");
  388. var expectedKeyRing1 = new Mock<IKeyRing>().Object;
  389. var expectedKeyRing2 = new Mock<IKeyRing>().Object;
  390. var mockCacheableKeyRingProvider = new Mock<ICacheableKeyRingProvider>();
  391. mockCacheableKeyRingProvider
  392. .Setup(o => o.GetCacheableKeyRing(now))
  393. .Returns(new CacheableKeyRing(
  394. expirationToken: CancellationToken.None,
  395. expirationTime: StringToDateTime("2015-03-01 00:30:00Z"), // expire in half an hour
  396. keyRing: expectedKeyRing1));
  397. mockCacheableKeyRingProvider
  398. .Setup(o => o.GetCacheableKeyRing(now + TimeSpan.FromHours(1)))
  399. .Returns(new CacheableKeyRing(
  400. expirationToken: CancellationToken.None,
  401. expirationTime: StringToDateTime("2015-03-02 00:00:00Z"),
  402. keyRing: expectedKeyRing2));
  403. var keyRingProvider = CreateKeyRingProvider(mockCacheableKeyRingProvider.Object);
  404. // Act
  405. var retVal1 = keyRingProvider.GetCurrentKeyRingCore(now);
  406. var retVal2 = keyRingProvider.GetCurrentKeyRingCore(now + TimeSpan.FromHours(1));
  407. // Assert - underlying provider only should have been called once
  408. Assert.Same(expectedKeyRing1, retVal1);
  409. Assert.Same(expectedKeyRing2, retVal2);
  410. mockCacheableKeyRingProvider.Verify(o => o.GetCacheableKeyRing(It.IsAny<DateTimeOffset>()), Times.Exactly(2));
  411. }
  412. [Fact]
  413. public void GetCurrentKeyRing_NoExistingKeyRing_HoldsAllThreadsUntilKeyRingCreated()
  414. {
  415. // Arrange
  416. var now = StringToDateTime("2015-03-01 00:00:00Z");
  417. var expectedKeyRing = new Mock<IKeyRing>().Object;
  418. var mockCacheableKeyRingProvider = new Mock<ICacheableKeyRingProvider>();
  419. var keyRingProvider = CreateKeyRingProvider(mockCacheableKeyRingProvider.Object);
  420. // This test spawns a background thread which calls GetCurrentKeyRing then waits
  421. // for the foreground thread to call GetCurrentKeyRing. When the foreground thread
  422. // blocks (inside the lock), the background thread will return the cached keyring
  423. // object, and the foreground thread should consume that same object instance.
  424. TimeSpan testTimeout = TimeSpan.FromSeconds(10);
  425. Thread foregroundThread = Thread.CurrentThread;
  426. ManualResetEventSlim mreBackgroundThreadHasCalledGetCurrentKeyRing = new ManualResetEventSlim();
  427. ManualResetEventSlim mreForegroundThreadIsCallingGetCurrentKeyRing = new ManualResetEventSlim();
  428. var backgroundGetKeyRingTask = Task.Run(() =>
  429. {
  430. mockCacheableKeyRingProvider
  431. .Setup(o => o.GetCacheableKeyRing(now))
  432. .Returns(() =>
  433. {
  434. mreBackgroundThreadHasCalledGetCurrentKeyRing.Set();
  435. Assert.True(mreForegroundThreadIsCallingGetCurrentKeyRing.Wait(testTimeout), "Test timed out.");
  436. SpinWait.SpinUntil(() => (foregroundThread.ThreadState & ThreadState.WaitSleepJoin) != 0, testTimeout);
  437. return new CacheableKeyRing(
  438. expirationToken: CancellationToken.None,
  439. expirationTime: StringToDateTime("2015-03-02 00:00:00Z"),
  440. keyRing: expectedKeyRing);
  441. });
  442. return keyRingProvider.GetCurrentKeyRingCore(now);
  443. });
  444. Assert.True(mreBackgroundThreadHasCalledGetCurrentKeyRing.Wait(testTimeout), "Test timed out.");
  445. mreForegroundThreadIsCallingGetCurrentKeyRing.Set();
  446. var foregroundRetVal = keyRingProvider.GetCurrentKeyRingCore(now);
  447. backgroundGetKeyRingTask.Wait(testTimeout);
  448. var backgroundRetVal = backgroundGetKeyRingTask.GetAwaiter().GetResult();
