Files
sure/test/models/sso_identity_block_test.rb
T
Josh ca66346dc5 feat: add safe admin user removal (#3131)
* feat: add safe admin user removal

* fix: address user removal review findings

* fix: close remaining user removal review gaps

* fix: handle deleted users during session creation

* fix: fail closed when session creation fails

* fix: reject token issuance for inactive users
2026-08-22 21:54:32 +02:00

42 lines
1.5 KiB
Ruby

require "test_helper"
class SsoIdentityBlockTest < ActiveSupport::TestCase
test "blocks an identity without storing its raw subject identifier" do
identity = oidc_identities(:bob_google)
SsoIdentityBlock.block_all!(OidcIdentity.where(id: identity.id), identity_label: identity.user.email)
assert SsoIdentityBlock.blocked?(provider: identity.provider, uid: identity.uid)
assert_not_equal identity.uid, SsoIdentityBlock.last.uid_digest
end
test "blocking the same identity is idempotent" do
identity = oidc_identities(:bob_google)
assert_difference -> { SsoIdentityBlock.count }, 1 do
2.times { SsoIdentityBlock.block_all!(OidcIdentity.where(id: identity.id), identity_label: identity.user.email) }
end
end
test "uses a keyed digest instead of a plain subject hash" do
uid = "predictable-subject"
assert_equal SsoIdentityBlock.digest(uid), SsoIdentityBlock.digest(uid)
assert_not_equal Digest::SHA256.hexdigest(uid), SsoIdentityBlock.digest(uid)
end
test "does not store the identity label in plaintext without encryption" do
SsoIdentityBlock.stubs(:encryption_ready?).returns(false)
raw_label = "removed-user@example.com"
block = SsoIdentityBlock.create!(
provider: "openid_connect",
uid_digest: SsoIdentityBlock.digest("removed-subject"),
identity_label: raw_label
)
assert_not_equal raw_label, block.identity_label
assert_match(/Removed identity/, block.identity_label)
end
end