  449. // Assert - underlying provider only should have been called once
  450. Assert.Same(expectedKeyRing, foregroundRetVal);
  451. Assert.Same(expectedKeyRing, backgroundRetVal);
  452. mockCacheableKeyRingProvider.Verify(o => o.GetCacheableKeyRing(It.IsAny<DateTimeOffset>()), Times.Once);
  453. }
  454. [Fact]
  455. public void GetCurrentKeyRing_WithExpiredExistingKeyRing_AllowsOneThreadToUpdate_ReturnsExistingKeyRingToOtherCallersWithoutBlocking()
  456. {
  457. // Arrange
  458. var originalKeyRing = new Mock<IKeyRing>().Object;
  459. var originalKeyRingTime = StringToDateTime("2015-03-01 00:00:00Z");
  460. var updatedKeyRing = new Mock<IKeyRing>().Object;
  461. var updatedKeyRingTime = StringToDateTime("2015-03-02 00:00:00Z");
  462. var mockCacheableKeyRingProvider = new Mock<ICacheableKeyRingProvider>();
  463. var keyRingProvider = CreateKeyRingProvider(mockCacheableKeyRingProvider.Object);
  464. // In this test, the foreground thread acquires the critial section in GetCurrentKeyRing,
  465. // and the background thread returns the original key ring rather than blocking while
  466. // waiting for the foreground thread to update the key ring.
  467. TimeSpan testTimeout = TimeSpan.FromSeconds(10);
  468. IKeyRing keyRingReturnedToBackgroundThread = null;
  469. mockCacheableKeyRingProvider.Setup(o => o.GetCacheableKeyRing(originalKeyRingTime))
  470. .Returns(new CacheableKeyRing(CancellationToken.None, StringToDateTime("2015-03-02 00:00:00Z"), originalKeyRing));
  471. mockCacheableKeyRingProvider.Setup(o => o.GetCacheableKeyRing(updatedKeyRingTime))
  472. .Returns<DateTimeOffset>(dto =>
  473. {
  474. // at this point we're inside the critical section - spawn the background thread now
  475. var backgroundGetKeyRingTask = Task.Run(() =>
  476. {
  477. keyRingReturnedToBackgroundThread = keyRingProvider.GetCurrentKeyRingCore(updatedKeyRingTime);
  478. });
  479. Assert.True(backgroundGetKeyRingTask.Wait(testTimeout), "Test timed out.");
  480. return new CacheableKeyRing(CancellationToken.None, StringToDateTime("2015-03-03 00:00:00Z"), updatedKeyRing);
  481. });
  482. // Assert - underlying provider only should have been called once with the updated time (by the foreground thread)
  483. Assert.Same(originalKeyRing, keyRingProvider.GetCurrentKeyRingCore(originalKeyRingTime));
  484. Assert.Same(updatedKeyRing, keyRingProvider.GetCurrentKeyRingCore(updatedKeyRingTime));
  485. Assert.Same(originalKeyRing, keyRingReturnedToBackgroundThread);
  486. mockCacheableKeyRingProvider.Verify(o => o.GetCacheableKeyRing(updatedKeyRingTime), Times.Once);
  487. }
  488. [Fact]
  489. public void GetCurrentKeyRing_WithExpiredExistingKeyRing_UpdateFails_ThrowsButCachesOldKeyRing()
  490. {
  491. // Arrange
  492. var cts = new CancellationTokenSource();
  493. var mockCacheableKeyRingProvider = new Mock<ICacheableKeyRingProvider>();
  494. var originalKeyRing = new Mock<IKeyRing>().Object;
  495. var originalKeyRingTime = StringToDateTime("2015-03-01 00:00:00Z");
  496. mockCacheableKeyRingProvider.Setup(o => o.GetCacheableKeyRing(originalKeyRingTime))
  497. .Returns(new CacheableKeyRing(cts.Token, StringToDateTime("2015-03-02 00:00:00Z"), originalKeyRing));
  498. var throwKeyRingTime = StringToDateTime("2015-03-01 12:00:00Z");
  499. mockCacheableKeyRingProvider.Setup(o => o.GetCacheableKeyRing(throwKeyRingTime)).Throws(new Exception("How exceptional."));
  500. var updatedKeyRing = new Mock<IKeyRing>().Object;
  501. var updatedKeyRingTime = StringToDateTime("2015-03-01 12:02:00Z");
  502. mockCacheableKeyRingProvider.Setup(o => o.GetCacheableKeyRing(updatedKeyRingTime))
  503. .Returns(new CacheableKeyRing(CancellationToken.None, StringToDateTime("2015-03-02 00:00:00Z"), updatedKeyRing));
  504. var keyRingProvider = CreateKeyRingProvider(mockCacheableKeyRingProvider.Object);
  505. // Act & assert
  506. Assert.Same(originalKeyRing, keyRingProvider.GetCurrentKeyRingCore(originalKeyRingTime));
  507. cts.Cancel(); // invalidate the key ring
  508. ExceptionAssert.Throws<Exception>(() => keyRingProvider.GetCurrentKeyRingCore(throwKeyRingTime), "How exceptional.");
  509. Assert.Same(originalKeyRing, keyRingProvider.GetCurrentKeyRingCore(throwKeyRingTime));
  510. Assert.Same(updatedKeyRing, keyRingProvider.GetCurrentKeyRingCore(updatedKeyRingTime));
  511. mockCacheableKeyRingProvider.Verify(o => o.GetCacheableKeyRing(originalKeyRingTime), Times.Once);
  512. mockCacheableKeyRingProvider.Verify(o => o.GetCacheableKeyRing(throwKeyRingTime), Times.Once);
  513. mockCacheableKeyRingProvider.Verify(o => o.GetCacheableKeyRing(updatedKeyRingTime), Times.Once);
  514. }
  515. private static KeyRingProvider CreateKeyRingProvider(ICacheableKeyRingProvider cacheableKeyRingProvider)
  516. {
  517. var serviceCollection = new ServiceCollection();
  518. serviceCollection.AddSingleton<ICacheableKeyRingProvider>(cacheableKeyRingProvider);
  519. return new KeyRingProvider(
  520. keyManager: null,
  521. keyManagementOptions: null,
  522. services: serviceCollection.BuildServiceProvider());
  523. }
  524. private static ICacheableKeyRingProvider CreateKeyRingProvider(IKeyManager keyManager, IDefaultKeyResolver defaultKeyResolver, KeyManagementOptions keyManagementOptions= null)
  525. {
  526. var serviceCollection = new ServiceCollection();
  527. serviceCollection.AddSingleton<IDefaultKeyResolver>(defaultKeyResolver);
  528. return new KeyRingProvider(
  529. keyManager: keyManager,
  530. keyManagementOptions: keyManagementOptions,
  531. services: serviceCollection.BuildServiceProvider());
  532. }
  533. private static void AssertWithinJitterRange(DateTimeOffset actual, DateTimeOffset now)
  534. {
  535. // The jitter can cause the actual value to fall in the range [now + 80% of refresh period, now + 100% of refresh period)
  536. Assert.InRange(actual, now + TimeSpan.FromHours(24 * 0.8), now + TimeSpan.FromHours(24));
  537. }
  538. private static DateTime StringToDateTime(string input)
  539. {
  540. return DateTimeOffset.ParseExact(input, "u", CultureInfo.InvariantCulture).UtcDateTime;
  541. }
  542. private static IKey CreateKey()
  543. {
  544. var now = DateTimeOffset.Now;
  545. return CreateKey(Invariant($"{now:u}"), Invariant($"{now.AddDays(90):u}"));
  546. }
  547. private static IKey CreateKey(string activationDate, string expirationDate, bool isRevoked = false)
  548. {
  549. var mockKey = new Mock<IKey>();
  550. mockKey.Setup(o => o.KeyId).Returns(Guid.NewGuid());
  551. mockKey.Setup(o => o.ActivationDate).Returns(DateTimeOffset.ParseExact(activationDate, "u", CultureInfo.InvariantCulture));
  552. mockKey.Setup(o => o.ExpirationDate).Returns(DateTimeOffset.ParseExact(expirationDate, "u", CultureInfo.InvariantCulture));
  553. mockKey.Setup(o => o.IsRevoked).Returns(isRevoked);
  554. mockKey.Setup(o => o.CreateEncryptorInstance()).Returns(new Mock<IAuthenticatedEncryptor>().Object);
  555. return mockKey.Object;
  556. }
  557. }
  558. }